Decoding the business of technology.
examnity.

AIR Secures $50M to Secure Enterprise AI Agents Against Malicious Add-ons

According to TechCrunch, AIR has emerged from stealth with $50 million raised across two seed rounds to build what its founders describe as the missing supply-chain layer for enterprise AI.

Grace Linwood, Silicon Valley Culture & Venture Chronicler · updated September 01, 2026

AIR Secures $50M to Secure Enterprise AI Agents Against Malicious Add-ons

A new AI security startup is betting the next major attack surface won't be a human clicking a bad link — it'll be an autonomous agent quietly loading the wrong skill at 3 a.m. According to TechCrunch, AIR has emerged from stealth with $50 million raised across two seed rounds to build what its founders describe as the missing supply-chain layer for enterprise AI.

The pitch lands like this: as companies hand AI agents keys to databases, CRMs, and the open internet, those agents are silently installing skills, plug-ins, MCP servers, and add-ons — with little of the vetting we've come to expect from operating systems. AIR, founded by Unit 8200 veterans Yair Saban (CEO) and Niv Hoffman (CTO), wants to be the bouncer standing at that loading dock.

The driver-signature analogy

Sitting across from Saban on this question, you hear an old cybersecurity frustration dressed up in newer clothes. "In the early 2000s, whenever you installed a driver, the driver didn't need to be signed," he told TechCrunch. "Today, every time you install a driver, you see a signature saying who signed it... You don't have that with skills or plug-ins or MCPs, and it's a shame, because it's the same mechanism, it's the same lesson, but we haven't learned it."

That framing — agents as a new kind of OS — shapes AIR's product. The platform discovers agents running across a company's environment, flags employees using AI tools IT never approved, and intercepts actions like loading a skill or pulling content from the web. A whitelist, continuously refreshed, decides what passes. AIR says its filter currently rejects roughly 27% of the add-ons and skills it finds online — a sobering figure if you've been treating agents as harmless interns.

The money, the customers, and the crowded door

The capital structure hints at how fast this conviction caught fire. Sequoia led the first $10 million round; Greenoaks led a $40 million follow-on that closed within weeks. Among the angels: Zach Frankel (president at Cognition), Yinon Costica (co-founder of Wiz), Ofir Ehrlich (co-founder of Eon), Anne Neuberger, Varun Anand (co-founder of Clay), and others — a roster that reads like the guest list for a "what worries you about agents" dinner.

AIR claims more than 20 customers, with roughly a quarter large enterprises — heavily weighted, Saban says, toward financial services and pharma, the regulated corners where a poisoned agent payload becomes a board-level incident rather than a Slack thread.

Still, AIR is hardly alone. AWS pushed its own answer into general availability around the same window: Agent Registry, a searchable, governed catalog for agents, tools, and skills with built-in access control and lifecycle tracking. The two products aren't identical — AIR sells visibility and enforcement, AWS sells a registry — but both start from the same premise: agent sprawl has already outgrown the spreadsheets trying to track it.

What to watch

The real test won't be the demo; it'll be whether enterprises let a startup sit in the path between their agents and the internet. Keep an eye on design-partner announcements, the first public incident where a previously vetted add-on turns malicious, and whether that 27% rejection rate climbs as attackers begin poisoning skills that already passed muster.