HiddenLayer in the News
See how our research, leadership, and innovations are shaping the global conversation on AI security.


min read
HiddenLayer Releases the 2026 AI Threat Landscape Report, Spotlighting the Rise of Agentic AI and the Expanding Attack Surface of Autonomous Systems
HiddenLayer secures agentic, generative, and predictAutonomous agents now account for more than 1 in 8 reported AI breaches as enterprises move from experimentation to production.
March 18, 2026 – Austin, TX – HiddenLayer, the leading AI security company protecting enterprises from adversarial machine learning and emerging AI-driven threats, today released its 2026 AI Threat Landscape Report, a comprehensive analysis of the most pressing risks facing organizations as AI systems evolve from assistive tools to autonomous agents capable of independent action.
Based on a survey of 250 IT and security leaders, the report reveals a growing tension at the heart of enterprise AI adoption: organizations are embedding AI deeper into critical operations while simultaneously expanding their exposure to entirely new attack surfaces.
While agentic AI remains in the early stages of enterprise deployment, the risks are already materializing. One in eight reported AI breaches is now linked to agentic systems, signaling that security frameworks and governance controls are struggling to keep pace with AI’s rapid evolution. As these systems gain the ability to browse the web, execute code, access tools, and carry out multi-step workflows, their autonomy introduces new vectors for exploitation and real-world system compromise.
“Agentic AI has evolved faster in the past 12 months than most enterprise security programs have in the past five years,” said Chris Sestito, CEO and Co-founder of HiddenLayer. “It’s also what makes them risky. The more authority you give these systems, the more reach they have, and the more damage they can cause if compromised. Security has to evolve without limiting the very autonomy that makes these systems valuable.”
Other findings in the report include:
AI Supply Chain Exposure Is Widening
- Malware hidden in public model and code repositories emerged as the most cited source of AI-related breaches (35%).
- Yet 93% of respondents continue to rely on open repositories for innovation, revealing a trade-off between speed and security.
Visibility and Transparency Gaps Persist
- Over a third (31%) of organizations do not know whether they experienced an AI security breach in the past 12 months.
- Although 85% support mandatory breach disclosure, more than half (53%) admit they have withheld breach reporting due to fear of backlash, underscoring a widening hypocrisy between transparency advocacy and real-world behavior.
Shadow AI Is Accelerating Across Enterprises
- Over 3 in 4 (76%) of organizations now cite shadow AI as a definite or probable problem, up from 61% in 2025, a 15-point year-over-year increase and one of the largest shifts in the dataset.
- Yet only one-third (34%) of organizations partner externally for AI threat detection, indicating that awareness is accelerating faster than governance and detection mechanisms.
Ownership and Investment Remain Misaligned
- While many organizations recognize AI security risks, internal responsibility remains unclear with 73% reporting internal conflict over ownership of AI security controls.
- Additionally, while 91% of organizations added AI security budgets for 2025, more than 40% allocated less than 10% of their budget on AI security.
“One of the clearest signals in this year’s research is how fast AI has evolved from simple chat interfaces to fully agentic systems capable of autonomous action,” said Marta Janus, Principal Security Researcher at HiddenLayer. “As soon as agents can browse the web, execute code, and trigger real-world workflows, prompt injection is no longer just a model flaw. It becomes an operational security risk with direct paths to system compromise. The rise of agentic AI fundamentally changes the threat model, and most enterprise controls were not designed for software that can think, decide, and act on its own.”
What’s New in AI: Key Trends Shaping the 2026 Threat Landscape
Over the past year, three major shifts have expanded both the power, and the risk, of enterprise AI deployments:
- Agentic AI systems moved rapidly from experimentation to production in 2025. These agents can browse the web, execute code, access files, and interact with other agents—transforming prompt injection, supply chain attacks, and misconfigurations into pathways for real-world system compromise.
- Reasoning and self-improving models have become mainstream, enabling AI systems to autonomously plan, reflect, and make complex decisions. While this improves accuracy and utility, it also increases the potential blast radius of compromise, as a single manipulated model can influence downstream systems at scale.
- Smaller, highly specialized “edge” AI models are increasingly deployed on devices, vehicles, and critical infrastructure, shifting AI execution away from centralized cloud controls. This decentralization introduces new security blind spots, particularly in regulated and safety-critical environments.
The report finds that security controls, authentication, and monitoring have not kept pace with this growth, leaving many organizations exposed by default.
HiddenLayer’s AI Security Platform secures AI systems across the full AI lifecycle with four integrated modules: AI Discovery, which identifies and inventories AI assets across environments to give security teams complete visibility into their AI footprint; AI Supply Chain Security, which evaluates the security and integrity of models and AI artifacts before deployment; AI Attack Simulation, which continuously tests AI systems for vulnerabilities and unsafe behaviors using adversarial techniques; and AI Runtime Security, which monitors models in production to detect and stop attacks in real time.
Access the full report here.
About HiddenLayer
ive AI applications across the entire AI lifecycle, from discovery and AI supply chain security to attack simulation and runtime protection. Backed by patented technology and industry-leading adversarial AI research, our platform is purpose-built to defend AI systems against evolving threats. HiddenLayer protects intellectual property, helps ensure regulatory compliance, and enables organizations to safely adopt and scale AI with confidence.
Contact
SutherlandGold for HiddenLayer
hiddenlayer@sutherlandgold.com

min read
HiddenLayer Recognized as a Gartner Cool Vendor for AI Security in 2024
HiddenLayer’s proactive solutions ensure organizations can rely on comprehensive and resilient AI systems in an era of accelerated AI adoption. Gartner's recognition underscores the company’s expertise and leadership in the AI security space, setting a benchmark for the industry as enterprises increasingly turn to cutting-edge solutions to protect sensitive AI systems and data.
Austin, TX – October 30, 2024 – HiddenLayer, a leader in security for AI solutions, is honored to be recognized as a Cool Vendor for AI Security in Gartner’s 2024 report. This prestigious distinction highlights HiddenLayer's innovative approaches to safeguarding artificial intelligence models, data, and workflows against a rapidly evolving threat landscape.
HiddenLayer’s proactive solutions ensure organizations can rely on comprehensive and resilient AI systems in an era of accelerated AI adoption. Gartner's recognition underscores the company’s expertise and leadership in the AI security space, setting a benchmark for the industry as enterprises increasingly turn to cutting-edge solutions to protect sensitive AI systems and data.
“Being named a Gartner Cool Vendor for AI Security validates our vision and the critical work our team has undertaken to provide organizations with sophisticated tools that address real-world AI threats,” said Chris Sestito, CEO of HiddenLayer. “This acknowledgment strengthens our commitment to staying ahead of adversarial attacks and ensuring safe AI deployment for our clients and partners.”
HiddenLayer’s innovative solutions encompass capabilities tailored to address unique security challenges in machine learning and artificial intelligence. HiddenLayer empowers businesses to fortify their AI assets without compromising on performance or innovation by focusing on AI integrity and model protection.
The Cool Vendor recognition reinforces HiddenLayer’s momentum as a leader in AI security, following recent achievements such as receiving the SINET16 Innovators award and being recognized as an AI Standout at the A-List Austin awards. These honors reflect HiddenLayer's continued dedication to advancing AI security standards and ensuring secure AI adoption on a global scale.
For organizations looking to safeguard their AI models and tools, HiddenLayer offers an unparalleled solution grounded in resilience and adaptability to modern security demands.
About HiddenLayer
HiddenLayer is the leading provider of Security for AI. Its security platform helps enterprises safeguard the machine learning models behind their most important products. HiddenLayer is the only company to offer turnkey security for AI that does not add unnecessary complexity to models and does not require access to raw data and algorithms. Founded by a team with deep roots in security and ML, HiddenLayer aims to protect enterprise AI from inference, bypass, extraction attacks, and model theft. The company is backed by a group of strategic investors, including M12, Microsoft's Venture Fund, Moore Strategic Ventures, Booz Allen Ventures, IBM Ventures, and Capital One Ventures.
Contact
Maia Gryskiewicz
SutherlandGold for HiddenLayer
hiddenlayer@sutherlandgold.com

min read
HiddenLayer Announces New Features to Safeguard Enterprise AI Models with Improved Risk Detection
HiddenLayer today announced the launch of several new features to its AISec Platform and Model Scanner, designed to enhance risk detection, scalability, and operational control for enterprises deploying AI at scale. As the pace of AI adoption accelerates, so do the threats targeting these systems, necessitating security measures that stay ahead of increasingly sophisticated adversaries. These updates to HiddenLayer’s platform allow organizations to deploy AI models more securely across diverse environments while mitigating critical risks.
Austin, TX – October 8, 2024 – HiddenLayer today announced the launch of several new features to its AISec Platform and Model Scanner, designed to enhance risk detection, scalability, and operational control for enterprises deploying AI at scale. As the pace of AI adoption accelerates, so do the threats targeting these systems, necessitating security measures that stay ahead of increasingly sophisticated adversaries. These updates to HiddenLayer’s platform allow organizations to deploy AI models more securely across diverse environments while mitigating critical risks.
“It’s vital that security providers keep pace with the bad actors–especially in enterprise environments, where we bear the responsibility of safeguarding our customers’ most critical assets,” said Chris Sestito, CEO and Co-Founder of HiddenLayer. “These new capabilities increase risk detection across the board and enable us to better serve and protect customers with more flexible and scalable options.”
AISec Platform: Enterprise-Ready Security and User Management
In addition to enhanced detection capabilities, HiddenLayer’s AISec Platform, which provides detection and response for AI models, is now equipped with advanced tools for managing large-scale enterprise deployments. These include comprehensive user management features and secure integration with existing enterprise infrastructure:
- User Management: Enterprises can now easily manage tenant users, including creating, editing, and deleting user accounts. This capability strengthens internal control and access management across large organizations.
- SAML SSO: A fully integrated Single Sign-On (SSO) and Role-Based Access Control (RBAC) experience ensures administrators can securely and efficiently assign roles and permissions. The SSO integration further enhances enterprise readiness by streamlining access for larger teams.
Enterprises are facing increased pressure to adopt AI technologies while simultaneously navigating a growing landscape of digital threats. HiddenLayer’s new features allow companies to confidently scale their AI initiatives without sacrificing security or efficiency, providing a competitive edge in industries where trust and innovation are key.
“The security frameworks established by organizations like ATLAS and NIST are invaluable resources—some of which we’ve had the privilege to help shape. By integrating well-established security frameworks into our solutions, we’re able to provide even stronger, more adaptable protection to our customers. In a world where AI plays a crucial role in day-to-day business operations, safeguarding these models is mission-critical.” said Malcolm Harkins, Chief Security & Trust Officer of HiddenLayer.
Model Scanner: Increased Scalability and Risk Detection
As AI continues to become an integral part of the digital supply chain, enterprises must ensure that every component of AI-driven systems is secure from development to deployment. HiddenLayer’s Model Scanner reduces the risk of adversarial attacks, with new updates offering enhanced deployment options and seamless integration into continuous integration/continuous deployment (CI/CD) pipelines.
Introducing Model Risk Context: Heightened Detection Risk Context
These updates include Model Risk Context, which enhances the depth of risk detection by mapping identified threats to widely recognized industry frameworks such as OWASP, ATLAS, and NIST. This level of visibility equips organizations with a holistic understanding of potential risks, enabling them to make informed security decisions based on the risk profile of AI models. Other updates include:
- Static Analysis Results Interchange Format (SARIF): The platform now outputs SARIF from its API, allowing integration with tools like GitHub Advanced Security that support the Static Analysis Results Interchange Format (SARIF).
- Local Model Scanning: Users can now conduct ad-hoc scans on local models, offering greater flexibility for proprietary or offline AI assets.
- CLI Object Storage Support: This feature allows enterprises to scan models stored in AWS S3 and Azure Blob, enhancing versatility for organizations operating across multiple cloud environments.
With new integrations such as JFrog Artifactory and GitHub Actions, and the ability to scan models directly from the terminal, the Model Scanner ensures that security is embedded into every phase of AI development. Enterprises using Google Cloud Platform (GCP) can also benefit from a fully self-hosted deployment option, giving them complete control over their AI security infrastructure.
HiddenLayer’s platform signals a fundamental shift in how enterprises secure their AI environments. With risk detection that maps to industry standards, seamless integration into existing workflows, and tools for flexible deployment, HiddenLayer is setting the new standard for AI security. To see how HiddenLayer's Security for AI solutions can protect your enterprise, visit the Microsoft Azure Marketplace or explore our latest Product Blog.

min read
HiddenLayer Announces Mike Bruchanski as Chief Product Officer
“Mike’s breadth of experience across the B2B enterprise software lifecycle will be critical as HiddenLayer executes on its mission to protect the machine learning models behind today’s most important products,” said Chris Sestito, CEO and Co-founder of HiddenLayer. “His expertise will play a key role in accelerating our product roadmap and enhancing our ability to defend enterprises’ AI models against various threats.”
Austin, TX - August 27, 2024 – HiddenLayer today announced the appointment of Mike Bruchanski as Chief Product Officer. Bruchanski brings over two decades of product and engineering experience to HiddenLayer, where he will drive the company’s product strategy and pipeline, and accelerate its mission to support customers’ adoption of generative and predictive AI.
“Mike’s breadth of experience across the B2B enterprise software lifecycle will be critical as HiddenLayer executes on its mission to protect the machine learning models behind today’s most important products,” said Chris Sestito, CEO and Co-founder of HiddenLayer. “His expertise will play a key role in accelerating our product roadmap and enhancing our ability to defend enterprises’ AI models against various threats.”
Bruchanski joins HiddenLayer from Elementary, where he was Vice President of Product, driving the advancement of the company's offerings and market growth. Previously, he held similar roles at Blue Lava, Inc., where he shaped the product vision and strategy, and at Cylance, where he managed the company’s portfolio of OEM products and partners.
With a strong foundation in engineering, holding degrees from Villanova University and Embry-Riddle Aeronautical University, Mike combines a technical background with experience in scaling organizations’ product strategies. His leadership will be invaluable as HiddenLayer continues to innovate and protect AI-driven systems.
“The acceleration of AI has introduced new vulnerabilities and risks in cybersecurity. I’m excited to join the talented team at HiddenLayer to develop solutions that meet the complex challenges facing enterprise customers today,”
said Bruchanski.
About HiddenLayer
HiddenLayer is the leading provider of security for AI. Its security platform helps enterprises safeguard the machine learning models behind their most important products. HiddenLayer is the only company to offer turnkey security for AI that does not add unnecessary complexity to models and does not require access to raw data and algorithms. Founded by a team with deep roots in security and ML, HiddenLayer aims to protect enterprise AI from inference, bypass, extraction attacks, and model theft. The company is backed by a group of strategic investors, including M12, Microsoft’s Venture Fund, Moore Strategic Ventures, Booz Allen Ventures, IBM Ventures, and Capital One Ventures.

min read
HiddenLayer Joins the Coalition for Secure AI
“AI has never been easier to develop, use, and implement within organizations. As deployment continues to surge, so does the need to adopt common security standards and best practices in AI security,” said Malcolm Harkins, Chief Security & Trust Officer, HiddenLayer. “HiddenLayer is proud to join the CoSAI in our shared mission to support the widespread adoption of AI security principles.”
Austin, TX - August 06, 2024 – HiddenLayer today announced it has joined the Coalition for Secure AI (CoSAI), a new initiative aimed at tackling the cybersecurity risks associated with artificial intelligence (AI). Hosted by the OASIS global standards body, CoSAI is an open-source initiative designed to give all practitioners and developers the guidance and tools they need to create Secure-by-Design AI systems. HiddenLayer will be engaged in all of CoSAI’s priority initiatives, and an active part of its ecosystem to share open-source methodologies, standardized frameworks, and tools.
“AI has never been easier to develop, use, and implement within organizations. As deployment continues to surge, so does the need to adopt common security standards and best practices in AI security,” said Malcolm Harkins, Chief Security & Trust Officer, HiddenLayer. “HiddenLayer is proud to join the CoSAI in our shared mission to support the widespread adoption of AI security principles.”
The coalition’s initial focus will be on three main areas:
- Software supply chain security for AI systems: enhancing composition and provenance tracking to secure AI applications.
- Preparing defenders for a changing cybersecurity landscape: addressing investments and integration challenges in AI and classical systems.
- AI security governance: developing best practices and risk assessment frameworks for AI security.
Housed under OASIS Open, the international standards and open source consortium, CoSAI includes founding members such as Amazon, Anthropic, Chainguard, Cisco, Cohere, GenLab, IBM, Intel, Microsoft, NVIDIA, OpenAI, PayPal, and Wiz.
“As a founding member and co-chair of CoSAI, I am thrilled to have HiddenLayer join us,” said Omar Santos, Security & Trust Organization, Cisco Systems. “With HiddenLayer’s technical expertise and collaboration, we are eager to help organizations around the world to address emerging threats more effectively.”
For more information about CoSAI, visit https://www.coalitionforsecureai.org/.
About HiddenLayer
HiddenLayer is the leading provider of security for AI. Its security platform helps enterprises safeguard the machine learning models behind their most important products. HiddenLayer is the only company to offer turnkey security for AI that does not add unnecessary complexity to models and does not require access to raw data and algorithms. Founded by a team with deep roots in security and ML, HiddenLayer aims to protect enterprise AI from inference, bypass, extraction attacks, and model theft. The company is backed by a group of strategic investors, including M12, Microsoft’s Venture Fund, Moore Strategic Ventures, Booz Allen Ventures, IBM Ventures, and Capital One Ventures.

min read
HiddenLayer Joins Center for Threat-Informed Defense in Research Initiative to Secure AI Systems
HiddenLayer is proud to announce its participation in the Secure AI project, a new research initiative by the Center for Threat-Informed Defense. Through this collaborative project, HiddenLayer will advance its mission to protect AI-enabled systems by contributing technical expertise and resources to the MITRE ATLAS™.
HiddenLayer is proud to announce its participation in the Secure AI project, a new research initiative by the Center for Threat-Informed Defense. Through this collaborative project, HiddenLayer will advance its mission to protect AI-enabled systems by contributing technical expertise and resources to the MITRE ATLAS™.
"We are excited to be part of this project and contribute to the expansion of the ATLAS framework,” said Tom Bonner, Vice President of Research at HiddenLayer. “Community-driven knowledge bases like ATLAS are essential resources for securing AI-enabled systems and supply chains against attacks."
MITRE ATLAS is a knowledge base of adversarial machine learning tactics, techniques, and case studies designed to help cybersecurity professionals, data scientists, and their companies stay up to date on the latest attacks and defenses against adversarial machine learning. The ATLAS matrix is modeled after and complementary to the MITRE ATT&CK framework, which is well-known and used in the cybersecurity industry to understand attack chains and adversary behaviors.
HiddenLayer joins a diverse group of industry leaders from communications, finance, healthcare, and technology sectors, such as Microsoft Corporation, Booz Allen Hamilton, Intel, and JPMorgan Chase Bank, N.A., who are contributing their expertise and resources to develop this vital community resource.
The Secure AI project aims to:
- Expand the ATLAS knowledge base through incident sharing metrics and mechanisms.
- Document new case studies within ATLAS that address vulnerabilities in industry-relevant systems, including generative AI.
- Describe new relevant mitigations based on documented AI incidents.
- Align ATLAS tactics, techniques, and procedures (TTPs) with the current version of MITRE ATT&CK TTPs.
"We welcome HiddenLayer to the Secure AI project and know their deep expertise in AI model security research will be invaluable in enhancing the ATLAS and addressing the unique challenges posed by AI-enabled systems,” said Jon Baker, Director of the Center for Threat-Informed Defense.
HiddenLayer's participation in this initiative aligns with its core mission to secure AI models and contribute to collaborative research communities. By joining forces with MITRE and other industry leaders, HiddenLayer aims to bolster the defenses of AI systems globally.
For more information about the Secure AI research project, visit the Center for Threat-Informed Defense.
About HiddenLayer
HiddenLayer is the leading provider of security for AI. Its security platform helps enterprises safeguard the machine learning models behind their most important products. HiddenLayer is the only company to offer turnkey security for AI that does not add unnecessary complexity to models and does not require access to raw data and algorithms. Founded by a team with deep roots in security and ML, HiddenLayer aims to protect enterprise AI from inference, bypass, extraction attacks, and model theft. The company is backed by a group of strategic investors, including M12, Microsoft’s Venture Fund, Moore Strategic Ventures, Booz Allen Ventures, IBM Ventures, and Capital One Ventures.
About the Center for Threat-Informed Defense
The Center is a non-profit, privately funded research and development organization operated by MITRE Engenuity. The Center’s mission is to advance the state of the art and the state of the practice in threat-informed defense globally. Comprised of participant organizations from around the globe with highly sophisticated security teams, the Center builds on MITRE ATT&CK®, an important foundation for threat-informed defense used by security teams and vendors in their enterprise security operations. Because the Center operates for the public good, outputs of its research and development are available publicly and for the benefit of all.
Let’s Secure AI Together
Join HiddenLayer in shaping the standards, defenses, and future of AI security. Whether you’re a researcher, partner, or enterprise innovator, we’re stronger together.




