Illustration for: AIR Raises $50M to Police What AI Agents Install

AIR Raises $50M to Police What AI Agents Install

AIR, founded by two Israeli Unit 8200 veterans, came out of stealth with $50 million raised across two seed rounds to continuously vet the skills, tools and add-ons AI agents pull in from the open internet.

By the Numbers

$50M
Total raised
$10M (Sequoia)
Round 1
$40M (Greenoaks)
Round 2
~27%
Add-ons filtered out
20+
Customers
TC
By the AI Desk
Edited by Trace Cohen · Early-stage VC & angel · Founder, New York Venture Partners
2 min read
ShareXLinkedInEmail

THE RUNDOWN

1

AIR came out of stealth with $50 million raised across two seed rounds closed within weeks of each other -- $10 million led by Sequoia, then $40 million led by Greenoaks -- to build a security layer for AI agents' supply chain of skills and tools.

2

Founders Yair Saban and Niv Hoffman are veterans of Israel's Unit 8200 intelligence corps, a background shared by a large share of Israeli cybersecurity founders building this cycle's AI-security startups.

3

AIR's platform discovers which agents are running inside a company, continuously vets the skills and add-ons those agents pull from the open internet, and blocks interactions that fail its security criteria -- filtering out roughly 27% of what it scans.

4

The company already has more than 20 customers, about a quarter of them large enterprises, with the strongest early demand from financial services and pharmaceutical companies -- regulated industries where an ungoverned agent supply chain is a compliance problem, not just a security one.

TC

The VC Read · Trace's Take

Trace Cohen

Two seed rounds in weeks, before any independent benchmark exists, is a bet on Unit 8200 pedigree over proof -- which is a normal and often correct bet in Israeli cybersecurity, but LPs should know that's explicitly what they're underwriting, not a validated 27% filter rate. The real diligence question for any AI-agent startup is whether they even know AIR's category exists yet: agent supply-chain governance is about to become a checkbox on every enterprise security questionnaire, the way SOC 2 did for SaaS.

Analysis

AIR, an AI security startup, came out of stealth with $50 million raised across two seed rounds closed within weeks of each other, TechCrunch reported Sept. 1. Sequoia led the first, $10 million round; Greenoaks led the second, $40 million round.

AIR was founded by Yair Saban, chief executive, and Niv Hoffman, chief technology officer, both veterans of Israel's Unit 8200 intelligence corps -- a pipeline that has produced a large share of this cycle's Israeli AI-security founders, including teams behind Wiz and multiple other cybersecurity companies now valued in the billions. AIR's product addresses a problem specific to the agentic-AI era: as AI agents increasingly pull in third-party "skills," plugins and tool integrations from open marketplaces to extend what they can do, most companies have no visibility into which of those add-ons are running inside their environment, let alone whether any of them are safe.

The platform discovers which agents are active inside a company, continuously vets the skills, tools and components those agents rely on, and blocks any that fail AIR's security criteria from interacting with company software or external systems. Pebblous reported that AIR's filtering currently rejects roughly 27% of the add-ons and skills it scans across the open internet -- meaning more than a quarter of what agents might otherwise pull in automatically fails a basic security check. AIR also runs a marketplace of pre-vetted add-ons, giving customers a safer default path rather than just a blocklist.

AIR also runs a marketplace of pre-vetted add-ons, giving customers a safer default path rather than just a blocklist.

AIR sits adjacent to, but distinct from, the guardrail and red-teaming companies also raising this month -- Lasso Security screens model inputs and outputs at inference time, and Alice builds adversarial test data to red-team models before deployment, while AIR is narrower and more supply-chain-specific: it governs which third-party components an agent is allowed to load in the first place, closer to a software bill-of-materials tool than a content filter. That distinction matters because this week's GitSpawn disclosure showed exactly the kind of attack surface AIR is built to catch -- a malicious component silently triggering code execution the moment an agent interacts with it.

AIR says it already has more than 20 customers, with roughly a quarter of them large enterprises and the strongest demand from financial services and pharmaceutical companies -- regulated industries where an agent quietly pulling in an unvetted skill isn't just a security incident, it's a compliance failure with its own reporting obligations.

A $50 million seed across two rounds closed within weeks, before any public product benchmark or third-party security audit exists, is priced almost entirely on founder pedigree and investor conviction rather than demonstrated defensibility -- Sequoia and Greenoaks are underwriting two Unit 8200 veterans and a live problem, not yet a proven moat, and the 27% rejection rate AIR cites is a self-reported metric from its own scanning methodology rather than an independently verified figure.

ShareXLinkedInEmail

Key Sources

3 sources

Reported by TechCrunch · First reported by TechCrunch · Analysis by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.