HiddenLayer

Type: company (AI-security / guardrails & red-teaming vendor) Sector: AI security — runtime protection, model supply-chain scanning, attack simulation/red-teaming First seen: 2026-07-13 Last updated: 2026-09-08

Updated 2026-09-08 based on S-2026-09-02-hiddenlayer-series-b (daily AI-governance vendor-intelligence scan; PR Newswire release and TechCrunch coverage, both fetched in full, 2 Sep 2026) — HiddenLayer closed a $100M Series B led by Delta-v Capital with Ten Eleven Ventures, Morgan Stanley, M12 (Microsoft) and Booz Allen Ventures, answering the 27 Aug open question on whether the go-to-market build-out preceded a financing event (it did, by three weeks). Proceeds target Agentic Runtime Security, Agent Harness Security, channel and international/EMEA expansion; TechCrunch reports financial services as the company’s largest vertical, and the release lists securities brokerage, banking and insurance among 50+ new customers — sector-described, none named, so the standing gap (no named EU/UK regulated-FS reference) persists, now alongside a stated FS concentration ⚠️ vendor-asserted. Still no regulatory standard named.

Updated 2026-08-28 based on S-2026-08-28-weekly-ai-governance-vendor-synthesis (own-writing; weekly market-level read, no new per-vendor facts) — the Prometheus selection (18 Aug) and CRO appointment (12 Aug) landing in the same capture week make HiddenLayer the only vendor to move twice in the week to 28 Aug, a scale-up pattern combining assurance credentials from a safety-critical regulated sector with enterprise go-to-market build-out [inference]. The vault still records no named EU/UK regulated-FS reference customer.

Updated 2026-08-27 based on S-2026-08-12-hiddenlayer-cro-gesnaldo (daily AI-governance vendor-intelligence scan; primary vendor release, 12 Aug 2026, fetched in full) — HiddenLayer appointed Mike Gesnaldo as Chief Revenue Officer to lead its go-to-market organisations. His stated pedigree (CrowdStrike, Tanium, Dazz — vendor’s account) signals a deliberate shift from research-led startup to mainstream enterprise-cybersecurity sales motion, with services and channel named as growth pillars. A vendor-durability data point for regulated buyers, not a capability change; still no named EU/UK regulated-FS reference customer.

Updated 2026-08-26 based on S-2026-08-18-hiddenlayer-doe-prometheus (daily AI-governance vendor-intelligence scan; primary vendor release, 18 Aug 2026, fetched in full) — HiddenLayer selected as AI-security contributor to Prometheus, the Idaho National Laboratory-led US DOE initiative ($60M Phase II over three years under the Genesis Mission, subject to appropriations) applying AI to nuclear reactor design, licensing, manufacturing and operations. This is the vendor’s first government / critical-infrastructure programme engagement in this vault, and a non-FS precedent worth tracking: a safety-critical regulated sector embedding independent AI vulnerability testing and adversarial protection as a foundational programme control. Still no named EU/UK regulated-FS reference customer, and still no named regulatory standard.

Updated 2026-08-07 based on S-2026-08-03-hiddenlayer-agent-harness-security (daily AI-governance vendor-intelligence scan; primary vendor release, 3 Aug 2026, fetched in full) — HiddenLayer’s runtime layer moves from protecting models and agents in production into the developer execution environment, launching Agent Harness Security for AI coding agents. This makes HiddenLayer the second vendor in this vault to claim the agent-harness enforcement locus (after Credo AI’s Agent Governor), reached independently and from the security rather than governance side. Its distinguishing feature is not detection but enforcement transparency: per-agent reporting of whether an action was detected, redacted, blocked or limited by the underlying agent platform — the first vendor statement in this vault that a runtime control’s strength is capped by a third party. Scope is narrower than the earlier Cohere item: coding agents (SDLC/change control), not customer- or decision-facing AI. Still no regulatory standard named and still no FS customer.

Created 2026-07-13 from HiddenLayer × Cohere — securing agentic AI for regulated industries (June 2026) (daily AI-governance vendor-intelligence scan). Second source reached the same day via S-2026-07-13-databricks-unity-ai-gateway-refetch (HiddenLayer named an upcoming Unity AI Gateway integration). All capability claims are the vendor’s own and not independently verified.

Snapshot

HiddenLayer is an Austin-based AI-security vendor (on Paul’s GenAI/LLM safety, guardrails and red-teaming watchlist) whose platform spans AI discovery, AI supply-chain security (model scanning), attack simulation/red-teaming, and runtime security for predictive, generative and agentic AI [S-2026-06-29-hiddenlayer-cohere-agentic]. It matters to the wiki because it is positioning its runtime-security layer as the control and evidence surface for agentic AI in regulated industries — most recently by pairing directly with a sovereign model provider (Cohere North) rather than selling only to the deploying enterprise [S-2026-06-29-hiddenlayer-cohere-agentic].

Positions / Claims they advance

  • Agentic AI “dramatically increases the attack surface” — prompt injection, data exfiltration and abuse of connected tools/systems — and needs security purpose-built for AI, “the AI layer that traditional controls miss” (CEO Chris Sestito) [S-2026-06-29-hiddenlayer-cohere-agentic].
  • Its collaboration with Cohere (29 Jun 2026) pairs the HiddenLayer AI Security Platform with Cohere’s North agentic platform, claiming runtime detection of prompt injection, model attacks and malicious tool use, data-leakage reduction, and “audit-ready visibility into AI interactions” — all vendor marketing, with no named regulatory standard and no named customer [S-2026-06-29-hiddenlayer-cohere-agentic].
  • The joint positioning targets “regulated industries and governments” wanting agentic AI that is “sovereign, secure, and fully under their control” (Cohere’s Nic Morales) [S-2026-06-29-hiddenlayer-cohere-agentic].
  • HiddenLayer maintains a financial-services solutions page (fraud detection, trading, customer-facing AI “while meeting strict regulatory requirements” — vendor site navigation, depth unexamined) [S-2026-06-29-hiddenlayer-cohere-agentic].
  • The agent harness — “the execution environments that enable AI agents to plan, reason, and take actions by connecting models with context, memory, tools, skills, and orchestration logic” — is a distinct runtime attack surface where indirect attacks steer agent behaviour, and therefore a distinct control point [S-2026-08-03-hiddenlayer-agent-harness-security].
  • Allow/block is insufficient for agentic control: security teams “need to control what agents see, reason over, and act on before something goes wrong” (CEO Chris Sestito), which HiddenLayer operationalises as content shaping — redacting secrets pre-model and injecting corrective context to steer agents off poisoned tool responses, letting the agent continue rather than halting a CI/CD run [S-2026-08-03-hiddenlayer-agent-harness-security].
  • Enforcement is bounded by the third-party agent platform: HiddenLayer states it “applies the strongest enforcement each platform supports” and reports per agent whether an action was “detected, redacted, blocked, or limited by the underlying agent platform” — an unusually candid disclosure of a control ceiling the firm does not own [S-2026-08-03-hiddenlayer-agent-harness-security].
  • Named customer reference (first for this vendor in the vault): Zivian Health — US healthcare, engineering-organisation use of coding agents; not a regulated-FS deployment [S-2026-08-03-hiddenlayer-agent-harness-security].
  • Positions itself as the AI-security layer for critical-infrastructure AI programmes: within DOE’s Prometheus it will contribute “securing AI systems against emerging threats and vulnerabilities”, building on prior work with government agencies to “identify AI risk, test AI systems for vulnerabilities, and protect AI models and applications against adversarial threats” — security framed as “foundational” to moving AI from research into nuclear-energy applications [S-2026-08-18-hiddenlayer-doe-prometheus].

Relationships

  • relates-to → Operational Resilience and Third-Party Risk — a well-capitalised, FS-concentrated AI-security supplier with EMEA expansion intent is a DORA ICT third-party / concentration-risk candidate for FS buyers [inference][S-2026-09-02-hiddenlayer-series-b].
  • partners-with → Databricks — named among “upcoming” AI-security integrations for Unity AI Gateway (roadmap, not shipped) [S-2026-07-13-databricks-unity-ai-gateway-refetch].
  • relates-to → AI Governance Platforms — supplies the runtime AI-security locus within the agentic-governance control architecture tracked there [S-2026-06-29-hiddenlayer-cohere-agentic].
  • relates-to → Model Risk Management and Agentic AI — runtime detection/logging for agents is adjacent to the agentic-MRM evidence question [inference].
  • relates-to → EU AI Act — the sovereignty/regulated-industries framing speaks to EU deployment concerns, though the release names no EU AI Act mapping [inference].

Tracked changes

  • 2026-09-02$100M Series B (lead Delta-v Capital; Ten Eleven Ventures, Morgan Stanley, M12, Booz Allen Ventures); total raised ~$150M per secondary coverage. Vendor claims >10x ARR growth and 50+ new platform customers across securities brokerage, banking, insurance, accounting, government, defence and others (none named); use of proceeds: Agentic Runtime Security, Agent Harness Security, channel, international expansion. TechCrunch: FS is the largest vertical; Europe/EMEA expansion planned [S-2026-09-02-hiddenlayer-series-b].
  • 2026-08-28 — Weekly synthesis read: two moves in one capture week (Prometheus, CRO) mark a commercial scale-up phase; only vendor to recur in the week to 28 Aug 2026 [S-2026-08-28-weekly-ai-governance-vendor-synthesis][inference].
  • 2026-06-29 — Announced collaboration with Cohere to secure the North agentic AI platform; explicit regulated-industries/sovereignty framing; no named customer [S-2026-06-29-hiddenlayer-cohere-agentic].
  • 2026-06 (undated listing) — Newsroom lists “HiddenLayer Joins Databricks Unity AI Gateway Ecosystem” and “New Agentic Runtime Security Capabilities” releases (not yet ingested); named an upcoming Unity AI Gateway integration in Databricks’ own post [S-2026-07-13-databricks-unity-ai-gateway-refetch].
  • 2026-08-18 — Selected as AI-security contributor to Prometheus, the INL-led US DOE Genesis Mission initiative ($60M Phase II over three years, subject to appropriations; first Phase II award under the Genesis Mission; consortium includes Oak Ridge, Argonne and Sandia plus 20+ industry partners) applying AI across nuclear reactor development/operations, fuel fabrication and legacy document management. Scope of work, commercial terms and any assurance-standard mapping unstated [S-2026-08-18-hiddenlayer-doe-prometheus].
  • 2026-08-12 — Appointed Mike Gesnaldo as Chief Revenue Officer, leading go-to-market organisations; release credits him with go-to-market scaling roles at CrowdStrike, Tanium and Dazz (vendor’s account, unverified) and names research, professional services and channel partners as the growth pillars. No financing, customer or standards content in the release [S-2026-08-12-hiddenlayer-cro-gesnaldo].
  • 2026-08-03 — Launched Agent Harness Security, available immediately as a stand-alone solution extending the Runtime Security module to AI coding agents: hook-surface integration, prompt-injection detection in files and tool outputs, pre-model secret redaction, poisoned-tool-response steering, unsafe-command and malicious-dependency detection, and per-agent enforcement-level reporting. First named customer (Zivian Health, US healthcare). No regulatory standard named [S-2026-08-03-hiddenlayer-agent-harness-security].

Open Questions

  • Which FS firms sit behind the “securities brokerage, banking, insurance” customer claim, and is Morgan Stanley a customer as well as an investor — unstated [S-2026-09-02-hiddenlayer-series-b].
  • What EU data-residency and DORA-contracting posture accompanies the planned EMEA expansion (runtime telemetry location, EU entity) — unaddressed [S-2026-09-02-hiddenlayer-series-b][inference].
  • No named EU/UK regulated-FS reference customer for the Cohere pairing, Agent Harness Security, or the platform generally (on evidence ingested so far) — the named references to date are Zivian Health (US healthcare) and now the DOE Prometheus programme (US public sector / nuclear energy), neither of them FS [S-2026-08-03-hiddenlayer-agent-harness-security][S-2026-08-18-hiddenlayer-doe-prometheus].
  • What HiddenLayer will actually secure within Prometheus (research models, pipelines, agentic systems?) and against what assurance criteria — unstated; the release names no NIST AI RMF or NRC framework mapping [S-2026-08-18-hiddenlayer-doe-prometheus]. Whether DOE’s treatment of independent AI security testing as a foundational programme control becomes a precedent FS supervisors expect for AI in critical functions (DORA ICT-resilience / EU AI Act Art. 15 robustness read-across) is an inference to watch, not a source claim [inference].
  • Whether “audit-ready visibility” maps to EU AIA Art. 12/14 or SS1/23 evidentiary thresholds — unstated by the vendor. The Agent Harness release does not close this: it specifies no retention period, format or immutability for its per-decision records [S-2026-08-03-hiddenlayer-agent-harness-security].
  • Commercial structure of the Cohere arrangement (integration vs joint GTM vs resale) — unstated.
  • Does the harness-layer control pattern generalise from coding agents (SDLC/change control) to the customer- and decision-facing agentic systems FS actually needs to govern? The release makes no such claim; treating it as model-risk tooling would be an over-read [inference].
  • Given HiddenLayer’s own admission that enforcement is capped by each agent platform’s hook surface, what residual risk does a firm carry when the strongest available enforcement on a given platform is “detect” rather than “block”, and how is that gap evidenced? [S-2026-08-03-hiddenlayer-agent-harness-security]

Sources

  • S-2026-09-02-hiddenlayer-series-b — Series B release (PR Newswire) plus TechCrunch coverage, both fetched in full (medium authority; funding facts corroborated, growth/customer claims vendor-asserted); supplies the financing, investor base, FS-concentration statement and EMEA intent.
  • S-2026-08-28-weekly-ai-governance-vendor-synthesis — weekly AI-governance vendor synthesis (own-writing, high authority); adds the market-level scale-up read across the Prometheus and CRO items, no new per-vendor facts.
  • HiddenLayer × Cohere — securing agentic AI for regulated industries (June 2026) — vendor press release, fetched directly (medium authority).
  • S-2026-07-13-databricks-unity-ai-gateway-refetch — Databricks blog (raw supplement); names HiddenLayer as an upcoming Unity AI Gateway integration.
  • S-2026-08-03-hiddenlayer-agent-harness-security — Agent Harness Security launch release, fetched in full from the vendor newsroom (medium authority; primary, self-interested, capability claims unverified, no regulatory standard named); supplies the harness-locus claim, the content-shaping mechanic, the enforcement-ceiling admission and the first named customer.
  • S-2026-08-18-hiddenlayer-doe-prometheus — DOE Prometheus selection release, PR Newswire, fetched in full (medium authority; primary vendor release, selection facts corroborated in outline by unfetched secondary coverage); supplies the critical-infrastructure programme engagement.
  • S-2026-08-12-hiddenlayer-cro-gesnaldo — CRO appointment release, fetched in full from the vendor newsroom (medium authority; primary and unambiguous on the appointment, self-interested on characterisations); supplies the leadership change and go-to-market scaling signal.