Updated September 1, 2026 7:25 pm
In short
AIR has exited stealth with $50 million to secure AI agents’ software supply chain, says it has about 40 employees, and plans to use the money to grow research and go-to-market efforts in the U.S. and Europe.
- AIR raised $50 million across two seed rounds led by Sequoia and Greenoaks.
- The startup focuses on securing the plugins, skills, and add-ons AI agents use, not just the models themselves.
- AIR says it can discover agents, monitor tools continuously, and block risky components in real time.
- The company reports more than 20 customers, with early traction strongest in regulated sectors like finance and pharma.
- Competition is heating up, with firms such as Zenity, Noma Security, Astrix Security, and Operant AI also targeting the market.
Update — September 1, 2026 7:25 pm
AIR says it now has about 40 employees, and the new capital will go mainly toward hiring researchers and expanding sales in the U.S. and Europe.
The company also framed its edge more sharply in a crowded market, saying its moat is the ability to continuously re-check the skills and add-ons agents rely on as they change over time.
TechCrunch also noted growing competition in the category, pointing to similar offerings from Noma Security, Zenity, Astrix Security and Operant AI, alongside fresh venture funding flowing into the space.
AIR has emerged from stealth with $50 million in seed funding to build security infrastructure for the growing ecosystem of tools that AI agents use. The startup wants to help enterprises discover, monitor, and block risky skills, plugins, MCP servers, and add-ons before those components can expose corporate systems to attack.
The company’s timing is deliberate: as organizations hand AI agents broader access to databases, internal apps, and the public internet, a new software supply chain is forming around the tools those agents install and invoke. AIR argues that this expanding layer needs continuous vetting, not one-time scanning, if companies want to keep agentic systems safe.
What AIR is building and why it matters
AIR is positioning itself as a security layer for the emerging agent economy. Rather than protecting only the model itself, the startup focuses on the skills, plugins, and third-party components that let agents perform useful work across enterprise environments.
According to the company, that layer is becoming a weak point. AI agents often rely on downloadable tools or external services to fetch information, take actions, or connect to systems. Once those agents are allowed into production, AIR says, organizations need visibility into what is running, what is being added, and whether any of those components have changed in ways that make them unsafe.
The startup’s platform is designed to do three things at once:
- discover AI agents operating inside a company’s environment,
- monitor the tools and add-ons those agents use in real time, and
- block interactions with software or external sources that fail security checks.
It also offers a marketplace of vetted skills and add-ons for companies that want approved options rather than open-ended access to the internet.
How the funding was raised
The company said the $50 million came from two seed rounds closed only weeks apart. Sequoia led the first round, which brought in $10 million, while Greenoaks led the second, a $40 million raise.
Other backers included Swish, Netz, Zach Frankel of Cognition, Yinon Costica of Wiz, Ofir Erlich of Eon, Anne Neuberger, Omer Adam, Varun Anand of Clay, and additional angel investors.
AIR’s founders, CEO Yair Saban and CTO Niv Hoffman, both previously served in Israel’s Unit 8200 intelligence corps, where they worked on offensive cybersecurity. That background is central to the company’s pitch: it is building for a world in which AI agents, like endpoints and applications before them, become a new target surface for attackers.
Why AI agents create a new security problem
The rise of AI agents is changing enterprise software in a way that resembles the early days of platform computing. Agents are increasingly being asked to act on behalf of users, navigate corporate systems, and install or call external tools to finish tasks. AIR says that shift makes the tool layer itself a security concern.
Yair Saban drew a comparison to software drivers, arguing that modern systems learned long ago to require signatures and verification before allowing code deep access to critical operating layers. In his view, skills, plugins, and MCP-style connectors are now acting in a similar role, but enterprise controls have not caught up.
“The lesson from drivers was that once code can touch the core of a system, you need to know who signed it and whether it can be trusted,” Saban said, paraphrasing the company’s view of the problem. “That same discipline has not yet been applied to skills and plugins.”
The core fear is not only that a malicious add-on could be installed directly. AIR says attackers may also try to manipulate the content an agent consumes, effectively poisoning the agent’s inputs and decisions rather than breaching the AI system head-on.
What risks do AI agents introduce?
AI agents can create indirect attack paths because they are designed to act autonomously and connect across many systems. If an agent can read data, fetch web content, call tools, and trigger actions, then a compromised plugin, manipulated package, or rogue endpoint could become a hidden entry point.
That risk extends beyond the model provider. Enterprises may approve one tool and later inherit new risk if the tool’s upstream package changes, if a developer account is compromised, or if a third-party service alters its behavior without warning. AIR says its system is built to detect those changes continuously.
How AIR’s platform works
AIR says its product combines visibility, enforcement, and trust decisions. First, it searches for agents active across a customer’s environment. It then identifies employees who may be using AI tools without IT approval or through personal accounts. After that, it inserts an enforcement layer that can intercept agent actions in real time.
That enforcement layer can inspect operations such as loading a skill, calling a plugin, or retrieving information from the internet. AIR then checks those actions against a whitelist of approved tools and components maintained by the startup.
The whitelist is not static. AIR says it repeatedly evaluates publicly available skills and add-ons for behavioral changes and signs of compromise. That matters because a previously safe component can become dangerous if its dependencies change, if malicious code is added, or if an owner’s account is taken over.
By AIR’s own account, the platform currently filters out about 27% of the add-ons and skills it encounters online.
| Key area | AIR’s approach | Why it matters |
|---|---|---|
| Discovery | Finds AI agents running in the enterprise | Creates a map of where agentic tools are active |
| Monitoring | Tracks skills, plugins, and add-ons continuously | Helps catch changes after initial approval |
| Enforcement | Intercepts agent actions in real time | Can stop risky tools before they execute |
| Approval | Checks against a maintained whitelist | Reduces exposure to unsafe components |
| Marketplace | Offers vetted add-ons and skills | Gives companies safer options to deploy |
Who is buying the product so far?
AIR says it already has more than 20 customers, with roughly a quarter of them classified as large enterprises. The strongest demand, according to the company, is coming from industries with stricter oversight and higher compliance burdens.
Financial services and pharmaceutical companies appear to be especially interested, which makes sense given their sensitivity to data access, auditability, and external dependencies. Those sectors tend to adopt new software more carefully, but when they do move, they often need stronger controls than smaller or less regulated businesses.
Why regulated industries are leading adoption
Regulated industries often feel the impact of a security control sooner than others. If an AI agent can query records, summarize compliance data, or initiate actions, then every connected plugin or tool can become part of a governance issue. AIR’s pitch is that its system can give those businesses a way to adopt agents without opening the door to uncontrolled software sprawl.
That may also explain why the startup is emphasizing continuous inspection. In finance and pharma, a tool that was acceptable yesterday may no longer be acceptable after an update, a dependency change, or a new threat disclosure.
How competitive is the market?
AIR is entering a crowded and fast-moving market. Several startups are targeting agent security, governance, and runtime protection, and many are raising large rounds to do it.
Noma Security provides discovery, access controls, and runtime monitoring for agents, MCP servers, and skills. Zenity offers security and governance features that overlap with AIR’s use case. Astrix Security’s identity platform can also help companies discover and control agents and MCP servers, while Operant AI sells agent protection tools and an MCP gateway.
Funding in the category has accelerated. Zenity raised $125 million in a Series C in August, and Noma raised $100 million in a Series B last year. The money pouring into the sector suggests investors believe agent deployment will create a security market large enough to support multiple vendors.
What AIR says is its edge
AIR argues that its differentiator is not simply visibility into agents, but continuous verification of the ecosystem of tools they rely on. Saban says the hard part is not discovering a machine or endpoint inside an enterprise. The harder challenge is tracking whether every connected skill, plugin site, or add-on remains trustworthy over time.
Bogomil Balkansky, a Sequoia partner, said in an emailed statement that the issue is less about one-time scanning than about re-verifying tools continuously across a live enterprise environment. He argued that AIR has spent the last year building the infrastructure needed for that process and that a better scanner alone would not close the gap.
AIR believes that approach creates a more durable moat than endpoint discovery alone. If every vendor can find agents, the company says, not every vendor can maintain an always-on trust pipeline for the entire tool ecosystem those agents consume.
Will model providers solve this themselves?
Possibly, but AIR does not think that will eliminate demand for an independent layer. Saban has acknowledged that AI labs and platform vendors are likely to add more built-in security checks over time. Even so, AIR expects enterprises to want controls that work across multiple vendors and agent frameworks rather than relying only on one provider’s policies.
That argument echoes a familiar enterprise security pattern: organizations often buy third-party controls even when the underlying platform offers built-in protection, especially when they need consistent policy across a mixed environment.
What the new funding will be used for
AIR currently employs about 40 people. The new capital will go primarily toward hiring researchers and expanding sales and marketing efforts in the United States and Europe.
That hiring plan suggests the company is still in a build-and-prove phase. It needs both technical depth, to keep up with rapidly changing agent frameworks, and commercial reach, to win customers in a market where many security vendors are making similar claims.
The company has not disclosed a valuation. But raising $50 million across two seed rounds, with top-tier investors leading both, signals strong confidence that the problem is real and that enterprise buyers are already looking for a solution.
Timeline: how AIR reached this point
| Date | Milestone | Details |
|---|---|---|
| Company founded | Stealth phase begins | Built by Yair Saban and Niv Hoffman after their Unit 8200 cybersecurity work |
| First seed round | $10 million raised | Sequoia led the round |
| Second seed round | $40 million raised | Greenoaks led the round |
| September 2026 | Stealth exit | Company publicly launches with $50 million total funding |
| Now | Expansion phase | Hiring researchers and scaling go-to-market in the U.S. and Europe |
Why this matters for enterprise AI
AIR’s launch is another sign that enterprise AI security is moving beyond model prompts and data leakage into a broader question: who controls the tools that agents use to take action. As companies integrate AI agents into more workflows, the problem is no longer just whether the model can answer safely, but whether the surrounding ecosystem can be trusted.
That shift matters because agentic systems are likely to become more autonomous before they become fully standardized. Enterprises may end up approving not only the agent itself, but also the skills, plugins, and connectors that give the agent real-world power. AIR is betting that this approval layer will become a category of its own.
For security teams, the takeaway is clear. The new risk may not be the model in the center of the system, but the growing ring of software around it. And as that ring expands, so does the need for verification, policy enforcement, and continuous oversight.
In that sense, AIR is not just selling a product. It is making a case that agent software will eventually need the same kind of supply-chain discipline that enterprise teams already expect from code, packages, and infrastructure.
If that prediction proves right, the market for AI agent security could become one of the most important layers in the next phase of enterprise software.
AIR is entering it early, well funded, and with a thesis that the companies building autonomous systems will need guardrails almost as quickly as they adopt the tools themselves.
Frequently asked questions
What does AIR do?
AIR builds security software for AI agents, helping enterprises discover agents, monitor the skills and plugins they use, and block risky add-ons in real time. The company focuses on the expanding tool layer around agents rather than the model alone.
How much funding did AIR raise?
AIR raised $50 million in total across two seed rounds. Sequoia led the first, a $10 million round, and Greenoaks led the second, which brought in $40 million. The company came out of stealth with the financing.
Why is AI agent security becoming important?
AI agent security matters because agents are increasingly allowed to access databases, internal apps, and the internet. That creates a new attack surface where malicious or compromised plugins, skills, and connectors can influence what the agent does.
Who are AIR’s main competitors?
AIR competes with several startups in the same space, including Noma Security, Zenity, Astrix Security, and Operant AI. Many of these companies offer overlapping discovery, governance, runtime monitoring, or MCP protection features.
Which industries are most interested in AIR?
Financial services and pharmaceutical companies appear to be the strongest early buyers. AIR says those heavily regulated industries are drawn to the product because they need tighter oversight over AI tools, data access, and third-party components.









