TL;DR: Nearly a third of organisations cannot confirm whether they have suffered an AI-related breach, and the funding underscores investor conviction that AI security must move from design-time controls to runtime protection, according to HiddenLayer; the company’s $100 million Series B reinforces a broader market shift toward securing agentic systems, where governance fails if behaviour, tool use, and action approval are not continuously verified.
NHIMG editorial — based on content published by HiddenLayer: HiddenLayer Raises $100M Series B to Advance Trustworthy AI
By the numbers:
- HiddenLayer reports that 96% of organisations already consider AI critical to core operations.
- HiddenLayer says its annual recurring revenue grew more than 10x in the past year.
Questions worth separating out
Q: How should security teams govern AI agents that can choose tools at runtime?
A: Security teams should govern runtime agent choice as an access event, not as a simple application action.
Q: Why do agentic AI systems create more risk when context is incomplete?
A: Because the system still has to decide whether a situation is real, expected, or safe to continue.
Q: What are the warning signs that an AI runtime security programme is failing?
A: Look for broad tool access, missing ownership for agents and connectors, weak audit trails, and AI actions that cannot be tied back to a clear task or policy decision.
Practitioner guidance
- Inventory AI runtime privileges List every tool, API, repository, database, and secret that each AI system can reach, then document whether access is read, write, or execute.
- Separate approval from execution paths Ensure human review, policy checks, and code or data actions do not share the same implicit trust path.
- Apply lifecycle controls to AI identities Register AI agents, connectors, and service accounts as governed identities with an owner, expiry, rotation rules, and revocation process.
What's in the full analysis
HiddenLayer's full news post covers the operational detail this analysis intentionally leaves for the source:
- The announced funding allocation across Agentic Runtime Security, Agent Harness Security, and broader platform development.
- The customer growth, ARR expansion, and market traction details behind the round.
- The specific product capabilities referenced for securing autonomous coding agents at runtime.
- The company’s own description of where its research and patent portfolio intersects with AI security deployment.
👉 Read HiddenLayer's announcement on its $100 million Series B for AI runtime security →
HiddenLayer's $100M Series B: what it means for AI governance?
Explore further
Runtime AI governance is now an identity problem, not only an AI problem. Once an AI system can call tools, access data, or write code, it behaves like a non-human runtime principal with delegated authority. That means lifecycle, entitlement, and audit controls matter as much as model evaluation. Organisations that manage AI security separately from IAM will miss the real control plane.
A question worth separating out:
Q: Should organisations use a dedicated AI agent identity model or extend current NHI controls?
A: Extend current NHI controls first, but only if they include ownership, scope, lifecycle, and revocation discipline. The mistake is treating AI agents as just another service account when they may combine permissions dynamically at runtime. A dedicated model is warranted when delegation chains span multiple applications and control ownership is unclear.
👉 Read our full editorial: HiddenLayer's $100M Series B signals tighter AI runtime security