HiddenLayer in the News
See how our research, leadership, and innovations are shaping the global conversation on AI security.


min read
HiddenLayer Releases the 2026 AI Threat Landscape Report, Spotlighting the Rise of Agentic AI and the Expanding Attack Surface of Autonomous Systems
HiddenLayer secures agentic, generative, and predictAutonomous agents now account for more than 1 in 8 reported AI breaches as enterprises move from experimentation to production.
March 18, 2026 – Austin, TX – HiddenLayer, the leading AI security company protecting enterprises from adversarial machine learning and emerging AI-driven threats, today released its 2026 AI Threat Landscape Report, a comprehensive analysis of the most pressing risks facing organizations as AI systems evolve from assistive tools to autonomous agents capable of independent action.
Based on a survey of 250 IT and security leaders, the report reveals a growing tension at the heart of enterprise AI adoption: organizations are embedding AI deeper into critical operations while simultaneously expanding their exposure to entirely new attack surfaces.
While agentic AI remains in the early stages of enterprise deployment, the risks are already materializing. One in eight reported AI breaches is now linked to agentic systems, signaling that security frameworks and governance controls are struggling to keep pace with AI’s rapid evolution. As these systems gain the ability to browse the web, execute code, access tools, and carry out multi-step workflows, their autonomy introduces new vectors for exploitation and real-world system compromise.
“Agentic AI has evolved faster in the past 12 months than most enterprise security programs have in the past five years,” said Chris Sestito, CEO and Co-founder of HiddenLayer. “It’s also what makes them risky. The more authority you give these systems, the more reach they have, and the more damage they can cause if compromised. Security has to evolve without limiting the very autonomy that makes these systems valuable.”
Other findings in the report include:
AI Supply Chain Exposure Is Widening
- Malware hidden in public model and code repositories emerged as the most cited source of AI-related breaches (35%).
- Yet 93% of respondents continue to rely on open repositories for innovation, revealing a trade-off between speed and security.
Visibility and Transparency Gaps Persist
- Over a third (31%) of organizations do not know whether they experienced an AI security breach in the past 12 months.
- Although 85% support mandatory breach disclosure, more than half (53%) admit they have withheld breach reporting due to fear of backlash, underscoring a widening hypocrisy between transparency advocacy and real-world behavior.
Shadow AI Is Accelerating Across Enterprises
- Over 3 in 4 (76%) of organizations now cite shadow AI as a definite or probable problem, up from 61% in 2025, a 15-point year-over-year increase and one of the largest shifts in the dataset.
- Yet only one-third (34%) of organizations partner externally for AI threat detection, indicating that awareness is accelerating faster than governance and detection mechanisms.
Ownership and Investment Remain Misaligned
- While many organizations recognize AI security risks, internal responsibility remains unclear with 73% reporting internal conflict over ownership of AI security controls.
- Additionally, while 91% of organizations added AI security budgets for 2025, more than 40% allocated less than 10% of their budget on AI security.
“One of the clearest signals in this year’s research is how fast AI has evolved from simple chat interfaces to fully agentic systems capable of autonomous action,” said Marta Janus, Principal Security Researcher at HiddenLayer. “As soon as agents can browse the web, execute code, and trigger real-world workflows, prompt injection is no longer just a model flaw. It becomes an operational security risk with direct paths to system compromise. The rise of agentic AI fundamentally changes the threat model, and most enterprise controls were not designed for software that can think, decide, and act on its own.”
What’s New in AI: Key Trends Shaping the 2026 Threat Landscape
Over the past year, three major shifts have expanded both the power, and the risk, of enterprise AI deployments:
- Agentic AI systems moved rapidly from experimentation to production in 2025. These agents can browse the web, execute code, access files, and interact with other agents—transforming prompt injection, supply chain attacks, and misconfigurations into pathways for real-world system compromise.
- Reasoning and self-improving models have become mainstream, enabling AI systems to autonomously plan, reflect, and make complex decisions. While this improves accuracy and utility, it also increases the potential blast radius of compromise, as a single manipulated model can influence downstream systems at scale.
- Smaller, highly specialized “edge” AI models are increasingly deployed on devices, vehicles, and critical infrastructure, shifting AI execution away from centralized cloud controls. This decentralization introduces new security blind spots, particularly in regulated and safety-critical environments.
The report finds that security controls, authentication, and monitoring have not kept pace with this growth, leaving many organizations exposed by default.
HiddenLayer’s AI Security Platform secures AI systems across the full AI lifecycle with four integrated modules: AI Discovery, which identifies and inventories AI assets across environments to give security teams complete visibility into their AI footprint; AI Supply Chain Security, which evaluates the security and integrity of models and AI artifacts before deployment; AI Attack Simulation, which continuously tests AI systems for vulnerabilities and unsafe behaviors using adversarial techniques; and AI Runtime Security, which monitors models in production to detect and stop attacks in real time.
Access the full report here.
About HiddenLayer
ive AI applications across the entire AI lifecycle, from discovery and AI supply chain security to attack simulation and runtime protection. Backed by patented technology and industry-leading adversarial AI research, our platform is purpose-built to defend AI systems against evolving threats. HiddenLayer protects intellectual property, helps ensure regulatory compliance, and enables organizations to safely adopt and scale AI with confidence.
Contact
SutherlandGold for HiddenLayer
hiddenlayer@sutherlandgold.com

min read
HiddenLayer Launches Channel Partner Program to Secure AI and MLOps Lifecycle
HiddenLayer, the leading security provider for artificial intelligence (AI) models and assets, today announced a new partner program to empower enterprises with complete AI protection including rapid threat detection and security across the entire MLOps lifecycle.
HiddenLayer bolsters its offerings after earning a spot on the CRN® 2023 Stellar Startups List
AUSTIN, Texas - January 23, 2024 - HiddenLayer, the leading security provider for artificial intelligence (AI) models and assets, today announced a new partner program to empower enterprises with complete AI protection including rapid threat detection and security across the entire MLOps lifecycle.
“Our Channel Partner Program is designed to drive innovation by allowing partners to introduce security for AI to their customers, helping to educate more businesses about a new threat landscape,” said Rebecca Cahak, Head of Channel, HiddenLayer. “By leveraging this new offering, partners will ensure margin and deal protection, leverage incentives, access flexible and easy-to-use training tools, demo environments, and proof of value tools to drive success.”
The Channel Partner Program allows partners to seamlessly onboard while providing predictable, transparent pricing and flexible licensing models, and a first-of-its-kind unobtrusive, automated, scalable Artificial Intelligence Security (AISec) Platform. Partners will be able to educate customers on a new threat landscape and provide the solutions they need to protect their AI, and competitive edge, build stronger relationships, and establish their team as AI leaders for their customers.
"The HiddenLayer line of products is an important component in our AI security service offerings,” said Matt Keating, Head of AI Security at Booz Allen Hamilton. “We are excited to continue to strengthen our strategic partnership with the HiddenLayer team, furthering our ability for joint strategy and co-solutioning.”
HiddenLayer aims to optimize its current partner network, enhancing it through streamlined support and collaborative offerings. There will be three tiers for the program, Covert, Concealed, and Clandestine, so customers can work together with HiddenLayer to achieve the best-shared outcome. Each tier includes pricing discounts, free online training for sales, and technical enablement and security for AI marketing partnerships. Concealed includes free on-site training and performance incentive programs for extra financial success. Clandestine includes everything previously mentioned, with the addition of account mapping, executive security research briefings, and more.
“By joining HiddenLayer’s partner program, we’re enabling customers to safeguard against constantly evolving cybersecurity risks,” said Rick Echevarria, Vice President and General Manager, Intel Security Center of Excellence. “We are now able to provide a scalable security solution for AI and help more businesses foster the acceleration of safer AI adoption.”
Additionally, HiddenLayer recently announced that CRN®, a brand of The Channel Company, named HiddenLayer to its 2023 Stellar Startups list. This annual list, previously known as CRN Emerging Vendors, recognizes fast-rising technology manufacturers committed to delivering leading-edge solutions that propel innovation and growth in the IT channel.
Learn more about HiddenLayer’s Channel Partner Program here.
About HiddenLayer
HiddenLayer, a Gartner-recognized AI Application Security company, helps enterprises safeguard the machine learning models behind their most important products with a comprehensive security platform. Only HiddenLayer offers turnkey security for AI that does not add unnecessary complexity to models and does not require access to raw data and algorithms. Founded in March of 2022 by experienced security and ML professionals, HiddenLayer is based in Austin, Texas. For additional information, including product updates and the latest research reports, visit www.hiddenlayer.com.
Contacts
Hannah Williams
SutherlandGold for HiddenLayer
hiddenlayer@sutherlandgold.com

min read
HiddenLayer is a proud participant in the Microsoft Security Copilot Partner Private Preview
Today announced its participation in the Microsoft Security Copilot Partner Private Preview. HiddenLayer was selected based on their proven experience with Microsoft Security technologies, willingness to explore and provide feedback on cutting edge functionality, and close relationship with Microsoft.
AUSTIN, Texas - January 9, 2024 - HiddenLayer today announced its participation in the Microsoft Security Copilot Partner Private Preview. HiddenLayer was selected based on their proven experience with Microsoft Security technologies, willingness to explore and provide feedback on cutting edge functionality, and close relationship with Microsoft.
“AI is one of the defining technologies of our time and has the potential to drive meaningful, step-change progress in cybersecurity,” said Ann Johnson, Corporate Vice President, Microsoft Security Business Development. “Security is a team sport, and we are pleased to work alongside our Security Copilot partner ecosystem to deliver customers solutions that enhance cyber defenses and make the promise of AI real.”
HiddenLayer is working with Microsoft product teams to help shape Security Copilot product development in several ways, including validation and refinement of new and upcoming scenarios, providing feedback on product development and operations to be incorporated into future product releases, and validation and feedback of APIs to assist with Security Copilot extensibility.
“Microsoft has long been a champion of cybersecurity and AI, and HiddenLayer shares a common commitment to securing AI and machine learning models through the application of traditional cybersecurity techniques,” said Abigail Maines, Chief Revenue Officer, HiddenLayer. “Our participation in the Security Copilot’s capabilities will bolster the protection of enterprises’ most important technology, and give us the opportunity to influence and shape product development throughout the space.”
Security Copilot is the first AI-powered security product that enables security professionals to respond to threats quickly, process signals at machine speed, and assess risk exposure in minutes. It combines an advanced large language model (LLM) with a security-specific model that is informed by Microsoft's unique global threat intelligence and more than 65 trillion daily signals.
About HiddenLayer:
HiddenLayer, a Gartner-recognized AI Application Security company, helps enterprises safeguard the machine learning models behind their most important products with a comprehensive security platform. Only HiddenLayer offers turnkey security for AI that does not add unnecessary complexity to models and does not require access to raw data and algorithms. Founded in March of 2022 by experienced security and ML professionals, HiddenLayer is based in Austin, Texas. For additional information, including product updates and the latest research reports, visit www.hiddenlayer.com.
For additional information:
David Sack
SutherlandGold for HiddenLayer
hiddenlayer@sutherlandgold.com
Product or service names mentioned herein may be the trademarks of their respective owners.

min read
HiddenLayer Partners with CVE Program as a Numbering Authority to Secure AI
The leading security provider for artificial intelligence (AI) models and assets, proudly announces its partnership with the Common Vulnerabilities and Exposures (CVE®) Program as a CVE Numbering Authority (CNA), reinforcing our commitment to enhancing AI system security.
Underscoring commitment to elevating Security for AI standards
AUSTIN, Texas — Dec 19, 2023 — HiddenLayer, the leading security provider for artificial intelligence (AI) models and assets, proudly announces its partnership with the Common Vulnerabilities and Exposures (CVE®) Program as a CVE Numbering Authority (CNA), reinforcing our commitment to enhancing AI system security.
HiddenLayer joins over 300 organizations across 37 countries, authorized by the CVE Program to assign CVE IDs to vulnerabilities within their specific scopes, enabling the efficient collaboration of multiple parties to address known AI security risks.
Each CNA has a specific Scope of responsibility for vulnerability identification and publishing. HiddenLayer is now authorized to assign CVEs to new zero-day vulnerabilities in both third-party software that does not fall under the scope of another CNA, and within their own products. This enables HiddenLayer in its mission to help protect the world’s most valuable technology, Artificial Intelligence.
“Being acknowledged as a CNA underscores HiddenLayer’s dedication and responsibility towards enhancing security for AI,” said Tom Bonner, VP of Research of HiddenLayer. “With the recent proliferation of machine learning and artificial intelligence, it is imperative that organizations have a complete awareness of the risks posed by insecure libraries, applications, and services. By researching and reporting vulnerabilities in critical ML and AI systems, HiddenLayer is underlining our commitment to help advance the security posture for the entire industry.”
The CVE Program, sponsored by the Cybersecurity and Infrastructure Security Agency (CISA) of the U.S. Department of Homeland Security (DHS), aims to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. The CVE Program is community-driven and is steered by an international board of industry, academic, and government representatives.
HiddenLayer offers a comprehensive suite of products through its AISec Platform to safeguard AI models from adversarial attacks, vulnerabilities, and malicious code injections. In addition, HiddenLayer collaborates with clients, providing consulting services leveraging deep domain expertise in cybersecurity, artificial intelligence, reverse engineering, and threat research.
HiddenLayer’s Adversarial Machine Learning (AdvML) experts empower cybersecurity teams and data scientists with knowledge, insight, and tools to integrate security into the MLOps Pipeline, understand the latest adversarial AI tactics and countermeasures, map the current AI threat landscape, develop high-impact attack scenarios, validate AI environments, and implement operational security controls that satisfy both data science and security teams’ needs.
About the CVE Program
The mission of the Common Vulnerabilities and Exposures (CVE®) Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. There is one CVE Record for each vulnerability in the catalog. The vulnerabilities are discovered then assigned and published by organizations from around the world that have partnered with the CVE Program. Partners publish CVE Records to communicate consistent descriptions of vulnerabilities. Information technology and cybersecurity professionals use CVE Records to ensure they are discussing the same issue, and to coordinate their efforts to prioritize and address the vulnerabilities.
About HiddenLayer
HiddenLayer, a Gartner-recognized AI Application Security company, helps enterprises safeguard the machine learning models behind their most important products with a comprehensive security platform. Only HiddenLayer offers turnkey security for AI that does not add unnecessary complexity to models and does not require access to raw data and algorithms. Founded in March of 2022 by experienced security and ML professionals, HiddenLayer is based in Austin, Texas. For additional information, including product updates and the latest research reports, visit www.hiddenlayer.com.

min read
HiddenLayer Attains SOC 2 Type II Compliance: Elevating Data Security for AI
HiddenLayer is proud to announce the achievement of Service Organization Control 2 (SOC 2) Type II compliance. This milestone underscores our commitment to upholding rigorous standards in security, availability, processing integrity, confidentiality, and privacy, aligning with our core mission to secure Artificial Intelligence and Machine Learning across enterprise and the public sector.
HiddenLayer is proud to announce the achievement of Service Organization Control 2 (SOC 2) Type II compliance. This milestone underscores our commitment to upholding rigorous standards in security, availability, processing integrity, confidentiality, and privacy, aligning with our core mission to secure Artificial Intelligence and Machine Learning across enterprise and the public sector.
This accomplishment, shortly following our Series A funding, emphasizes our dedication to safeguarding our customer’s data from the outset through robust operational practices.
Understanding SOC 2
SOC 2 is an industry standard set by the American Institute of Certified Public Accountants (AICPA), and a trusted framework for customers and third-party auditors to evaluate a service organization's information management systems' security, availability, processing integrity, confidentiality, and privacy.
HiddenLayer, alongside its Machine Learning Detection & Response platform, has successfully met SOC 2 standards, validating the design and operational effectiveness of our controls in security, availability, and confidentiality.
SOC 2 compliance is more than a milestone. It resonates with our customers, partners, and investors. It enhances our ability to form partnerships with organizations prioritizing data security and strengthens our capacity to continue to protect organizations from adversarial AI attacks.
What’s Next?
HiddenLayer remains committed to surpassing industry standards. We will continue implementing best practices to prioritize sensitive information protection across our data, systems, and confidentiality processes.
In essence, SOC 2 compliance signifies HiddenLayer's dedication to setting the benchmark for Data Security for AI, reinforcing the trust our stakeholders place in us.

min read
HiddenLayer Awarded Phase 2 SBIR Contract by the U.S. Department of Defense
The leading security provider for artificial intelligence (AI) models and assets, announces it has been selected by AFWERX for a SBIR Direct-to-Phase II contract in the amount of $1.25 million focused on implementing their Machine Learning Security (MLSec) Platform to address the most pressing challenges in the Department of the Air Force (DAF).
Machine learning security platform will secure government AI systems
AUSTIN, Texas — Oct. 24, 2023 — HiddenLayer, the leading security provider for artificial intelligence (AI) models and assets, announces it has been selected by AFWERX for a SBIR Direct-to-Phase II contract in the amount of $1.25 million focused on implementing their Machine Learning Security (MLSec) Platform to address the most pressing challenges in the Department of the Air Force (DAF).
The Air Force Research Laboratory and AFWERX have partnered to streamline the Small Business Innovation Research (SBIR) and Small Business Technology Transfer (STTR) process by accelerating the small business experience through faster proposal to award timelines, changing the pool of potential applicants by expanding opportunities to small business and eliminating bureaucratic overhead by continually implementing process improvement changes in contract execution.
The DAF began offering the Open Topic SBIR/STTR program in 2018 which expanded the range of innovations the DAF funded and now on September 22, 2023, HiddenLayer will deploy their innovative security solution to further strengthen the national defense of the United States of America.
"HiddenLayer is honored to continue our partnership with the US Air Force through our second SBIR contract award. This partnership brings our cutting-edge threat detection capabilities to specific Air Force scenarios in operation and will ensure that our military’s use of next-generation technology is secure. Everyone at HiddenLayer is committed to ensuring our government's AI is secure today and always," said Chris Sestito, CEO and co-founder of HiddenLayer.
The views expressed are those of the author and do not necessarily reflect the official policy or position of the Department of the Air Force, the Department of Defense, or the U.S. government.
About HiddenLayer
HiddenLayer, a Gartner-recognized AI Application Security company, helps enterprises safeguard the machine learning models behind their most important products with a comprehensive security platform. Only HiddenLayer offers turnkey AI security that does not add unnecessary complexity to models and does not require access to raw data and algorithms. Founded in March of 2022 by experienced security and ML professionals, HiddenLayer is based in Austin, Texas. For additional information, including product updates and the latest research reports, visit www.hiddenlayer.com.
About Air Force Research Laboratory (AFRL)
Sole organization leading the planning and execution of U.S. Air Force & U.S. Space Force science & technology programs. Orchestrates a world-wide government, industry & academia coalition in the discovery, development & delivery of a wide range of revolutionary technology. Provides leading-edge warfighting capabilities keeping air, space and cyberspace forces the world's best. Employs 10,800 military, civilian and contractor personnel at 17 research sites executing an annual $4B budget. For more information, visit: www.afresearchlab.com.
About AFWERX
The innovation arm of the DAF and a directorate within the Air Force Research Laboratory brings cutting edge American ingenuity from small businesses and start-ups to address the most pressing challenges of the DAF. Employs approximately 325 military, civilian and contractor personnel at six hubs and sites executing an annual $1.4B budget. Since 2019, has executed 4,671 contracts worth more than $2B to strengthen the U.S. defense industrial base and drive faster technology transition to operational capability. For more information, visit: www.afwerx.com.

min read
HiddenLayer Appoints Malcolm Harkins as Chief Security and Trust Officer
The leading security provider for artificial intelligence (AI) models and assets, has welcomed Malcolm Harkins as its Chief Security and Trust Officer. He is responsible for enabling business growth through trusted infrastructure, systems, and peer outreach to evangelize best practices for mitigating AI risk
Harkins brings more than two decades of experience in risk management and security
AUSTIN, Texas — Oct. 17, 2023 — HiddenLayer, the leading security provider for artificial intelligence (AI) models and assets, has welcomed Malcolm Harkins as its Chief Security and Trust Officer. He is responsible for enabling business growth through trusted infrastructure, systems, and peer outreach to evangelize best practices for mitigating AI risk.
Harkins brings more than two decades of experience in information security leadership roles at top technology companies, including Intel, Cymatic, Cylance, and others. Earlier this year, he was named the Top Chief Security and Trust Officer by Cyber Defense Magazine. He is also an independent board member and advisor to several organizations, including TrustMAPP, Cyvatar, and the Cyber Risk Alliance.
“Malcolm is one of the most innovative security leaders in the industry, and I’ve seen first-hand why he’s the right person for this job,” said Chris Sestito, Co-Founder and Chief Executive Officer at HiddenLayer. “Malcolm’s passion for security and his track record with the public sector will help advance HiddenLayer’s mission to protect enterprise and our nation’s most critical AI systems.”
Harkins has testified before the Federal Trade Commission and U.S. Senate Committee on Commerce, Science, and Transportation. He is a Fellow with the Institute for Critical Infrastructure Technology, a non-partisan think tank providing cybersecurity expertise to the House of Representatives, Senate, and various federal agencies. Earlier this year, Harkins served on a task force led by the Center for Strategic International Studies to provide direction and leadership for the Cybersecurity and Infrastructure Security Agency’s evolving mission to protect the federal government.
“The recent revolution of AI innovation can be a great advancement for society, but only if we ensure those systems are secured,” said Harkins. “HiddenLayer’s approach to protecting AI systems is crucial to enabling them. Helping organizations detect suspicious activity and prevent attacks on AI assets allows them to fully harness this powerful technology.”
Harkins has written multiple books on risk management, information security, and IT and earned awards from the RSA Conference, ISC2, Computerworld, and the Security Advisor Alliance. He previously taught at UCLA’s Anderson School of Management and Susquehanna University. He holds a bachelor’s degree in economics from the University of California at Irvine and an MBA in finance and accounting from the University of California at Davis.
About HiddenLayer
HiddenLayer, a Gartner-recognized AI Application Security company, helps enterprises safeguard the machine learning models behind their most important products with a comprehensive security platform. Only HiddenLayer offers turnkey AI security that does not add unnecessary complexity to models and does not require access to raw data and algorithms. Founded in March of 2022 by experienced security and ML professionals, HiddenLayer is based in Austin, Texas. For additional information, including product updates and the latest research reports, visit www.hiddenlayer.com.
Let’s Secure AI Together
Join HiddenLayer in shaping the standards, defenses, and future of AI security. Whether you’re a researcher, partner, or enterprise innovator, we’re stronger together.



