kalinga.ai

What Is AI Security, and Why Did HiddenLayer Just Raise $100 Million?

AI security concept highlighting HiddenLayer's $100M funding and growing AI threat protection market
AI security is becoming essential as enterprises deploy more powerful AI models and autonomous agents.

Imagine spending months fine-tuning an AI agent for your company, only to have someone trick it into leaking customer data with a cleverly worded prompt. That scenario is exactly why AI security has become one of the hottest categories in tech funding. In September 2026, Austin-based startup HiddenLayer raised a $100 million Series B to help enterprises protect their AI models, agents, and workflows from exactly this kind of attack, and the deal is a strong signal that AI security is no longer a niche concern,  it’s becoming a core part of how every company deploys AI.

For students and young professionals in Odisha and across India tracking where the AI industry is headed, this is a story worth understanding closely. It’s not just a funding headline; it points to an entire new job market, a new set of skills, and a new way of thinking about how AI systems get built safely.

What Is AI Security, Exactly?

AI security is the practice of protecting artificial intelligence models, agents, and the data pipelines around them from attacks, misuse, and unintended failures. Unlike traditional cybersecurity, which focuses on protecting networks, servers, and applications, AI security specifically addresses risks unique to machine learning systems,  things like model theft, data poisoning, and manipulation through malicious prompts. Think of it as the digital immune system for AI: just as antivirus software watches for malware on your laptop, AI security tools watch for attackers trying to manipulate or exploit an AI model or agent while it’s running.

This distinction matters because AI systems don’t fail the way traditional software does. A hacker doesn’t need to breach a firewall to compromise an AI agent,  sometimes all it takes is the right combination of words typed into a chat window.

Why does AI security matter right now? Because AI is no longer confined to research labs,  it’s embedded in banking apps, customer service bots, internal company tools, and government systems, and each of those deployments creates a new potential entry point for attackers.

HiddenLayer’s $100M Raise: The Numbers That Matter

HiddenLayer’s new funding round is a useful lens into how fast the AI security market is moving. Here’s what happened, based on TechCrunch’s reporting on the deal:

  • HiddenLayer raised a $100 million Series B, led by Delta-v Capital, with participation from Ten Eleven Ventures, Morgan Stanley, Microsoft’s M12, and Booz Allen Hamilton, among others.
  • This comes three years after the company’s $50 million Series A in 2023,  back then, it was genuinely unclear whether AI-specific attacks would happen at meaningful scale.
  • HiddenLayer’s CEO, Chris Sestito, told TechCrunch the company’s annual recurring revenue (ARR),  the yearly income it can reliably count on from subscriptions,  grew more than 10x over the past year, with over 90% of that growth coming from brand-new customers.
  • Its largest customer verticals are financial services and large tech companies, and it also holds contracts with the U.S. Department of Defense and the intelligence community.
  • One customer is described as a “leading frontier model provider” with more than 700 million weekly users,  a hint, though not a confirmed name, that points toward a company the size of OpenAI or Anthropic.

Definition + Expansion,  Series B funding: A Series B round is a later stage of startup fundraising, typically used to scale a business that has already proven demand for its product. For HiddenLayer, moving from a $50 million Series A in 2023 to a $100 million Series B in 2026 signals investors believe the company has moved past the “will this market even exist” question and into “how fast can this scale” territory.

Why Is Money Suddenly Pouring Into AI Security?

This isn’t just one company’s success story,  it reflects an industry-wide shift. According to Gartner’s own forecast, cited in TechCrunch’s report, companies are expected to spend $2.83 billion in 2026 on tools to secure AI systems, which is 83% more than in 2025, and that number is projected to reach nearly $4.78 billion in 2027.

Why is spending accelerating so quickly? Because AI adoption itself accelerated faster than the security tools built to protect it, leaving a widening gap that enterprises are now racing to close as AI moves from experimentation into production.

A few forces are driving this surge:

  • AI agents are now doing real work. Agents that can browse the web, use software tools, and take autonomous actions create far more risk than a simple chatbot that only answers questions.
  • Open-source and open-weight models are everywhere. HiddenLayer says it scans about 50 different AI file frameworks to check that an open-source model is actually what it claims to be, rather than a disguised or tampered version.
  • Prompt injection and agent manipulation are real threats. These attacks trick an AI system into ignoring its original instructions and doing something harmful instead.
  • Big cybersecurity players are validating the space through acquisitions. Cisco, Palo Alto Networks, and Check Point have all acquired AI security startups (Robust Intelligence, Protect AI, and Lakera respectively) rather than building this technology in-house.
  • Competitors are raising similar-sized rounds. Startups like Noma Security and Zenity have each raised more than $100 million to tackle overlapping parts of the AI security space, confirming this isn’t a one-company trend.

Key AI Security Threats You Should Know

Question → Direct Answer,  What is prompt injection? Prompt injection is an attack where someone embeds hidden or disguised instructions into text an AI system processes, tricking the AI into ignoring its original rules and following the attacker’s commands instead. It’s one of the most common and hardest-to-fully-prevent risks in modern AI security, because the “attack” often looks like ordinary text rather than malicious code.

Beyond prompt injection, a few other threats define the current AI security landscape:

  • Data poisoning,  corrupting the training data an AI model learns from, so it behaves incorrectly or maliciously later.
  • Model theft,  stealing a proprietary AI model’s weights or architecture, essentially copying years of expensive research.
  • Agent manipulation,  tricking an autonomous AI agent into taking harmful real-world actions, like sending money or leaking files, rather than just generating bad text.
  • Malicious tool use,  an AI agent being manipulated into calling an external tool or API in a way it was never supposed to.
  • Hidden or disguised models,  an open-source model that claims to be one thing but actually contains different, potentially harmful behavior baked in.

Definition + Expansion,  Runtime protection: Runtime protection refers to security measures that monitor an AI system while it’s actively running, rather than only checking it before deployment. HiddenLayer’s CEO compared this to traditional endpoint detection and response (EDR) tools used in classic cybersecurity, except built specifically for AI systems. In practice, this means an AI security tool watches live traffic going into and out of a model or agent, flagging suspicious prompts, unusual outputs, or unexpected tool calls as they happen,  not just during a one-time audit.

AI Security vs. Traditional Cybersecurity: A Quick Comparison

Understanding how AI security differs from traditional cybersecurity helps explain why an entirely new category of startups had to be built, instead of existing security vendors simply expanding their old products.

AspectTraditional CybersecurityAI Security
Primary targetNetworks, servers, applications, endpointsAI models, agents, prompts, training data
Common attack typeMalware, phishing, ransomware, network breachesPrompt injection, data poisoning, model theft, agent manipulation
Detection approachSignature-based malware scanning, firewallsBehavioral monitoring of model inputs/outputs, runtime inference protection
What “compromise” looks likeUnauthorized system access, data breachModel tricked into unsafe outputs, hidden malicious model, hijacked agent actions
Key vendors (per TechCrunch report)Cisco, Palo Alto Networks, Check Point (as acquirers)HiddenLayer, Noma Security, Zenity, Protect AI (acquired), Lakera (acquired)
Maturity of fieldDecades old, well-established standardsEmerging, standards still forming

This table also explains why large cybersecurity companies increasingly buy rather than build AI security capabilities,  the underlying skills, like understanding how a language model can be manipulated through text, are genuinely different from classic network security expertise.

What This Means If You’re Building an AI Career in India

For students and early-career professionals in Odisha and across India, the AI security boom represents a genuinely fresh career lane,  one that doesn’t require you to have started five years ago to be relevant, since the field itself is only a few years old.

  • AI security research roles are opening up at security-focused AI startups and inside the AI teams of larger companies, requiring a mix of machine learning literacy and security thinking.
  • Prompt engineering with a security lens,  understanding how prompts can be attacked, not just how to write good ones,  is becoming a specialized skill in its own right.
  • AI governance and compliance work is growing too; HiddenLayer’s CEO himself expects AI infrastructure providers to lean more toward governance features like discovery, identity, and policy controls.
  • Red-teaming AI systems,  deliberately trying to break or manipulate an AI model to find its weaknesses before real attackers do,  is an emerging specialty that blends creativity with technical skill.
  • Traditional cybersecurity backgrounds transfer well, since concepts like runtime monitoring and endpoint detection map directly onto how AI security tools are being built.

Question → Direct Answer,  Do I need a machine learning degree to work in AI security? Not necessarily. Many AI security roles value strong security fundamentals combined with a working understanding of how AI models behave, rather than requiring deep ML research expertise,  meaning a security-focused background with self-taught AI literacy can be just as valuable as a pure ML background.

Where AI Security Is Headed Next

HiddenLayer’s plans for its new $100 million offer a preview of where the broader AI security industry is likely to go. The company says the funding will go primarily toward sales and distribution, while continuing to grow its engineering and research teams, and it plans to expand into Europe and EMEA markets.

There’s also an interesting tension worth watching: HiddenLayer’s own CEO acknowledged that some of the security features his company builds could eventually get bundled directly into AI platforms built by companies like Microsoft, OpenAI, and AWS. His bet is that platform providers will focus on broader governance,  things like identity and policy controls,  rather than the deep, specialized runtime protection tools that dedicated AI security vendors build. Whether that bet holds up will shape which companies in this space survive as independent businesses versus getting absorbed into bigger platforms.

For now, the direction is clear: as AI agents move from experiments into production systems handling real money, real data, and real decisions, the tools designed to keep them safe are becoming just as essential as the AI systems themselves.

FAQ: AI Security, Explained Simply

What is AI security in simple terms? AI security is the set of tools and practices used to protect AI models and AI agents from being hacked, tricked, or manipulated,  similar to how traditional cybersecurity protects computers and networks, but built specifically for how AI systems work and fail.

What did HiddenLayer raise, and who led the round? HiddenLayer raised a $100 million Series B funding round led by Delta-v Capital, with participation from Ten Eleven Ventures, Morgan Stanley, Microsoft’s M12, and Booz Allen Hamilton, according to TechCrunch’s report on the deal.

How big is the AI security market right now? Gartner estimates companies will spend $2.83 billion on AI security tools in 2026, an 83% increase over 2025, with spending projected to reach almost $4.78 billion in 2027.

What is prompt injection, and why is it dangerous? Prompt injection is an attack where hidden or disguised instructions are slipped into text an AI system processes, tricking it into ignoring its original rules and following the attacker’s commands instead,  it’s dangerous because it doesn’t require breaking into a system, just crafting the right words.

Is AI security different from regular cybersecurity? Yes. While traditional cybersecurity protects networks, servers, and applications from things like malware and phishing, AI security specifically defends AI models and agents against risks like data poisoning, model theft, prompt injection, and agent manipulation.

Which other companies are big players in AI security? Besides HiddenLayer, notable AI security startups include Noma Security and Zenity, both of which have raised over $100 million, while larger cybersecurity firms like Cisco, Palo Alto Networks, and Check Point have acquired AI security startups (Robust Intelligence, Protect AI, and Lakera respectively) to enter the space.


Curious how AI security fits into the broader AI skills you should be building right now? Explore more explainers and beginner-friendly breakdowns of the AI industry on Kalinga.ai, and keep an eye out for our upcoming workshops on practical AI tools for students and young professionals in Odisha.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top