Artificial intelligence security startup AIR publicly launched on September 1, securing $50 million across two seed rounds to monitor and secure software supply chains for autonomous AI agents. Founded by Unit 8200 veterans Yair Saban and Niv Hoffman, the company targets unvetted third-party plug-ins and skills creating enterprise vulnerabilities.
Policing the Enterprise Autonomous Tool Supply Chain
Corporate deployment of autonomous AI agents has accelerated faster than traditional security architecture can adapt. According to reports from TechCrunch, AI agents routinely utilize digital skills, third-party plug-ins, and Model Context Protocol (MCP) servers to independently pull internet resources and execute database tasks. Because these unvetted software add-ons lack kernel-level signature verification, malicious actors can easily poison underlying code or dependency chains. AIR steps into this emerging governance gap with a platform designed to discover, vet, and enforce compliance across corporate networks.
The Bottom Line
- Capital Influx: AIR secured $50 million total across two rapid-fire seed rounds led by Sequoia Capital ($10 million) and Greenoaks Capital ($40 million).
- High-Risk Ecosystem: The startup’s scanning mechanism currently filters out approximately 27% of evaluated online add-ons and skills due to security flags.
- Target Verticals: Early adoption concentrates in heavily regulated sectors, with financial services and pharmaceuticals making up its 20-plus corporate client base.
Mapping AIR’s Three-Layer Security Architecture
The core vulnerability facing enterprise risk managers today isn’t the core large language model itself, but the decentralized web of extensions connected to it. Traditional firewalls were engineered for static applications rather than autonomous systems that interpret natural language prompts and cross software boundaries independently. To counter this threat vector, AIR deploys a three-layer operational model consisting of discovery, vetting, and enforcement.
The platform first inventories all active agents running within an organization, flagging shadow AI tools and unauthorized employee add-ons. Next, it intercepts plugin loads at runtime, checking them against a continuously maintained whitelist. Finally, the system automatically blocks non-compliant software and suspicious external API calls before agents execute them. This proactive approach mirrors the evolution of operating system driver security from the early 2000s.
| Funding Round | Capital Raised | Lead Investor |
|---|---|---|
| Initial Seed | $10 Million | Sequoia Capital |
| Second Seed | $40 Million | Greenoaks Capital |
| Total Seed Capital | $50 Million | Combined |
Market Traction and Competitive Positioning
AIR enters a fragmented competitive landscape that includes specialized agent governance providers like Noma Security, Zenity, Astrix Security, and Operant AI. However, few competitors have matched AIR’s early funding scale or secured an equivalent angel investor roster, which includes backing from prominent figures associated with Wiz and Cognition. With more than 20 corporate clients—roughly a quarter of which are large enterprises—the company is positioning itself as an infrastructure layer for institutions where operational failures carry severe regulatory liabilities.

As financial institutions increasingly rely on automated agents to draft compliance filings, process transactions, and cross-reference customer records, demand for strict access controls will intensify. Market consolidation is expected to favor platforms possessing the broadest skill datasets and lowest false-positive rates. By establishing standardized vetting procedures now, AIR aims to become a dependency for enterprise risk management teams navigating the autonomous software era.
Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute financial advice.