AIR Secures $50 Million to Assist Businesses in Evaluating AI Agents’ Capabilities and Enhancements
As organizations increasingly grant AI agents access to a wider array of their systems, a new software supply chain is emerging surrounding the tools utilized by these AI agents, including skills, plugins, MCP servers, and add-ons that enable their internet interactions.
AI security startup AIR emphasizes the necessity for companies to keep an eye on this developing supply chain. After recently emerging from stealth mode, the startup has secured $50 million through two seed funding rounds to create a solution to address this requirement.
Founded by Yair Saban (CEO) and Niv Hoffman (CTO), both of whom are former members of Israel’s Unit 8200 intelligence corps with expertise in offensive cybersecurity, AIR provides a platform aimed at identifying agents operating within organizations. It thoroughly evaluates any skills, tools, and components leveraged by these agents, ensuring they do not interact with software or external resources that fail to meet security standards. Moreover, the platform includes a marketplace for verified skills and add-ons tailored specifically for AI agents.
The two funding rounds happened in quick succession, as Saban shared with TechCrunch. The first round raised $10 million, followed by a second round that garnered $40 million. Sequoia led the initial round, while Greenoaks headed the second, as noted by Saban. Other investors comprise Swish, Netz, Zach Frankel (president of Cognition), Yinon Costica (co-founder of Wiz), Ofir Ehrlich (co-founder of Eon), Anne Neuberger, Omer Adam, Varun Anand (co-founder of Clay), alongside various angel investors.
AIR’s assertion is that the widespread integration of AI agents into organizations is starting to resemble the evolution of operating systems; however, the tools they employ and the software they can install often lack the oversight usually expected for drivers or applications.
“In the early 2000s, when you installed a driver, a signature wasn’t required. These days, any driver you install must be signed, as it loads code into the kernel,” Saban explained. “We lack that requirement for skills, plugins, or MCPs—which is regrettable because the underlying principle still holds; the lesson remains unlearned.”
He pointed out that considerable risks arise as AI agents become more autonomous across databases and enterprise systems while connecting to the internet, enabling malicious actors to manipulate the content consumed by an AI agent rather than launching direct attacks.
The startup asserts it can tackle this issue with a visibility product that detects active agents within a company’s environment and pinpoints employees using AI tools that have not received IT department approval or involve personal accounts. The platform integrates an enforcement layer that monitors and analyzes activities, such as loading skills or accessing internet content. AIR also cross-references the tools, add-ons, or software an agent intends to utilize against a maintained whitelist.
Saban noted that the whitelist is curated by monitoring skills and add-ons available online for any alterations or malicious behavior, as an approved skill could become harmful if its downloaded package changes or the developer’s account is compromised. Currently, AIR filters out approximately 27% of the add-ons and skills it encounters online.
AIR reports having more than 20 clients, with Saban mentioning that around a quarter of these are large enterprises. The firm has observed rising demand in highly regulated sectors, especially in financial services and pharmaceuticals.
Nonetheless, AIR is not the sole player in this field. Noma Security provides discovery, access controls, and real-time monitoring for agents, MCP servers, and skills, while Zenity offers security and governance tools with overlapping functionality. Additionally, Astrix Security’s identity platform aids companies in discovering and managing agents and MCP servers, and Operant AI delivers protections for agents along with an MCP gateway.
There is a notable interest from venture capital in this space. Zenity raised $125 million in Series C funding last August, while Noma obtained $100 million in Series B funding the previous year.
Saban believes AIR’s competitive edge lies in its capacity to continuously evaluate the growing ecosystem of skills and add-ons associated with AI agents. “The ongoing evaluation of skills and plugin websites is quite a challenging task. Achieving visibility over the endpoint is relatively straightforward; anyone can accomplish that. Creating a protective barrier around it is considerably more complex,” he stated.
The CEO acknowledged that AI labs and providers are likely to eventually establish security checks and policies to mitigate the use of harmful skills and tools. However, he is convinced that companies will still favor an independent product that functions across various vendors.
“This isn’t merely about scanning; it relates to continuous re-verification,” mentioned Bogomil Balkansky, a partner at Sequoia, in a communication to TechCrunch. “Evaluating every skill, plugin, MCP server, and sub-agent that interacts with an enterprise’s agents—reassessing each one whenever it changes, in real time, across the entire company’s agent fleet—is a foundational infrastructure challenge long before it becomes a security concern. AIR has spent the past year constructing that vital pipeline. You cannot catch up by simply developing a better scanner.”
Currently, AIR employs around 40 individuals. Saban indicated that the newly acquired funds will be primarily directed towards hiring researchers and enhancing the company’s market efforts in the U.S. and Europe.
When you make a purchase through links in our articles, we may earn a small commission. This does not influence our editorial independence.
