Securing the Autonomous Frontier: AI Security Startup AIR Emerges From Stealth With $50 Million to Guard the Emerging Agent Supply Chain

Executive Overview

As artificial intelligence rapidly transitions from a conversational novelty to an autonomous operational force within the enterprise, a hidden security crisis is quietly taking shape. Modern corporations are no longer just deploying chatbots; they are giving AI agents deep, functional access to internal databases, mission-critical enterprise systems, and the open internet. To achieve these complex workflows, these agents rely on a burgeoning ecosystem of external tools: plug-ins, custom skills, add-ons, and Model Context Protocol (MCP) servers.

However, this growing reliance has birthed a brand-new threat vector: the AI software supply chain.

Enter AIR, an ambitious cybersecurity startup founded by alumni of Israel’s elite Unit 8200 intelligence corps. Emerging from stealth mode with a staggering $50 million secured across two rapid-fire seed rounds, AIR is building the infrastructure necessary to monitor, vet, and govern the tools that AI agents consume. Led by prominent venture capital firms Sequoia and Greenoaks, the company’s massive early funding underscores a terrifying reality for modern CISOs: the software driving corporate AI agents lacks even the most basic security oversight.

In this deep dive, we examine how AIR plans to protect the enterprise, the mechanics behind the emerging AI agent supply chain crisis, the competitive landscape crowding the market, and why industry leaders believe continuous re-verification will define the next decade of cybersecurity.


Detailed Chronology: From Concept to a $50 Million Stealth Launch

The genesis of AIR traces back to the digital trenches of Unit 8200, the cyber-warfare and intelligence agency of the Israel Defense Forces. Co-founders Yair Saban (CEO) and Niv Hoffman (CTO) spent their formative professional years navigating offensive cybersecurity—a background that uniquely positions them to anticipate how malicious actors will exploit the blind spots of enterprise AI.

As enterprises began deploying generative AI agents en masse, Saban and Hoffman recognized a critical vulnerability. The tools empowering AI agents—external code libraries, plug-ins, and data connectors—were being adopted with reckless abandon, operating entirely outside the purview of traditional IT and security departments. To combat this impending crisis, the founders established AIR and immediately set to work building a comprehensive platform designed to discover, vet, and control agentic ecosystems.

The market response to their vision was swift and overwhelming. According to Saban, AIR closed two separate seed funding rounds within a matter of weeks of each other:

  • The First Seed Round ($10 Million): Led by Sequoia Capital, this initial tranche established foundational capital and validated the core thesis around AI supply chain security.
  • The Second Seed Round ($40 Million): Led by Greenoaks, this gargantuan follow-on round brought the startup’s total seed funding to an eye-watering $50 million.

The rounds also attracted a high-profile roster of strategic angel investors and industry heavyweights, including Swish, Netz, Zach Frankel (President of Cognition), Yinon Costica (Co-founder of Wiz), Ofir Ehrlich (Co-founder of Eon), Anne Neuberger, Omer Adam, and Varun Anand (Co-founder of Clay).

With a lean team of approximately 40 employees, AIR is using this fresh capital to aggressively scale its operations. The funding will primarily fuel the expansion of research and development teams and accelerate go-to-market strategies across the United States and Europe.


The Core Problem: The AI Agent Supply Chain and "Kernel-Level" Vulnerabilities

To understand why investors are pouring millions into AIR, one must understand how AI agents function and where the security paradigms are failing.

According to AIR’s leadership, the way modern corporations utilize AI agents is beginning to mirror full-fledged operating systems. Agents are granted autonomy to execute workflows, read and write data, and pull resources from the web. Yet, the components they install—their skills, plug-ins, and MCP servers—enjoy an astonishing lack of regulatory oversight compared to traditional enterprise software.

Yair Saban draws a direct parallel to the evolution of operating system security in the early 2000s:

"In the early 2000s, whenever you installed a driver, the driver didn’t need to be signed. Today, every time you install a driver, you see a signature saying who signed it, because the driver is actually loading code into the kernel. You don’t have that with skills or plug-ins or MCPs, and it’s a shame, because it’s the same mechanism, it’s the same lesson, but we haven’t learned it."

The Threat of Indirect Prompt Injection and Poisoned Content

As AI agents grow more autonomous, traditional direct hacking attempts (like SQL injections or malware payloads targeting a system directly) are being supplemented by more insidious methods. The most pressing risk is indirect prompt injection.

Instead of attacking the AI model directly, sophisticated threat actors are poisoning the content that an AI agent consumes while performing its tasks. For example, if an AI agent is tasked with summarizing customer feedback, reviewing web pages, or querying unstructured corporate documents, a malicious actor can embed hidden instructions within that data. When the agent reads the poisoned text, it misinterprets the data as a system command, causing it to exfiltrate sensitive database records, execute unauthorized code, or compromise enterprise infrastructure.

AIR’s Three-Pronged Defense Architecture

To neutralize these threats, AIR has engineered an end-to-end platform structured around three core operational pillars:

  1. Discovery and Visibility: The platform sweeps the enterprise environment to detect all active AI agents—including "shadow IT" deployments where employees utilize unapproved AI tools or personal corporate accounts without IT clearance.
  2. Real-Time Enforcement Layer: AIR hooks directly into active agents to intercept and analyze actions in real time. Whether an agent attempts to load a new custom skill or fetch external data from the open internet, the enforcement layer blocks actions that fail pre-set security criteria.
  3. The Vetted Marketplace and Whitelist: AIR maintains a proprietary whitelist of safe, verified add-ons and software tools. If an agent attempts to pull a tool that hasn’t cleared vetting, it is automatically blocked.

Supporting Context, Metrics, and Market Traction

Despite launching out of stealth with zero prior public fanfare, AIR enters the market with significant operational validation. The startup already boasts over 20 enterprise-grade customers, with roughly a quarter of them representing massive, multinational corporations.

Industry Demands and Vetting Metrics

Unsurprisingly, demand is concentrated in sectors dealing with sensitive data and strict regulatory compliance. Saban notes that AIR has seen its strongest traction within financial services and pharmaceutical companies—industries where a data leak or a compromised AI workflow can result in catastrophic financial or legal penalties.

Maintaining platform integrity requires constant vigilance. AIR continuously evaluates open-source and publicly available skills and add-ons for malicious behavior, hidden vulnerabilities, and sudden structural changes. According to internal platform data, AIR currently filters out approximately 27% of all add-ons and skills it discovers online, highlighting just how heavily polluted the public AI tool ecosystem has become.

A previously approved skill can quickly transform into a liability if the package it depends on is updated with malicious code, or if the original developer’s account is hijacked by bad actors. This reality transforms security from a one-time audit into an ongoing operational challenge.


Official Statements and Industry Perspectives

The urgency of AIR’s mission has drawn enthusiastic endorsements from its financial backers, who view the company’s infrastructure as an absolute necessity for the enterprise AI boom.

Bogomil Balkansky, a partner at Sequoia, articulated the scale of the challenge in an emailed statement to TechCrunch:

"This is not a scanning problem, it is a continuous re-verification problem. Inspecting every skill, plugin, MCP server and sub-agent an enterprise’s agents touch, re-inspecting each one every time it changes, in real time and across an entire company’s agent fleet, is an infrastructure problem long before it is a security problem. Air has spent the last year building that pipeline. You do not catch up to it by writing a better scanner."

While some industry skeptics might wonder whether major AI model providers and foundational labs will eventually bake these safety checks directly into their models, Saban remains confident. He argues that enterprises will always demand an independent, vendor-agnostic security layer that functions uniformly across diverse agent fleets, regardless of which underlying model powers them.


The Competitive Landscape: A Crowded Venture Market

AIR is far from the only player recognizing the dangers of the agentic software supply chain. A well-funded wave of specialized security startups is racing to secure the enterprise AI layer, backed by massive venture capital allocations:

  • Noma Security: Offers comprehensive discovery, access controls, and runtime monitoring for AI agents, MCP servers, and skills. Noma raised a massive $100 million Series B funding round last year.
  • Zenity: Provides robust security, discovery, and governance tools tailored for enterprise AI applications, underscored by a massive $125 million Series C funding round secured in August.
  • Astrix Security: Focuses heavily on an identity-centric platform that allows security teams to discover and control third-party agents and MCP servers.
  • Operant AI: Specializes in runtime agent protections alongside a dedicated MCP gateway.

Despite the intense competition, AIR’s leadership believes their true corporate moat lies not in endpoint visibility—which Saban dismisses as a solved commodity—but in the grueling, continuous backend work of vetting the sprawling ecosystem of third-party plugins, code repositories, and web-connected skills.


Future Outlook: Securing the Autonomous Enterprise

As enterprises cross the Rubicon from experimental generative AI pilots to fully autonomous agent deployments, the surface area for cyberattacks will expand exponentially. Companies are no longer just securing human users logging into dashboards; they are securing autonomous software entities acting on behalf of the business across millions of lines of external code.

With $50 million in fresh capital, an elite pedigree from Unit 8200, and a growing roster of enterprise clients in regulated sectors, AIR is positioning itself as an indispensable traffic cop for the agentic economy. Whether through its proprietary threat whitelists, its continuous re-verification pipeline, or its curated marketplace of safe integrations, AIR’s emergence from stealth marks a defining turning point. The industry is finally waking up to a stark truth: if AI agents are going to run the enterprise, someone needs to make sure they aren’t bringing a Trojan horse through the front door.

Leave a Reply

Your email address will not be published. Required fields are marked *