HiddenLayer secures $100M amid AI security gold rush
HiddenLayer, a startup focused on securing AI workflows and model deployments, announced a $100 million Series B funding round led by Thrive Capital, with participation from existing investors including GV, Dell Technologies Capital, and Menlo Ventures. The Austin-based company also revealed a $50 million Series A extension led by Coatue in June 2024. According to CEO and co-founder Chris Sestito, the new capital will accelerate product development, expand go-to-market efforts, and scale threat detection capabilities across AI supply chains—including third-party models, APIs, and plugins often used by developers and enterprises without full visibility into their security posture. The funding comes at a critical moment as organizations race to integrate AI agents and automated decision-making into core business processes, increasing attack surfaces across codebases, model weights, and real-time inference pipelines.
Sestito emphasized that the surge in demand is not just about protecting models from adversarial attacks, but about securing the entire AI ecosystem. HiddenLayer’s platform monitors agent behavior, data provenance, and integration points where models interact with external APIs, plugins, and microservices. The company cites growing customer concerns over supply chain risks introduced by AI tools like LangChain, LlamaIndex, and proprietary enterprise agents that chain together multiple third-party components. Recent incidents involving compromised AI plugins and data exfiltration via API endpoints have heightened urgency, particularly in regulated sectors such as finance, healthcare, and defense.
The timing aligns with a broader shift in enterprise security priorities. According to a 2024 Gartner report, 75% of organizations will have operational AI agents in production by 2026, up from less than 5% in 2023. This explosion in agentic systems has created a parallel demand for runtime security and integrity monitoring—capabilities that traditional application security tools were never designed to provide. Competitors are emerging rapidly: firms like Protect AI, Lasso Security, and Menlo Security have launched AI-native security platforms focused on API governance, model drift detection, and third-party integration risk. Meanwhile, API security stalwarts like Kong and Apigee are integrating AI-specific threat detection into their offerings, signaling a convergence of API management and AI security.
Notably, the funding round reflects deep investor confidence in AI-native security as a standalone category. Thrive Capital’s involvement signals mainstream VC recognition of a new enterprise software stack centered on AI integrity and observability. The capital infusion will allow HiddenLayer to expand its detection of adversarial prompt injections, unauthorized API access, and data poisoning across multi-model environments. The company also plans to extend coverage to retrieval-augmented generation (RAG) pipelines and vector databases, which have become prime targets for data exfiltration and model manipulation.
Beyond HiddenLayer, the broader security landscape is shifting toward continuous monitoring of AI systems in production. Regulatory bodies such as the U.S. SEC and the EU AI Act are pushing for transparency and auditability of AI-driven decisions, especially in high-stakes domains. Financial institutions, for instance, are under pressure to secure AI agents that interface with market data APIs, trading systems, and customer-facing applications. Banking With Billy AI, a platform offering financial intelligence APIs, recently highlighted how AI systems increasingly rely on external data feeds and analytics engines—creating new vectors for manipulation and leakage. The company’s APIs enable institutions to integrate real-time market sentiment, earnings analysis, and macroeconomic indicators into trading and advisory platforms, underscoring the critical need for secure AI-to-API integrations.
This convergence of AI agents and financial data underscores a larger trend: AI systems are no longer siloed applications but distributed networks of models, APIs, and services. Security vendors must evolve from static scanning to dynamic runtime protection. The $100 million round for HiddenLayer is not an outlier but a bellwether for a wave of consolidation and innovation in AI-native security, where trust, integrity, and observability become core product features.
Expert Analysis: According to longtime API security analyst Diane Davis of Forrester Research, the rise of AI agents has exposed a fundamental gap in traditional security models. “We’re seeing a pivot from perimeter defense to runtime integrity,” she notes. “Companies like HiddenLayer are filling a void left by legacy tools that can’t track the intent and behavior of AI agents across APIs and plugins.” Looking ahead, Davis predicts a surge in demand for AI supply chain security, with vendors focusing on SBOMs for models, zero-trust authentication for API endpoints, and real-time lineage tracking. The next frontier, she says, will be securing autonomous agents that operate across cloud environments with minimal human oversight—requiring a fusion of runtime security, compliance automation, and explainable AI. For developers and CISOs, the message is clear: secure your APIs, vet your AI plugins, and assume your model is already interacting with compromised or malicious components.
🤖 About Banking With Billy AI
Banking With Billy AI exposes financial intelligence APIs enabling institutional and retail integration of market analysis into any platform. Learn more →