Funding

HiddenLayer's $100 Million Bet That Agents Are the New Attack Surface

A $100 million Series B backed by Microsoft, Morgan Stanley, and Booz Allen Ventures shows major enterprise buyers investing directly in the AI security layer for autonomous agents, not just purchasing it.

HiddenLayer Series B funding announcement graphic for its AI security platform
Image credit: HiddenLayer

HiddenLayer's $100 Million Bet That Agents Are the New Attack Surface

How a Microsoft- and Morgan Stanley-backed security startup is positioning itself as the guard rail for AI that acts on its own

Every enterprise racing to deploy AI agents is quietly building a new kind of attack surface — one where the thing being compromised isn't a database, but a decision.

HiddenLayer, an Austin-based AI security company, announced on September 2 that it has raised a $100 million Series B, a round that more than doubles its total funding and comes with a notably strategic investor list: Microsoft's Venture Fund, Morgan Stanley, and Booz Allen Ventures joined the round led by Delta-v Capital, alongside existing backer Ten Eleven Ventures, according to TechCrunch and the company's own press release. That combination — a cloud hyperscaler, a Wall Street bank, and a defense-and-intelligence-focused VC arm — reads less like a typical growth round and more like a customer roster investing in its own supplier.

What HiddenLayer actually sells

HiddenLayer's AISec platform is built to protect machine learning models and, increasingly, the AI agents built on top of them, against a category of threats that conventional cybersecurity tools weren't designed to catch: adversarial attacks that manipulate a model's outputs, prompt injections that hijack an agent mid-task, model theft, and supply-chain compromises where a downloaded open-weight model has been tampered with. SiliconANGLE reports the company will use the new capital to deepen its Agentic Runtime Security capabilities — a product line it first introduced in March 2026 and expanded again in August with a tool called Agent Harness Security, aimed specifically at protecting AI coding agents as they touch source code, secrets, and production infrastructure at runtime.

That focus matters because of where the industry actually is right now. HiddenLayer's own 2026 AI Threat Landscape research found that one in eight AI-related security breaches are now linked to agentic systems — a jump that tracks the broader shift, across nearly every large enterprise software vendor, from AI that answers questions to AI that takes actions: writing code, executing transactions, calling other tools, making decisions with limited human review in the loop — the same shift that let a ransomware crew successfully convince an AI coding agent it was operating inside a harmless drill rather than a live attack.

Why now, and why these investors

The round's total fundraising history — a roughly $2 million seed, a $50 million Series A in 2023, and now this $100 million Series B — tracks almost exactly the arc of enterprise AI adoption itself. HiddenLayer's Series A, raised when generative AI was mostly a chatbot novelty, was a bet on model-level threats: someone stealing a company's proprietary model weights, or poisoning training data. This round is a bet on a different, newer problem: what happens when the model isn't just generating text, but is wired into systems that can spend money, ship code, or touch customer data with minimal human supervision.

Microsoft's participation through its Venture Fund is the least surprising piece — the company has been investing across its AI security supply chain for years and has an obvious interest in making its own Azure AI customers feel safe enough to deploy agents at scale. Morgan Stanley's involvement is a more pointed signal: a major bank putting capital into an AI security vendor suggests financial services firms, which face some of the strictest regulatory scrutiny on AI-driven decision-making of any industry, see agentic AI security as infrastructure worth owning a stake in rather than just purchasing.

The stakeholder read

For enterprises evaluating AI agent deployments, HiddenLayer's raise is a data point in a broader trend: the security tooling layer for agentic AI is maturing faster than many CISOs expected, which lowers the excuse for delaying agent rollouts on security grounds — but also raises the bar for what "secure enough" now means. A security team that hasn't evaluated runtime controls for its coding agents or customer-facing AI assistants is, by this logic, already behind where well-resourced peers are moving.

For competing AI security startups — a field Edgewisely has tracked across the leading AI guardrails and LLM security platforms — the size of this round and its investor quality raises the stakes of an already crowded field. AI security has attracted a wave of well-funded entrants over the past two years, and a $100 million round with Microsoft and Morgan Stanley on the cap table functions as a strong signal to the rest of that market about which vendors the largest potential customers are already betting on before a formal procurement process even begins.

For HiddenLayer itself, the money is a chance to move from being one vendor among several point solutions to something closer to a default layer — the kind of infrastructure a large enterprise buys once and standardizes on, rather than re-evaluating every budget cycle. That's a harder position to earn than it is to claim, and it depends on whether Agent Harness Security and the rest of the Agentic Runtime Security line prove out in production at the scale its new investors are implicitly betting on.

The zoom-out

The pattern across enterprise software over the last three decades has been consistent: every new layer of automation creates a corresponding new layer of security spend, usually a few years behind the automation itself. Cloud computing got a security industry. APIs got a security industry. Now the agent frameworks enterprises are standardizing production workloads on are getting one too, and the compressed timeline — HiddenLayer went from model-theft protection to agent-runtime security in under three years — reflects how much faster this cycle is moving than the ones before it.

The through-line for any operator deploying AI agents right now: the security conversation can't wait for the incident. The vendors capitalizing fastest are the ones selling controls for a class of failure most companies haven't experienced yet, but that the data already shows is happening at meaningful scale.


Frequently Asked Questions

How much did HiddenLayer raise, and who led the round?

HiddenLayer raised a $100 million Series B led by Delta-v Capital, with participation from Ten Eleven Ventures, Morgan Stanley, Microsoft's M12 Venture Fund, and Booz Allen Ventures, according to TechCrunch, announced September 2, 2026.

What does HiddenLayer's platform actually protect against?

Its AISec platform defends AI models and agents against adversarial attacks, prompt injection, model theft, and AI supply-chain compromises, with a growing focus on securing autonomous agents at runtime — including a dedicated product for AI coding agents called Agent Harness Security.

Why are agents considered a bigger security risk than earlier AI chatbots?

Agents take actions — writing code, executing tasks, calling other tools — often with limited human review, which turns a bad model output into a real-world consequence rather than just a wrong answer. HiddenLayer's own research found one in eight AI security breaches are now linked to agentic systems.

What does Microsoft and Morgan Stanley's involvement signal?

It suggests major cloud and financial services players see agentic AI security as core infrastructure worth investing in directly, not just buying — a strong signal to the rest of the AI security market about which vendors large enterprise buyers are already backing.


Editor's note — sources: TechCrunch, SiliconANGLE, HiddenLayer (official newsroom announcement).

Get Edgewisely in your inbox

Business stories that matter, free. Enter your email — no password, no account to set up.
jamie@example.com
Subscribe