AIR Raises $50M as AI Agent Security Becomes a Supply Chain Issue

AIR has emerged from stealth with $50 million raised across two seed rounds to secure the tools AI agents use inside companies. Its platform discovers agents, vets skills, plugins, MCP servers and add-ons, and blocks interactions that fail its security criteria.

WTF Index TERMINATOR
◄ Terminator 3 Idiocracy 0 ►

The story centers on AI agents gaining broad access to company systems and creating new security and governance risks, even though the product is defensive.

AIR Raises $50M as AI Agent Security Becomes a Supply Chain Issue

As companies give AI agents broader access to internal systems and the internet, a new security problem is taking shape around the tools those agents rely on. AIR, an AI security startup, is entering the market with $50 million raised across two seed rounds and a product aimed at monitoring that emerging software supply chain.

Why AI Agent Tools Need Oversight

AI agents are beginning to operate across more of a company’s environment. According to AIR’s view of the market, that shift makes the surrounding ecosystem of skills, plugins, MCP servers and add-ons more important than a simple productivity layer.

The company argues that AI agents are starting to look more like operating systems inside businesses. They can connect with databases, enterprise systems and external sources, while relying on separate components that expand what they can do.

That creates a governance gap. Traditional software has established controls around what can run, what can connect, and who approved it. AIR’s central claim is that the same level of scrutiny has not yet caught up with the tools agents load and use.

Yair Saban, AIR’s CEO, compares the issue to software drivers. In his view, companies learned to verify drivers because they can load code into sensitive parts of a system. He says skills, plugins and MCPs need a similar kind of trust signal because they can affect how agents behave and what they access.

What AIR Is Building

AIR was founded by Yair Saban and Niv Hoffman, who is the company’s CTO. Both are veterans of Israel’s Unit 8200 intelligence corps, where they worked on offensive cybersecurity.

The company’s platform is designed to find AI agents running inside a business and then examine the skills, tools and components those agents use. It also aims to stop agents from interacting with software or external sources that do not meet security requirements.

The product has several parts:

  • Discovery of agents active across a company’s environment.
  • Identification of employees using AI tools not approved by IT departments or using personal accounts.
  • An enforcement layer that hooks into agents and intercepts actions such as loading a skill or fetching content from the internet.
  • A whitelist that checks whether tools, add-ons or software should be allowed.
  • A marketplace of vetted add-ons and skills for AI agents.

The important point is that AIR is not only scanning for a component once. Saban says the company continuously evaluates skills and add-ons found online because a previously approved tool can become risky later.

That risk can come from a package it downloads changing, or from a developer’s account being compromised. AIR says its platform currently filters out about 27% of the add-ons and skills it finds online.

Funding and Early Demand

AIR raised its $50 million through two seed rounds that closed within weeks of each other, Saban told TechCrunch. The first round raised $10 million and was led by Sequoia. The second raised $40 million and was led by Greenoaks.

Other participants included Swish, Netz, Zach Frankel, Yinon Costica, Ofir Erlich, Anne Neuberger, Omer Adam, Varun Anand and other angel investors. Zach Frankel is president of Cognition, Yinon Costica is co-founder of Wiz, Ofir Erlich is co-founder of Eon, and Varun Anand is co-founder of Clay.

AIR says it has more than 20 customers. Saban said roughly a quarter of those customers are large enterprises.

The startup has seen the strongest demand in heavily regulated industries, particularly financial services and pharmaceutical companies. That pattern fits the nature of the problem AIR is describing: when AI agents can touch sensitive systems or external content, organizations with strict control requirements have more reason to ask what those agents are using.

AIR currently has around 40 employees. Saban said the new capital will primarily support hiring researchers and expanding go-to-market efforts in the U.S. and Europe.

A Crowded AI Security Market

AIR is entering a category that already includes several companies focused on AI agent security, access control and governance. Noma Security offers discovery, access controls and runtime monitoring for agents, MCP servers and skills. Zenity sells similar security and governance tools.

Astrix Security’s identity platform helps companies discover and control agents and MCP servers. Operant AI offers agent protections as well as an MCP gateway.

Venture money is also flowing into the space. Zenity raised a $125 million Series C in August, while Noma raised a $100 million Series B last year.

Saban’s argument is that AIR’s defensibility comes from the difficulty of continuously vetting the growing ecosystem around AI agents. He sees basic endpoint visibility as something many companies will be able to provide, while ongoing evaluation of skills, plugins, MCP servers and add-ons is harder to reproduce.

Bogomil Balkansky, partner at Sequoia, framed the same idea as an infrastructure challenge. In his emailed statement to TechCrunch, he said the task is not merely scanning, but re-inspecting every skill, plugin, MCP server and sub-agent an enterprise’s agents touch whenever they change, in real time and across a company’s agent fleet.

Why Independent Controls May Matter

Saban acknowledged that AI labs and providers will eventually build more security checks and policies to filter malicious skill and tool usage. Even so, he believes companies will still want an independent product that works across vendors.

That point is central to AIR’s position. If a company uses agents from multiple providers, a security layer tied to only one provider may not give a complete view of what agents are doing across the environment.

The broader implication is that AI agent security is becoming less about the agent alone and more about everything the agent can load, call, read or execute. For businesses adopting agents at scale, the next security question may not be whether an agent is approved. It may be whether every skill, plugin, MCP server and add-on it touches is still safe enough to use.