AIR raises $50 million to police the apps and plug-ins that AI agents use at work

A new security startup wants to be the bouncer for all the third-party tools your company's AI agents are quietly loading, before attackers slip something nasty into the mix.

AI2Day Newsdesk4 min read
Macro photograph of a glowing amber spider web stretched across a dark server rack interior, dew droplets catching the rack's blue LED light, sharp focus on the
Share

Key points

  • AIR, an AI security startup, raised $50 million across two seed rounds, with Sequoia leading the first ($10 million) and Greenoaks leading the second ($40 million).
  • The company was founded by two veterans of Israel's Unit 8200 military intelligence unit and currently employs around 40 people.
  • AIR's platform scans and continuously re-checks the skills, plug-ins and MCP servers, the connectors that let AI agents talk to outside software and websites, that companies' agents use.
  • AIR says it currently blocks roughly 27% of the agent add-ons it finds online as unsafe.
  • Rival firms Zenity and Noma have each raised over $100 million in the same category, showing how much investor money is flowing into AI agent security.

If your company uses an AI agent, a piece of software that can carry out multi-step tasks on its own, that agent probably relies on a small army of plug-ins and add-ons to do its job. It might pull data from a spreadsheet tool, browse a website, or fire off an email. Each of those connections is a potential door an attacker could walk through.

AIR, an AI security startup, thinks companies have no idea how many of those doors are open.

What problem is AIR actually solving?

The issue is that AI agents load third-party tools the same way a computer loads software drivers, but without the safety checks we take for granted on our laptops. When you install a driver on a modern PC, it carries a verified digital signature proving who made it. When an AI agent loads a skill or a plug-in, there is typically no such check at all.

"In the early 2000s, whenever you installed a driver, the driver didn't need to be signed," CEO Yair Saban told TechCrunch. "You don't have that with skills or plugins or MCPs, and it's a shame, because it's the same mechanism, it's the same lesson, but we haven't learned it."

The risk he is describing is called "poisoning": instead of hacking an AI system directly, an attacker corrupts the content or tools the AI reads and uses. The agent does the damage itself, without anyone realising something is wrong.

AIR's platform works in three steps. First, it maps every AI agent running inside a company, including tools employees are using on personal accounts without IT approval. Second, it intercepts actions those agents take in real time, such as fetching content from a website or loading a new skill. Third, it checks every tool and add-on against a vetted list the startup maintains and updates continuously.

Who built this, and who is paying for it?

Saban and co-founder Niv Hoffman (CTO) both come from Unit 8200, the Israeli military's intelligence and cyber unit that has produced a string of security company founders. AIR currently has more than 20 customers, roughly a quarter of them large enterprises, with the strongest demand from financial services and pharmaceutical firms.

The $50 million came in two rounds that closed within weeks of each other. Angel investors included Yinon Costica, co-founder of cloud security firm Wiz, and Anne Neuberger, former US Deputy National Security Advisor for cyber.

Round Amount Lead investor
Seed 1 $10 million Sequoia
Seed 2 $40 million Greenoaks
Total $50 million Both rounds

AIR is not alone in this space. Zenity raised $125 million in a Series C round in August, and Noma raised $100 million in a Series B last year. Saban's argument for why AIR can compete is simple: continuously re-checking thousands of changing add-ons is genuinely hard, and he believes rivals are underestimating that.

"This is not a scanning problem, it is a continuous re-verification problem," Sequoia partner Bogomil Balkansky said in a statement.

The new funding will go mainly toward hiring researchers and expanding sales in the US and Europe.

Should ordinary employees care about this?

If your workplace uses AI tools, probably yes. One thing AIR's platform flags is employees using personal AI accounts that IT has not approved, a common habit that can expose company data to outside servers your employer has no contract with or visibility into. Worth checking whether your workplace has a policy on this, and following it.

Common questions

What is an MCP server?

MCP stands for Model Context Protocol. It is a connector, a small piece of software that lets an AI agent talk to an outside service, like a calendar app or a database. Think of it as a plug adapter between the AI and the tool it needs to use.

Is this relevant if my company only uses one AI tool?

Possibly. Even a single AI tool often pulls in multiple plug-ins or data sources behind the scenes. The more those connections multiply, the more there is to check, which is the exact problem AIR is trying to automate.

© 2026 AI2Day