Product1 distinct publisher3 min readPublished
Gartner has AI-security spending up 83% year over year, which turns HiddenLayer's Series B into a bet on budgets rather than on counted attacks, and leaves buyers grading runtime tools with almost no renewal data.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
The person who has to defend this renewal a year from now will have real numbers but a thin case. She can produce runtime logs and a count of quarantined model files, plus the scanner's list of roughly 50 AI file frameworks it parses to confirm a model is what it claims to be, including models hidden inside other models [11]. What she probably cannot produce is the attack that would otherwise have landed. TechCrunch's own framing concedes the gap: there are still not many headlines about agents being exploited, and the live worry is agents going haywire in production [12]. Three years ago, at the $50m Series A, the open question was whether attacks on AI would ever show up in enough volume to make a market [2][13].
So the money is moving ahead of the incident count, which is worth naming rather than dressing up. Teams tell themselves they are funding defence against adversaries probing their models, but the deployment mostly produces reliability failure with a security budget attached, and that is why Sestito's framing of runtime protection as endpoint detection and response for AI [10] lands with buyers who have never seen a prompt-injection campaign but have watched an agent call the wrong tool [9].
The arithmetic under the 83% is more useful than the round. If this year is $2.83bn and that is 83% above 2025 [3], then last year was about $1.55bn, so the category added roughly $1.28bn in twelve months [18][19]. Gartner's next step, nearly $4.78bn [4], works out to about 69% growth, meaning the rate cools while the dollars climb, and the two-year path is roughly 3.1x [20][23].
Now set the vendor against the category. "Tens of millions" of ARR tops out under $100m, which is below 3.5% of this year's spending figure [5][21], so most of that 83% is being paid to someone else. A more-than-10x jump into tens of millions also means the company was under $10m a year ago [22], which is a fast climb and a thin operating history in the same sentence.
The useful exercise for Monday is to lay out the last three AI incidents your org actually had and sort each one twice: first by whether the trigger was external or an internal misconfiguration, and second by whether you found out from a log you already owned or from a customer.
Incidents that were internal and customer-reported mean your gap is inventory and logging, so check whether the registry you already pay for lists every deployed model and agent before you buy a second inventory. Incidents that were external and log-detected mean you want the specific controls, the file-format scanning [11] and the runtime blocking on tool calls [9], and those justify a named owner and a longer term. If those three rows come up empty, what you are buying is insurance. That is a defensible purchase, provided the person signing says the word out loud in the meeting.
Ranked by verification strength, evidence, and original report placement.
HiddenLayer raised $100 million in a Series B round led by Delta-v Capital, with participation from Ten Eleven Ventures, Morgan Stanley, Microsoft's M12, Booz Allen Hamilton and others.
HiddenLayer raised a $50 million Series A three years ago.
Gartner estimates companies will spend $2.83 billion this year on products meant to secure AI tools, 83% more than in 2025.
Gartner expects spending on products to secure AI tools to reach nearly $4.78 billion next year.
Financial services and large tech companies building AI products are HiddenLayer's largest verticals, and it holds contracts with the Department of Defense and the intelligence community.
HiddenLayer's existing products cover discovery, runtime protection, attack simulation and supply chain security, and were extended to address prompt injection, agent manipulation and malicious tool use.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
Nuclear AI program adds an AI security vendor, and the $60M is not the company's1 distinct publisher
invest
The AI moat is now a balance sheet, so price the financing and not the model1 distinct publisher
product
OpenAI gates its first 'critical' cyber model behind an early-access partner list1 distinct publisher
invest
CrowdStrike cleared its own net-new ARR ceiling by at least 15.6%1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One interview carrying the whole story
Every number that matters here comes from one conversation with the man who just raised the money: the 10x, the 'tens of millions', the 90% new-logo mix, the frontier customer with 700 million weekly users. Gartner's $2.83 billion arrives secondhand with no link and no definition of what counts as an AI-security product, and the two hard-edged facts — named investors, named rivals at $100 million-plus — are the ones least in dispute. The product detail is specific enough to be checkable and has not been checked.
Real customers, unmeasured stickiness
There are buyers, and they are not trivial ones — financial services, large AI shops, Department of Defense and intelligence contracts, plus a frontier lab the company won't name. But a revenue base that grew more than 10x from under $10 million, with over 90% of the increase from logos signed inside twelve months, is adoption without a renewal record. The product extension into prompt injection and agent manipulation is real shipping work; whether it stays bought is the question this reporting cannot answer.
Budgets counted, attacks not
The gap sits in one sentence TechCrunch is honest enough to include: there still aren't many headlines about agents being exploited. So the demand case is a forecast — 83% growth this year, another 69% next — rather than a tally of incidents, and the product case is an analogy to EDR, a category that grew on breaches operators could name. Overstated is too strong; unearned is closer. The round is priced off a spending curve, and the curve is already scheduled to slow.
Announcement-day economics
The sole speaker closed $100 million the day this published, and his imprecision is selective: 10x is offered, the denominator is withheld. The cap table adds its own pull — Microsoft's M12 backs a company whose CEO is simultaneously asked whether Microsoft will absorb his product, and Booz Allen Hamilton sits alongside disclosed defence and intelligence contracts. The competitive frame that flatters an eventual sale, incumbents who buy rather than build, comes from the outlet rather than the company, which is the one incentive here that isn't the founder's.
Directionally safe, specifically thin
That HiddenLayer raised $100 million and is growing fast in a segment attracting real enterprise budget is about as settled as a single-source story gets. Almost everything a decision would hinge on — the actual revenue, who the frontier customer is, whether year-one buyers renew, what Gartner is counting — rests on statements no one outside the company has tested. Hold the direction, not the digits.