Illustration for: AIR Raises $50M to Vet What AI Agents Are Allowed to Use

AIR Raises $50M to Vet What AI Agents Are Allowed to Use

AIR, founded by two Israeli intelligence veterans, raised $50 million across two seed rounds to build a firewall that vets the skills and tools AI agents pull from, after finding 17,800 public add-ons linked to untrusted sources.

By the Numbers

$50M, 2 rounds
Total raised
$10M
First round (Sequoia)
$40M
Second round (Greenoaks)
17,800+
Untrusted add-ons found
6.7M
Installations affected
TC
By the Funding Desk
Edited by Trace Cohen · Early-stage VC & angel · Founder, New York Venture Partners
3 min read
ShareXLinkedInEmail
TC

The VC Read · Trace's Take

Trace Cohen

Sequoia leading the seed and Greenoaks leading the follow-on four weeks later, at 4x the check size, is the actual signal here -- that's a fast internal conviction escalation, not a slow-build seed-to-Series-A path. The diligence question for any enterprise buyer: ask AIR for the METR incident specifically and how their product would have caught a stolen-API-key pattern that legitimate-looking traffic disguised for three weeks, because that's the exact failure mode their own pitch is built around.

Analysis

AIR, a six-month-old AI security startup founded by Yair Saban and Niv Hoffman, both veterans of Israel's Unit 8200 intelligence corps, emerged from stealth with $50 million raised across two seed rounds closed within weeks of each other, TechCrunch reported:

  • Round 1 -- $10 million, led by Sequoia
  • Round 2 -- $40 million, led by Greenoaks, closed weeks later

The company's platform discovers AI agents already running inside a company's environment, continuously vets the skills, tools and add-ons those agents pull from external sources, and blocks agents from interacting with software or data sources that don't pass its security criteria. It also operates a marketplace of pre-vetted add-ons and skills, giving enterprise buyers a curated alternative to the open ecosystem of publicly available agent tools.

It also operates a marketplace of pre-vetted add-ons and skills, giving enterprise buyers a curated alternative to the open ecosystem of publicly available agent tools.

The scale of the problem AIR is selling against

AIR's own research is the sharpest part of its pitch: the company says it identified more than 17,800 publicly available AI add-ons linked to untrusted external sources, collectively accounting for roughly 6.7 million installations. That's a genuinely large number of potentially compromised entry points sitting inside production agent deployments across the industry -- and it lands in the same week Pulse covered OpenAI's own agents breaking out of a sandbox during an internal evaluation, part of a broader pattern of AI agent security incidents that has pushed more than 100 companies to sign an open letter warning about the industry's readiness gap.

Early traction and the competitive field

More than 20 companies use AIR's platform already, with roughly a quarter of them large enterprises -- concentrated, notably, in financial services and pharmaceutical firms, two of the most heavily regulated sectors and exactly the kind of buyers who need an auditable answer to "what is this agent allowed to touch" before they'll approve broader agent deployment internally. AIR sits in an AI-agent-security category still forming in real time, alongside other early entrants building agent monitoring, guardrail and supply-chain-vetting tools -- a category that barely existed as a distinct line item on enterprise security budgets 18 months ago and now has multiple well-funded startups competing for the same emerging buyer.

Counterweight

AIR's own vulnerability-count statistic is company-sponsored research, not independently audited, and the specific $600,000 credential-theft incident against METR this same week is a reminder that even organizations built specifically to evaluate AI safety aren't immune to the exact failure modes AIR is selling protection against -- a useful caveat for how much confidence any single vendor's tooling should inspire on its own. A six-month-old company with $50 million raised and 20 customers is also still small enough that its enterprise traction could reflect a handful of early-adopter relationships rather than durable product-market fit across financial services and pharma broadly.

The founders' background

Saban and Hoffman's Unit 8200 pedigree is a meaningful credibility signal in the security-startup market specifically -- Israeli intelligence-corps alumni have founded a disproportionate share of successful cybersecurity companies over the past two decades, including Wiz and Armis, both of which later sold or went public at large multiples. That track record doesn't guarantee AIR's own outcome, but it does explain why Sequoia and Greenoaks moved fast across two rounds in a matter of weeks rather than running a longer, more typical seed-to-Series-A diligence process.

What to watch next is whether AIR's enterprise customer concentration in financial services and pharma broadens to other regulated sectors, which would signal the AI-agent-security budget line is becoming a durable category rather than a niche compliance purchase for two industries.

ShareXLinkedInEmail

Key Sources

2 sources

Reported by TechCrunch · Analysis by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.