Artificial intelligence is moving beyond traditional applications. Organizations are increasingly deploying AI agents that can make decisions, interact with systems, write and review code, and perform tasks with limited human intervention.
As these systems become more autonomous, securing AI only during development is no longer enough. Security must extend into production, where AI agents continuously interact with data, applications, identities, APIs, and enterprise infrastructure.
The latest funding announcement from AI security company HiddenLayer highlights this growing market. The company has raised $100 million in a Series B funding round, bringing its total funding to more than $155 million. The company plans to use the investment to expand its AI runtime security capabilities, particularly for agentic AI and AI coding agents.
Why AI Runtime Security Matters
Traditional cybersecurity approaches generally focus on securing applications, endpoints, networks, and identities.
AI introduces another layer of complexity.
An AI agent can potentially:
• Access enterprise applications
• Process sensitive information
• Interact with APIs and external services
• Generate or modify code
• Make decisions based on changing inputs
• Trigger automated workflows
• Operate with privileged credentials
• Take actions without continuous human intervention
This creates a new security challenge. Organizations need visibility not only into whether an AI system is functioning correctly, but also into what the system is doing, what information it is accessing, and whether its actions remain within approved boundaries.
The Rise of Agentic AI
Agentic AI is becoming an important part of enterprise technology strategies.
AI agents can assist developers, automate business processes, analyze data, support security operations, and interact with enterprise systems.
However, greater autonomy can also increase the potential impact of a compromised or misconfigured agent.
An attacker who gains control over an AI agent may attempt to manipulate its behavior, abuse its permissions, access sensitive information, or use the agent as a pathway toward other enterprise resources.
This means organizations should begin treating AI agents as security-sensitive digital identities.
AI Coding Agents Create Additional Risks
AI coding agents are particularly important from a security perspective because they can participate directly in the software development lifecycle.
Modern coding agents may assist with:
• Writing source code
• Reviewing code
• Testing applications
• Identifying defects
• Managing development tasks
• Interacting with repositories
• Supporting deployment processes
When these capabilities are connected to production development environments, security teams need strong controls around permissions, repository access, credentials, generated code, and automated actions.
A compromised or poorly controlled coding agent could potentially introduce vulnerabilities or make unauthorized changes at a much greater speed than a traditional manual workflow.
From AI Model Security to AI Runtime Security
AI security cannot stop at model validation.
Organizations should consider security across the complete AI lifecycle:
1. AI Discovery
Organizations need an accurate inventory of AI models, agents, applications, integrations, APIs, and supporting infrastructure.
2. AI Supply Chain Security
Third-party models, datasets, libraries, plugins, and external services can introduce additional security and compliance risks.
3. Attack Simulation
Security teams should test AI systems against realistic threats, including manipulation, unauthorized actions, prompt-based attacks, data exposure, and privilege abuse.
4. Runtime Monitoring
Production AI systems require continuous monitoring for anomalous behavior, unexpected interactions, policy violations, and suspicious activity.
5. Identity and Access Controls
AI agents should receive only the permissions required for their assigned tasks. High-risk actions should have appropriate approval and authentication controls.
6. Incident Response
Organizations need procedures for isolating compromised agents, revoking credentials, investigating activity, and recovering affected systems.
AI Governance and Compliance Must Evolve Together
The adoption of autonomous AI also creates important governance questions.
Organizations need to understand:
• What data can an AI agent access?
• Which systems can it interact with?
• What actions can it perform automatically?
• Who is responsible for its decisions?
• How are AI activities logged and monitored?
• How are high-risk actions approved?
• How is sensitive information protected?
• How can organizations demonstrate compliance?
These questions become increasingly important for industries handling financial information, healthcare records, intellectual property, customer information, and critical operational systems.
AI governance should therefore be integrated with cybersecurity, privacy, risk management, and regulatory compliance programs.
Industries Facing Increasing AI Security Requirements
The shift toward agentic AI is particularly relevant for:
• Financial Services and Banking
• Healthcare and Life Sciences
• Retail and E-commerce
• Manufacturing and Industrial Enterprises
• Government and Public Sector
• Telecommunications
• Technology and SaaS Companies
• Insurance
• Critical Infrastructure
For these organizations, AI security must address both traditional cybersecurity threats and risks created by increasingly autonomous systems.
What Organizations Should Do Now
Businesses adopting AI agents should consider establishing security controls before autonomous systems become deeply integrated into production environments.
Key priorities include:
• Maintain an inventory of AI models and agents
• Apply least-privilege access to AI systems
• Protect API keys and service credentials
• Monitor AI activity in production
• Validate third-party AI components
• Conduct AI-focused penetration testing
• Implement AI security policies and guardrails
• Maintain detailed audit logs
• Test AI systems against adversarial scenarios
• Establish incident response procedures for AI-related events
• Integrate AI governance with existing compliance programs
The objective should not be to slow AI adoption. Instead, organizations should create the security foundation required to adopt AI responsibly and at scale.
Conclusion
The $100 million investment announced by HiddenLayer reflects a broader shift in cybersecurity priorities. As enterprises move toward agentic and autonomous AI systems, runtime security is becoming an increasingly important component of enterprise security architecture.
AI systems are no longer simply tools that generate information. They are increasingly becoming active participants in business processes and software development.
That evolution requires organizations to rethink traditional security models.
AI visibility, runtime monitoring, identity controls, secure development practices, attack simulation, and governance will all play an important role in building trustworthy AI environments.
The organizations that integrate security into AI adoption from the beginning will be better positioned to innovate while protecting sensitive data, applications, intellectual property, and critical business operations.
About COE Security
COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.
Our offerings include:
• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services
For organizations adopting AI agents and autonomous systems, COE Security can help strengthen AI security through AI application assessments, adversarial testing, AI runtime security reviews, identity and access control assessments, secure AI architecture reviews, API security testing, cloud security assessments, AI governance, vulnerability management, and compliance-focused security programs.
We help organizations across financial services, healthcare, retail, manufacturing, government, technology, telecommunications, insurance, and other industries identify security gaps and build stronger defenses around AI-powered environments.
Our approach focuses on helping organizations adopt AI securely while protecting sensitive information, business applications, intellectual property, and critical infrastructure.
Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption and stay updated and cyber safe.
Click to read our LinkedIn feature article