Trust in AI finds a new paymaster

HiddenLayer's $100m came from a bank and a defense contractor, the parties that pay when a model fails

// Share
Trust in AI finds a new paymaster

Morgan Stanley does not, as a rule, invest in three-year-old security startups. On September 2nd it did. HiddenLayer, an Austin company that sells security for AI models and agents, announced a $100m Series B led by Delta-v Capital, a growth investor, with Ten Eleven Ventures, Microsoft's M12 and Booz Allen Ventures alongside — the expected cast for a security round. Morgan Stanley's strategic-investment group is not part of that cast, and it sits next to Booz Allen Hamilton, by its own description the largest provider of AI services to the federal government, which first bought in three years ago and has now come back for more. Neither is an AI-native investor, and neither has said it is here because the category is fashionable.

HiddenLayer's product is built for that customer. The company scans model files across some 50 formats to confirm that an open-weight model is what it claims to be (Chris Sestito, HiddenLayer's chief executive, describes the failure case as "hidden models inside of models"), watches inference at runtime the way endpoint tools watch a laptop, and runs automated red-teaming, all without access to a customer's weights or training data. In December it was named an awardee on the Missile Defense Agency's $151bn SHIELD contract vehicle, the acquisition pipe for Golden Dome, on the strength of an air-gapped version built for classified networks. Annual recurring revenue grew more than tenfold in the past year to the tens of millions, over 90% of it from new customers, and the list now includes a frontier lab with more than 700m weekly users, which narrows the field to two. "Inference is still inference," Sestito told TechCrunch, which is the modest way of saying the company did not have to pivot when the market moved from classifiers to agents.

Trust fund

The week HiddenLayer closed, the other kind of trust in AI came apart in public. On August 27th Rita Lin, a federal judge in San Francisco, ruled that the Pentagon's designation of Anthropic as a supply-chain risk had been retaliation for the company's refusal to allow its models to be used for domestic surveillance and autonomous weapons. The designation had hitherto been reserved for the likes of Huawei and Kaspersky; it exists for the fear that a supplier will sabotage what it ships. Lin noted that the department kept pursuing work with Anthropic after branding it a threat, and wrote that none of this was consistent with a genuine fear the company would poison its own software. Within the week Howard Lutnick, the commerce secretary, told Axios that Anthropic was "back on the right side" and that "they've done what we asked," while Tom Brown, an Anthropic co-founder, stood beside him at a G20 ministerial and praised a Trump post about data centers.

Anthropic's weights did not change between the blacklist and the endorsement. Its posture did, and so did the administration's, and the government's verdict on the most safety-branded lab in the industry tracked those and nothing else. The Pentagon had reached for the vocabulary of model integrity, poisoning and supply-chain risk, to settle a dispute about use policy, and a court found it could not substantiate the technical claim. Two kinds of trust have now come apart: whether a lab will do what the state asks, which is politics, and whether a model does what its file says it does, which is engineering. The lab cannot certify the second, since it is the party being judged, and the state has shown it will put the engineering words to political use. That is the gap into which a company selling a scan of the file has just raised $100m.

This has happened before, and the precedent explains the syndicate. In 1894 William Henry Merrill, a 25-year-old electrical engineer out of MIT, set up in Chicago the testing operation that became Underwriters Laboratories, and the people who paid for it were the Chicago Board of Fire Underwriters and the Western Insurance Association. Manufacturers of electrical goods could not credibly vouch for their own wiring; no government body yet did; the insurers were the ones settling claims after the fire. So the parties bearing the loss financed the lab, and in time the UL mark became a condition of coverage and then a condition of sale. The referee in a market for trust is funded by whoever eats the downside, and the maker's own assurances are worth roughly what an underwriter would guess.

Read the cap table that way and the odd names explain themselves, in their own words. Zheng Wang, who runs strategic investments at Morgan Stanley, described the investment as backing "compliant AI adoption," which is what a bank running open-weight models against customer data needs before a regulator asks. Booz Allen said in 2023 that "every AI-enabled solution should be assessed for risk" before it reaches its Defense Department and intelligence clients, and it has now paid twice for the assessor. HiddenLayer lists securities brokerage and banking among its largest verticals. Gartner, a research firm, expects $2.83bn of spending on securing AI this year and a further 69% rise next year; those are the premiums. The frontier-lab customer completes the picture, because a manufacturer submitting its own deployment to an outside lab is the UL moment, the point at which self-certification stops being enough even for the party that wrote the model.

Two things separate HiddenLayer from Merrill's lab, and both cut against the round. UL could take the toaster apart. HiddenLayer certifies from the outside, without weights or training data, so its verdict covers the file and the behavior at inference and nothing about how the model came to be; that is thinner than a lab's own red team and thinner than what a court would want before it let anyone call a supplier a saboteur. And the insurers who funded UL had no ambition to sell toasters, whereas HiddenLayer's paymasters include the players. M12 is Microsoft; the lab is a customer; Sestito himself concedes that parts of the product could end up bundled into the platforms of Microsoft, OpenAI and AWS. The incumbents have already shown their preference, with Cisco buying Robust Intelligence, Palo Alto Networks buying Protect AI and Check Point buying Lakera. A referee that can be bought by one of the teams is a feature waiting for a term sheet.

For now the money is doing what the insurers' money did in 1894, paying an outsider to say what the maker cannot say for itself and the state has proved it will say for reasons of its own. Between August 27th and September 2nd Anthropic's standing with the government reversed and its models did not, and HiddenLayer's customers are paying for the part of that sentence that stays put.

// The Daily

Get Vector in your inbox.

A free morning briefing on the AI revolution. Weekdays at 6am CT.