Two men smiling outdoors, standing in front of a tree and wooden fence, wearing casual shirts.

Former Google security leaders raise $36M to take on AI spear phishing

AegisAI raised $36M to fight AI spear phishing with AI agents, aiming to outsmart personalized email scams and expand beyond email security.

In short

AegisAI, founded by former Google security leaders, raised $36 million to counter AI spear phishing using AI agents that analyze email context. The startup says its approach is already winning customers and could expand beyond email into broader data security.

  • AegisAI raised a $36 million Series A led by Battery Ventures.
  • The startup was founded by former Google security executives Cy Khormaee and Ryan Luo.
  • Its product uses AI agents to detect AI-powered spear phishing and malicious attachments.
  • AegisAI says it already has dozens of customers, including Mash, LangChain and Lokker.
  • The company plans to expand from email defense into broader data security use cases.

AegisAI, a startup founded by two former Google security executives, has raised $36 million to fight AI-powered spear phishing as criminals increasingly use artificial intelligence to mass-produce convincing email attacks. The new funding lifts the company’s total financing to $49 million and underscores how email security is becoming one of the sharpest battlegrounds in enterprise cybersecurity.

The company was launched by Cy Khormaee and Ryan Luo, both of whom previously helped build Google’s safe browsing and reCAPTCHA defenses. Their pitch is straightforward: legacy email filters are struggling to keep up with highly personalized scams, so the next generation of protection has to act more like an investigator than a rule engine.

Why AI spear phishing is escalating now

AI is making phishing campaigns faster, cheaper and more persuasive. Attackers can use public information and scraped data to assemble highly tailored emails that reference coworkers, projects, travel plans and other details that make a message seem authentic.

That shift matters because spear phishing is no longer limited to a handful of manually crafted scams. With generative AI, a single operator can produce large volumes of believable messages and continuously refine them until they slip past standard defenses.

AegisAI says that is exactly the problem it was created to solve. The startup argues that conventional security products rely too heavily on static rules and checklists, which are effective against older spam but much less reliable against attacks that can adapt their language, formatting and attachments on the fly.

What AegisAI does differently

AegisAI uses AI agents to inspect incoming email in a more contextual way. Instead of depending on rigid “if this, then that” logic, the company’s agents are designed to evaluate messages more like a human analyst would, looking for subtle inconsistencies, hidden intent and patterns that do not fit the surrounding context.

According to the founders, that approach helps identify threats that traditional systems may miss entirely. The company says its technology can flag malicious attachments that appear legitimate at first glance, including PDF files that contain passwords, CAPTCHA pages or other tricks intended to defeat conventional spam detection.

In a market where attackers are also using AI to imitate tone, timing and corporate language, context has become a major differentiator. AegisAI is betting that investigative automation can outperform older defenses that were built for a different era of email abuse.

How the startup describes its approach

Khormaee says the central challenge is that AI-enabled attacks are now bypassing existing protections far too often. He argues that modern attackers are researching victims in detail and using that information to send highly customized messages that are much harder to spot than generic spam.

Khormaee said AI-driven attacks are now getting through current controls more than half the time, and added that attackers are using research and personalization to make scams look bespoke to each target.

That framing reflects a broader industry concern: the old separation between “malware,” “spam” and “phishing” is blurring as attackers combine social engineering, document obfuscation and AI-generated language into single campaigns.

Who backed the new funding round?

AegisAI’s Series A was led by Battery Ventures, with participation from existing investors Accel and Foundation Capital. The $36 million round comes less than a year after the startup’s launch and signals that venture capital remains eager to fund infrastructure companies that can defend enterprises against AI-native threats.

Battery general partner Dharmesh Thakker said he was motivated by the growing use of AI in email-based attacks and wanted to support a company that could use AI defensively.

Thakker said criminals are using email and AI at a pace defenders are struggling to match, and argued that stopping those attacks is becoming a top priority for companies.

For investors, the pitch is not simply about selling another point solution. It is about replacing older email security products with systems that can keep pace with increasingly dynamic threats.

What customers is AegisAI already signing?

The startup says it has already been adopted by dozens of customers, including crypto payments company Mash, AI startup LangChain and Lokker, a privacy compliance platform owned by Google. That customer list is notable not only because it spans different industries, but also because it suggests demand from businesses that are likely to be frequent targets for impersonation or fraud.

Early adoption matters in cybersecurity because buyers are often cautious about swapping out established tools. If a young company can win over security teams at recognizable firms, it can strengthen the case that its detection approach is meaningfully better than incumbent systems.

AegisAI is also entering a crowded field. Other startups are trying to use AI to analyze every email for signs of fraud, impersonation or social engineering, including Ocean, which is backed by Lightspeed. Those companies are aiming at larger vendors such as Proofpoint and Mimecast, as well as newer challengers like Abnormal Security.

That competitive pressure is likely to intensify as more buyers look for products that can handle threats designed by AI rather than just human scammers.

How big is the opportunity in email security?

Email remains one of the easiest and most profitable entry points for attackers. It is widely used, deeply embedded in business operations and often connected to sensitive payment, login and document-sharing workflows. That makes it an ideal target for fraud, credential theft and malware delivery.

The rise of AI has expanded the threat surface. Attackers can now customize emails at scale, making it harder for employees to rely on obvious signs such as spelling mistakes, awkward grammar or generic greetings. In practice, this means organizations need tools that can spot unusual intent rather than just suspicious phrasing.

Security buyers are also facing a broader reset in defensive architecture. As enterprise systems adopt more AI agents, the same technology is being repurposed to inspect, triage and respond to malicious messages. AegisAI is part of that shift.

Key item Details Why it matters
Founders Cy Khormaee and Ryan Luo, former Google security executives Brings credibility from work on major consumer security systems
Funding raised $36 million Series A Expands the startup’s ability to scale product and sales
Total funding $49 million Shows strong early investor support
Lead investor Battery Ventures Signals belief in AI-first security defense
Current focus Spear phishing detection in email Targets one of the most common enterprise attack vectors
Future expansion Data security and broader investigations Could widen the company’s platform beyond email

Why the founders believe legacy filters are no longer enough

Khormaee and Luo are not newcomers to the problem. Their backgrounds in security at Google gave them years of exposure to large-scale abuse patterns, particularly around browser protection and user authentication. That experience appears to have shaped their view that modern email defense needs more flexibility than rules-based systems can provide.

Traditional security tools are built around known patterns: suspicious links, blocked domains, reused indicators of compromise and predefined behavioral rules. Those methods still matter, but they can be slow to adapt when attacks are constantly mutating and customized for each target.

AegisAI’s premise is that AI agents can close that gap by interpreting messages in context and by identifying abnormalities that are difficult to express as a checklist. In practical terms, that could mean seeing through a malicious attachment that looks polished enough to evade standard heuristics or recognizing an urgent request that does not match a normal business relationship.

How AegisAI’s model differs from older email security vendors

Older email security systems typically focus on filtering known threats and scoring messages against fixed signals. AegisAI is positioning itself as a more adaptive layer that can investigate each message more deeply and learn from the surrounding context.

That distinction matters because attackers are increasingly using the same AI tools defenders use. If both sides can generate polished text, mimic workplace communication and automate follow-up, then the edge shifts toward whoever can interpret intent more accurately.

  • Legacy tools focus on known indicators and predefined rules.
  • AegisAI says its agents evaluate full-message context.
  • The company is targeting AI-generated spear phishing and impersonation.
  • Its systems are designed to catch deceptive attachments and disguised documents.

What comes next for AegisAI?

The startup is beginning with email, but it does not plan to stay there. Khormaee says the broader opportunity is in data security and other areas where AI agents can investigate suspicious activity, review access patterns and help defenders respond more quickly.

That expansion path could matter if the company can prove its core method works at scale. Email is a natural first step because the problem is large, visible and urgent. If the product performs well there, it may be easier to extend the same agentic framework to adjacent security tasks.

Still, the road ahead will not be simple. Incumbents already have deep enterprise relationships, and several startups are chasing the same market opportunity. AegisAI’s edge may depend on whether its founding team’s experience securing Gmail translates into a product that security teams trust in production.

Battery’s Thakker believes that advantage could be decisive. In his view, the next major cybersecurity winner may be the company that can combine advanced AI with customized investigations rather than relying on static detection rules.

Timeline of AegisAI’s rapid rise

The company’s growth has been unusually fast for a cybersecurity startup still in its first year. The timeline below shows how quickly it moved from launch to major enterprise traction and a large funding round.

Period Milestone Significance
Last year AegisAI is founded by Khormaee and Luo Brings former Google security experience into a new startup
Within the first year The product is adopted by dozens of customers Shows early market demand for AI-focused email defense
July 2026 Series A of $36 million is announced Provides capital to expand product development and sales
After the round Total funding reaches $49 million Strengthens the company’s position in a crowded category

How investors are reading the market

Investor interest in AegisAI reflects a wider realization across enterprise software: AI is not only changing how work gets done, but also how that work is attacked. Security firms now need to defend against attacks that can be generated, tested and personalized at machine speed.

That is why the market is increasingly rewarding products that do more than score threats. Buyers are looking for systems that can reason about context, investigate suspicious behavior and adapt as quickly as attackers do.

The rise of AI-driven phishing also creates a messaging advantage for startups. It is easier to explain the value of a tool that protects employees from highly believable fake emails than it is to sell abstract improvements in detection accuracy. In that sense, AegisAI is tapping into a real and visible pain point.

What this means for enterprise security

The AegisAI funding round is another sign that the cybersecurity market is entering a new phase. Email security is no longer just about blocking spam and known malicious links. It is about understanding behavior, context and intent in a world where attackers can automate all three.

For enterprises, that means the bar for protection is rising. Security teams may need to evaluate whether their current systems can detect highly personalized fraud before employees click, reply or transfer money. For startups, it means the opportunity is large but highly competitive, with room only for tools that can demonstrate clear improvement over existing platforms.

AegisAI’s bet is that AI agents will become the new frontline of defense. Its founders believe the companies that win in this environment will be those that can investigate suspicious messages with enough depth and speed to outpace the attackers.

For now, the company’s challenge is proving that its technology can keep doing that as threats evolve. The funding gives it a bigger platform to try.

Frequently asked questions

What is AegisAI?

AegisAI is a cybersecurity startup that uses AI agents to detect spear phishing and other malicious email activity. Founded by former Google security executives, it aims to replace older rule-based defenses with more contextual analysis of incoming messages.

How much funding did AegisAI raise?

AegisAI raised $36 million in a Series A round led by Battery Ventures. With this financing, the startup says its total funding has reached $49 million.

Why are AI spear phishing attacks harder to stop?

AI spear phishing attacks are harder to stop because criminals can quickly generate personalized emails using public and scraped information. Those messages often look authentic enough to bypass traditional filters that rely on fixed rules or obvious spam signals.

Who are AegisAI’s founders?

AegisAI was founded by Cy Khormaee and Ryan Luo, both former Google security executives. They previously worked on safe browsing and reCAPTCHA technologies, giving them experience in large-scale abuse prevention.

Which companies use AegisAI?

AegisAI says it has been adopted by dozens of customers, including Mash, LangChain and Lokker. Those early customers suggest interest from companies that handle sensitive communications and are likely targets for impersonation or fraud.

Share this 🚀