HiddenLayer Raises $100 Million to Guard AI Agents From Manipulation and Misuse
The Austin-based firm, which builds security tools specifically for artificial intelligence systems, will use the funding to watch over AI agents that write and ship code with little human oversight.

Key points
- HiddenLayer raised $100 million in a Series B funding round announced Wednesday, bringing its total funding to over $155 million.
- Founded in 2022, the company builds security software designed to protect artificial intelligence systems from attack and misuse.
- Delta-v Capital led the round, with participation from Microsoft's Venture Fund M12, Booz Allen Ventures, Morgan Stanley, and Ten Eleven Ventures.
- New spending will focus on monitoring AI coding agents, meaning software that writes, reviews, and ships program code largely on its own.
Artificial intelligence is moving fast inside companies. So are the criminals looking to abuse it.
HiddenLayer, an Austin, Texas security firm founded in 2022, announced Wednesday that it has raised $100 million in a Series B round, a standard private funding stage for a growing company seeking capital to scale. The raise lifts the firm's total funding past $155 million.
What does HiddenLayer actually do?
The company builds a security platform for AI systems, not for ordinary software or networks. Think of it as a watchdog that sits alongside the AI tools a business relies on, looking for signs that those tools are behaving in ways they should not.
Its platform covers four main areas: finding AI systems inside a company's environment, checking the security of the components those systems are built from, simulating attacks against them to find weaknesses, and monitoring them in real time once they are live and running.
The real-time monitoring piece, called runtime protection, is the focus of the new investment. Specifically, HiddenLayer wants to watch AI agents, meaning software programs that take actions on their own, without a human approving each step. A coding agent, for example, might read a requirement, write the code to fulfil it, test it, and push it to a production system, all without anyone in the loop.
Why does an autonomous coding agent need its own security?
Because an agent acting autonomously can do real damage if something goes wrong. Criminals could try to manipulate one through a technique called a prompt injection attack, where hidden instructions in data the agent reads trick it into doing something harmful. Bad inputs could also cause the agent to leak private code, introduce security flaws deliberately, or take actions the company never authorised.
HiddenLayer co-founder and CEO Chris Sestito put it plainly: "We set out to pioneer trusted, secure use of AI for enterprises, long before most organizations saw the urgency we do today. This funding lets us keep growing the purpose-built team and platform required to meet that moment as agentic AI becomes core to how enterprises operate."
The funding round was first reported by SecurityWeek.
What does this mean for ordinary employees and customers?
If you work at a company that uses AI tools to write software or automate tasks, this kind of security is meant to protect you indirectly. Compromised AI agents could expose your personal data, introduce flaws into products you use, or carry out financial transactions without proper approval.
For now, there is no action required from customers or end users. This is a vendor funding story, not a breach. But watch for your employer's AI-use policies to tighten as regulators, particularly under frameworks like the European Union's AI Act, begin demanding exactly the kind of audit trails and runtime controls that HiddenLayer sells.
Common questions
Is this a sign AI systems are regularly being attacked?
Yes. Security researchers have documented prompt injection attacks, model theft, and data-poisoning attempts against commercial AI systems. The threat is real, even if it is less visible to the public than ransomware.
Should my organisation worry about AI agents it already uses?
If your organisation runs AI tools that take actions automatically, reviewing what those tools can access and what oversight exists is a sensible first step, regardless of which security vendor you use.



