Editorial still-life photograph of an open brass padlock beside a coiled orange network cable and server components on a warm ivory surface

Your AI Agent Has No Bodyguard. An Austin Startup Just Raised $100M to Fix That.

September 03, 2026

Last Tuesday, a company about three miles from my office closed a $100 million funding round. HiddenLayer, an Austin-based AI security startup, pulled in a Series B led by Delta-v Capital with Microsoft's M12, Morgan Stanley, and Booz Allen Ventures piling in behind them.

That's a big check for a company most business owners have never heard of. But the problem they're solving is one you've probably already run into.

If you've deployed an AI agent, chatbot, or any kind of model in production, you've built something that can be tricked. Prompt injection, model manipulation, malicious tool calls. These aren't theoretical. They're happening right now, and most businesses have zero visibility into it.

The gap nobody budgeted for

Think about how you rolled out your last AI tool. You picked a model, wired it into your workflow, tested the happy path, and shipped it. Security probably came up as a checkbox on a compliance form, if it came up at all.

That's the norm. And it's a problem.

HiddenLayer's CEO Chris Sestito put it plainly: the company had to "grow our scope from traditional modeling to GenAI to agentic." In other words, the attack surface grew faster than anyone expected. Your chatbot that answers customer questions can be manipulated into leaking internal data. Your coding agent can be tricked into running malicious code. Your document-processing pipeline can be fed poisoned inputs.

This isn't science fiction. One of HiddenLayer's customers is described as a "leading frontier model provider" with more than 700 million weekly users. If companies at that scale need dedicated AI security, the rest of us probably do too.

The numbers tell the story

HiddenLayer's annual recurring revenue grew more than tenfold in the past year. Over 90% of that growth came from brand-new customers. Financial services firms, large tech companies building AI products, and even the Department of Defense are signing up.

In August, the DOE picked HiddenLayer to support Prometheus, a $60 million initiative applying AI to nuclear energy challenges across national laboratories. When the federal government trusts you to secure AI in nuclear facilities, that says something about where this market is heading.

What this means if you run a small business

You probably don't need a $100 million security platform. But you do need to start thinking about AI security the way you think about password management or email phishing training.

Here's what I'd recommend right now:

Audit your AI touchpoints. List every place where an AI model interacts with your customers, your data, or your internal tools. Most businesses have more of these than they realize.

Test the bad path. Try to break your own AI tools. Feed them weird inputs. Ask your chatbot to reveal its system prompt. If you can trick it, someone else will.

Watch the supply chain. If you're using open-source models, know where they came from. HiddenLayer scans more than 50 AI file formats for malicious code. That scanning exists because the threat is real.

Budget for it. AI security is going to become a line item, just like cloud security did ten years ago. Getting ahead of it now is cheaper than cleaning up a breach later.

The bigger picture

We're watching the same pattern that played out with cloud computing. First everyone rushes to adopt. Then someone gets burned. Then security becomes a market of its own. HiddenLayer's $100 million raise is a signal that we've entered phase three for AI.

The companies that figure out AI security early will build the kind of trust with customers that becomes a real edge. And honestly, that's worth more than any single AI feature you could ship.

— Mark Garza, Laimen AI

Mark Garza

Mark Garza

Mark is an automation and AI growth strategist and the founder of Laimen AI.

LinkedIn logo icon
Back to Blog