4 Sources
[1]
AIR raises $50M to help companies vet the skills and add-ons AI agents use
As companies start giving AI agents access to an increasing portion of their systems, a nascent software supply chain seems to be forming around the new tooling AI agents are using: skills, plugins, MCP servers, and add-ons that let them interact with the internet. AI security startup AIR believes companies will need a way to monitor that supply chain, and it's now coming out of stealth with $50 million raised across two seed rounds to build that product. Founded by Yair Saban (CEO) and Niv Hoffman (CTO), veterans of Israel's Unit 8200 intelligence corps, where they worked on offensive cybersecurity, AIR offers a platform that can discover agents running inside companies, continuously vet any skills, tools, and components those agents use, and block them from interacting with software or external sources that don't pass security criteria. It also offers a marketplace of vetted add-ons and skills for AI agents. The funding rounds closed within weeks of each other, Saban told TechCrunch, with the first round raising $10 million, and the second $40 million. Sequoia led the first round, while Greenoaks led the second, Saban said. Swish, Netz, and Zach Frankel (president of Cognition), Yinon Costica (co-founder of Wiz), Ofir Erlich (co-founder of Eon), Anne Neuberger, Omer Adam, Varun Anand (co-founder of Clay), and other angel investors also participated. AIR's pitch goes thusly: The way AI agents are used wholesale at companies is beginning to resemble operating systems, but the tools they use, or the software they can install, aren't yet being given the kind of oversight we give to drivers or applications. "In the early 2000s, whenever you installed a driver, the driver didn't need to be signed. Today, every time you install a driver, you see a signature saying who signed it, because the driver is actually loading code into the kernel," Saban said. "You don't have that with skills or plugins or MCPs, and it's a shame, because it's the same mechanism, it's the same lesson, but we haven't learned it." The big risk, he argues, is that as AI agents start working more autonomously across databases, enterprise systems, and connecting to the internet, attackers can poison the content an AI agent consumes instead of attacking it directly. The startup says it can solve that with a visibility product that finds agents active across a company's environment, as well as identifies employees who use AI tools unapproved by IT departments or those who use personal accounts. Then, it uses an enforcement layer that hooks into agents to intercept and analyze actions, like loading a skill or fetching content from the internet. Lastly, AIR also checks the tools, add-ons, or software an agent wants to use against a whitelist the startup maintains. Saban says the startup maintains this whitelist by evaluating skills and add-ons openly available on the internet for changes and malicious behavior, as a previously approved skill could become risky if a package it downloads changes, or its developer's account is compromised. He added that AIR's platform currently filters out about 27% of the add-ons and skills it finds online. AIR claims it has more than 20 customers, and Saban said roughly a quarter of these are large enterprises. He said the company has so far seen the strongest demand in heavily regulated industries, particularly financial services and pharmaceutical companies. However, AIR is hardly alone in this space. Noma Security offers discovery, access controls and runtime monitoring for agents, MCP servers and skills, while Zenity sells security and governance tools that work similarly. Astrix Security's identity platform also lets companies discover and control agents and MCP servers, and Operant AI offers agent protections as well as an MCP gateway. There is significant venture money chasing the category, too. Zenity raised a $125 million Series C in August, while Noma raised a $100 million Series B last year. Saban thinks AIR's moat lies in its ability to continuously vet the skills and add-ons ecosystem growing around AI agents. "Continuously vetting skills and plugin websites, this is a hard mission to do. Gaining visibility over the endpoint, that is easy. Everybody's going to do it. It's hard to create a moat around that," he said. And while the CEO acknowledged that AI labs and providers will eventually build in security checks and policies to filter out malicious skill and tool usage, he thinks companies will still want to buy an independent product that works across vendors. "This is not a scanning problem, it is a continuous re-verification problem," Bogomil Balkansky, partner at Sequoia, told TechCrunch in an emailed statement. "Inspecting every skill, plugin, MCP server and sub-agent an enterprise's agents touch, re-inspecting each one every time it changes, in real time and across an entire company's agent fleet, is an infrastructure problem long before it is a security problem. Air has spent the last year building that pipeline. You do not catch up to it by writing a better scanner." AIR currently has around 40 employees. Saban said the new capital will primarily go toward hiring researchers and expanding the company's go-to-market efforts in the U.S. and Europe.
[2]
AIR Security launches with $50M to build a firewall for AI agents
AIR Security launches with $50M to build a firewall for AI agents Artificial intelligence agent security startup AIR Security Inc. formally launched Monday with $50 million in funding to build what it calls an inline firewall for AI agents. Founded earlier this year, AIR is going after a gap that has opened as coding agents spread through large enterprises. Those agents reach for third-party skills, plugins and Model Context Protocol servers on their own initiative. The security team rarely sees what got picked up. AIR's software sits in that path and screens the instructions, tools and data heading into an agent's context before the agent acts on any of it. Discovery comes first. The platform maps the agents already running across endpoints, cloud accounts and software-as-a-service applications, then keeps re-checking the components those agents depend on. A skill that passed review in March can be rewritten in June by whoever maintains it. Untrusted tools and injected instructions are blocked at runtime, and AIR also runs a marketplace of add-ons it has already cleared. Company researchers have put some numbers on the exposure. More than 17,800 public AI add-ons, accounting for 6.7 million installations, drew instructions from outside sources nobody had verified. The team also turned up AI skills impersonating Anthropic PBC and OpenAI Group PBC that could run arbitrary code once installed. Roughly 27% of the add-ons and skills AIR finds online get filtered out. More than 20 companies use the platform and about a quarter of them are large enterprises, with the strongest demand so far coming from financial services and pharmaceutical firms, according to TechCrunch. "Every enterprise has a firewall protecting its network," Chief Executive Yair Saban said. "Now they need one protecting their AI agents." Saban started the company with Chief Technology Officer Niv Hoffman. Both spent years in Unit 8200, the Israeli military intelligence corps, doing offensive cybersecurity work, and about 40 people now work for them. Ryan Knisley signed on as chief strategy officer after holding the chief information security officer job at both The Walt Disney Co. and Costco Wholesale Corp. The $50 million came in two rounds, both closed inside the company's first six months. Sequoia Capital led the first at $10 million and Greenoaks Capital Partners led the $40 million that followed. Swish Ventures and Netz Capital also invested. Angel backers include Wiz Inc. co-founder Yinon Costica, Clay co-founder Varun Anand, Eon co-founder Ofir Ehrlich, Cognition President Zach Frankel and Anne Neuberger, the former White House deputy national security adviser for cyber and emerging technology. Bogomil Balkansky, a partner at Sequoia Capital, told TechCrunch the problem AIR is addressing is "not a scanning problem" but one of continuous re-verification, since the components an agent uses keep changing underneath it. Greenoaks partner Patrick Backhouse made a related point in the funding announcement, saying agents work at runtime with skills, plugins, add-ons and MCP servers "from sources that no security team has reviewed." AIR is based in New York and will spend the new money on hiring researchers and building out sales in the U.S. and Europe.
[3]
AIR Emerges from Stealth With $50M to Build a Firewall for Agents
After research exposing vulnerabilities across millions of AI add-on installations, AIR launches an inline firewall for AI agents, protecting their context from external threats NEW YORK, September 1, 2026 (Newswire.com) - AIR, the company building an inline firewall for agents , today emerged from stealth and announced $50 million in funding. The funding was led by Sequoia Capital and Greenoaks. Other participating investors included Swish Ventures and Netz Capital. As enterprises deploy AI agents, they're connecting to more tools, data, and third-party services. They're also browsing websites, accessing files and emails, and taking actions on employees' behalf. This is becoming more complex as agents gain autonomy and connect to more of the enterprise. Malicious content or a compromised tool can influence an agent into taking unintended actions, creating a path to data theft, fraud, or unauthorized access. Unlike traditional software, agents make decisions based on the information they encounter, leaving security teams with limited visibility into what is influencing them, what they can access, and what actions they take. AIR's launch follows a series of original security research findings that demonstrate the risk. In one study, Air found that more than 17,800 public AI add-ons - representing 6.7 million installations - relied on untrusted external instruction sources. In another, the company uncovered AI Skills in the wild impersonating trusted brands including Anthropic and OpenAI to bypass platform security reviews and execute arbitrary code. "Every enterprise has a firewall protecting its network. Now they need one protecting their AI agents., AI agents need a new kind of firewall - one that protects what enters their context," said Yair Saban, co-founder and CEO of AIR. "Today, agents are autonomously installing tools, connecting to internal systems, and making decisions - and in most organizations, nobody knows what's running, what's trusted, or how to shut it off." Founded by Yair Saban and Niv Hoffman, AIR combines deep expertise in offensive security, enterprise infrastructure, and AI security research. The team is also joined by Ryan Knisley, former CISO at The Walt Disney Company and Costco Wholesale, as Chief Strategy Officer. AIR continuously discovers and evaluates every skill, plugin, MCP server, and add-on across an organization's AI agent supply chain, before and after deployment. When an add-on is found to be malicious, vulnerable, or unapproved, AIR enables security teams to trace every agent and workflow that depends on it and revoke it across the organization. AIR also provides a marketplace of pre-vetted, certified add-ons, giving enterprises a safe path to expand agent capabilities without introducing unmanaged risk. "What gave us conviction in AIR from the beginning was the founders," said Bogomil Balkansky, Partner at Sequoia Capital. "They saw early that AI agents would create a completely new security problem for enterprises and started building for it before most companies were even thinking about it. We believe they have the team and the vision to define this category." "Software supply chains were never the most critical attack surface within an enterprise. Now, with AI agents, they are vitally important," said Patrick Backhouse, Partner at Greenoaks. "Agents operate at runtime, using skills, plugins, add-ons, and MCPs from sources that no security team has reviewed, and slipping past scanners built for yesterday's code. AIR is building the platform to discover every agent, govern what they are allowed to touch, and monitor them in production. We believe that this layer will become mandatory to enterprise cybersecurity, and we are proud to partner with Yair, Niv, and the Air team as they define it." About AIR AIR is the inline firewall for AI agents. It protects agents from malicious instructions, untrusted data, and compromised tools before they can influence an agent's decisions or actions. AIR gives enterprises the visibility and control to securely deploy and operate AI agents at scale. Learn more at air.security.
[4]
AI Agent Security Startup AIR Raises $50 Million to Guard Enterprise Supply Chains | PYMNTS.com
The company was founded by CEO Yair Saban and Chief Technology Officer Niv Hoffman, both veterans of Israel's Unit 8200 intelligence corps. The report noted that AIR secured the funding across two seed rounds closed within weeks of each other. Venture firm Sequoia Capital led an initial $10 million round, followed by a $40 million investment led by Greenoaks Capital, with participation from enterprise security founders and angel investors. According to the report, corporate AI agents routinely deploy third-party plug-ins and Model Context Protocol (MCP) servers to connect with internet resources, while utilizing digital "skills" to autonomously execute tasks across internal databases. As companies grant agents broader operational access, these unvetted software components present supply-chain vulnerabilities where malicious actors can poison the data or code that an agent consumes. As reported, AIR's platform seeks to address these security risks by discovering active agents across a network, flagging unauthorized employee tools, continuously checking external components for malicious alterations and blocking non-compliant software. The startup reported in the article that its system currently filters out approximately 27% of the agent add-ons and skills evaluated online. Customer adoption has been strongest in heavily regulated sectors, particularly financial services and pharmaceuticals. The report stated that AIR currently serves more than 20 corporate clients, with large enterprise customers representing about a quarter of that total. Emphasizing the current lack of governance across AI agent extensions, Saban drew a parallel to historical enterprise software challenges. "In the early 2000s, whenever you installed a driver, the driver didn't need to be signed. Today, every time you install a driver, you see a signature saying who signed it, because the driver is actually loading code into the kernel," he told TechCrunch. "You don't have that with skills or plug-ins or MCPs, and it's a shame, because it's the same mechanism, it's the same lesson, but we haven't learned it." The funding comes as financial institutions and enterprise risk managers confront a growing governance gap surrounding autonomous systems. As PYMNTS reported in March, traditional cybersecurity infrastructure was engineered for static applications and firewalls rather than autonomous AI agents that interpret natural language prompts, cross software boundaries and retrieve corporate data independently. Because financial services firms increasingly rely on agents to process transactions, cross-reference customer records and draft compliance filings, unmonitored agent activity creates severe operational and regulatory risks. These threats highlight the need for dedicated platforms that enforce audit trails and strict access controls before rogue code reaches core banking networks.
Share
Copy Link
AIR Security launched from stealth with $50M in funding to address a critical gap in AI agent security. The cybersecurity startup built an inline firewall that vets skills, plugins, and add-ons AI agents use, filtering out 27% of components found online. Founded by Unit 8200 veterans, AIR already serves over 20 customers in heavily regulated sectors.
AIR Security emerged from stealth with $50M funding to build what the cybersecurity startup calls an inline firewall for AI agents
1
. The funding came across two seed rounds closed within weeks of each other, with Sequoia Capital leading the first $10 million round and Greenoaks leading a subsequent $40 million investment2
. Additional investors included Swish Ventures, Netz Capital, and notable angel backers such as Wiz co-founder Yinon Costica, Clay co-founder Varun Anand, and former White House deputy national security adviser Anne Neuberger1
.
Source: PYMNTS
Founded by CEO Yair Saban and CTO Niv Hoffman, both veterans of Israel's Unit 8200 intelligence corps where they specialized in offensive cybersecurity, AIR now employs approximately 40 people
2
. The team also includes Ryan Knisley as chief strategy officer, who previously served as CISO at The Walt Disney Company and Costco Wholesale3
.As enterprises deploy AI coding agents with increasing autonomy across databases, enterprise systems, and internet connections, a nascent software supply chain has formed around the tooling these agents use. AIR Security tackles the security risks inherent in vetting AI skills and add-ons, plugins, and Model Context Protocol servers that AI agents autonomously install and execute
1
.The startup's research exposed alarming vulnerabilities. More than 17,800 public AI add-ons representing 6.7 million installations relied on untrusted external instruction sources
3
. AIR researchers also uncovered AI skills impersonating Anthropic and OpenAI to bypass platform security reviews and execute arbitrary code2
. Currently, AIR's platform filters out approximately 27% of the add-ons and skills it evaluates online1
.AIR's platform operates through three core layers to guard enterprise supply chains. Discovery comes first, mapping agents already running across endpoints, cloud accounts, and software-as-a-service applications while identifying employees using AI tools unapproved by IT departments or personal accounts
1
. The enforcement layer hooks into agents to intercept and analyze actions like loading a skill or fetching content from the internet before the agent acts on it2
.Continuous vetting forms the platform's third pillar. AIR maintains a whitelist by evaluating skills and add-ons openly available on the internet for changes and malicious behavior, recognizing that a previously approved skill could become risky if a package it downloads changes or its developer's account is compromised
1
. When an add-on is found malicious, vulnerable, or unapproved, security teams can trace every agent and workflow that depends on it and revoke it across the organization3
. AIR also provides a marketplace of pre-vetted, certified add-ons.AIR Security already serves more than 20 customers, with approximately a quarter being large enterprises
1
. The strongest demand has emerged from heavily regulated sectors, particularly financial services and pharmaceuticals4
. This adoption pattern reflects mounting concerns about data theft, fraud, and unauthorized access as financial institutions increasingly rely on agents to process transactions, cross-reference customer records, and draft compliance filings4
.Related Stories
AIR Security enters a competitive market with significant venture capital interest. Competitors include Noma Security, which offers discovery, access controls, and runtime monitoring for agents and MCP servers, and Zenity, which raised a $125 million Series C in August for similar security and governance tools
1
. Noma raised a $100 million Series B last year. Astrix Security and Operant AI also compete in this space1
.Saban believes AIR's competitive advantage lies in its ability to continuously vet the skills and add-ons ecosystem. "Continuously vetting skills and plugin websites, this is a hard mission to do. Gaining visibility over the endpoint, that is easy. Everybody's going to do it. It's hard to create a moat around that," he told TechCrunch
1
.
Source: TechCrunch
The launch addresses a fundamental shift in enterprise security architecture. Traditional cybersecurity infrastructure was engineered for static applications and firewalls rather than autonomous AI agents that interpret natural language prompts, cross software boundaries, and retrieve corporate data independently
4
. Saban drew parallels to historical software challenges: "In the early 2000s, whenever you installed a driver, the driver didn't need to be signed. Today, every time you install a driver, you see a signature saying who signed it, because the driver is actually loading code into the kernel. You don't have that with skills or plugins or MCPs, and it's a shame, because it's the same mechanism, it's the same lesson, but we haven't learned it"4
.Bogomil Balkansky, partner at Sequoia Capital, emphasized the infrastructure challenge: "This is not a scanning problem, it is a continuous re-verification problem. Inspecting every skill, plugin, MCP server and sub-agent an enterprise's agents touch, re-inspecting each one every time it changes, in real time and across an entire company's agent fleet, is an infrastructure problem long before it is a security problem"
1
. Patrick Backhouse from Greenoaks added that agents operate at runtime using components "from sources that no security team has reviewed"3
.AIR will deploy the funding toward hiring researchers and expanding sales operations in the United States and Europe
2
. Watch for how enterprises in regulated industries adopt security for agents as AI agent deployment accelerates, and whether AIR's continuous re-verification approach becomes the industry standard for protecting the AI agent supply chain.Summarized by
Navi
30 Jul 2025•Technology

04 Aug 2026•Startups

13 Jan 2026•Technology

1
Technology

2
Policy and Regulation

3
Health