TECH

AIR Secures $50M to Assist Companies in Evaluating AI Agents’ Skills and Enhancements

As organizations begin to grant AI agents access to an expanding array of their systems, an emerging software supply chain is taking shape around the new tools these AI agents utilize: skills, plug-ins, MCP servers, and add-ons that enable them to interact with the internet.

AI security startup AIR believes there will be a crucial need for companies to monitor this supply chain. It has now emerged from stealth mode with $50 million raised across two seed funding rounds to create that solution.

Founded by Yair Saban (CEO) and Niv Hoffman (CTO), both veterans of Israel’s Unit 8200 intelligence corps with experience in offensive cybersecurity, AIR provides a platform capable of discovering agents operating within organizations. It continuously evaluates any skills, tools, and components used by these agents and prevents them from interacting with software or external sources that fail to meet security criteria. Additionally, it offers a marketplace for vetted add-ons and skills tailored for AI agents.

The two funding rounds occurred within weeks of each other, Saban revealed to TechCrunch, with the first raising $10 million and the second bringing in $40 million. Sequoia led the initial round, while Greenoaks spearheaded the second, as noted by Saban. Other participants included Swish, Netz, and Zach Frankel (president of Cognition), Yinon Costica (co-founder of Wiz), Ofir Ehrlich (co-founder of Eon), Anne Neuberger, Omer Adam, Varun Anand (co-founder of Clay), and several angel investors.

AIR’s proposition is centered on the idea that the extensive use of AI agents in businesses is beginning to resemble operating systems, yet the tools they use or the software they can install haven’t been granted the same level of oversight typically reserved for drivers or applications.

“In the early 2000s, when you installed a driver, it didn’t have to be signed. Nowadays, any driver you install comes with a signature identifying the signer, because it actually loads code into the kernel,” explained Saban. “We don’t have that for skills, plug-ins, or MCPs—which is unfortunate, as it’s the same principle; the lesson remains unlearned.”

He argues that the significant risk emerges as AI agents begin to operate more autonomously across databases and enterprise systems while connecting to the internet, allowing attackers to corrupt the content consumed by an AI agent rather than attempting a direct attack.

The startup claims it can address this issue through a visibility product that identifies active agents within a company’s environment and pinpoints employees using AI tools that lack IT department approval or personal accounts. Furthermore, it employs an enforcement layer that integrates with agents to monitor and analyze actions, such as loading skills or retrieving content from the internet. AIR also checks the tools, add-ons, or software an agent intends to use against a whitelist maintained by the startup.

Saban noted that the whitelist is upheld by scrutinizing skills and add-ons publicly available online for any changes or malicious activities, as a previously approved skill could turn risky if its downloaded package alters or if its developer’s account is compromised. Currently, AIR filters out approximately 27% of the add-ons and skills it encounters online.

AIR asserts that it has secured over 20 customers, with Saban indicating that about a quarter of these are major enterprises. The company has observed the most demand in highly regulated sectors, especially financial services and pharmaceuticals.

However, AIR is not the sole player in this field. Noma Security provides discovery, access controls, and real-time monitoring for agents, MCP servers, and skills, while Zenity offers security and governance tools that are similarly functional. Additionally, Astrix Security’s identity platform helps companies discover and manage agents and MCP servers, and Operant AI provides protections for agents along with an MCP gateway.

There is also considerable venture capital interest in this category. Zenity secured a $125 million Series C in August, while Noma raised $100 million Series B last year.

Saban believes AIR’s competitive edge lies in its capability to continuously assess the growing ecosystem of skills and add-ons surrounding AI agents. “The ongoing evaluation of skills and plug-in websites is a challenging task. Gaining visibility over the endpoint is relatively straightforward; everyone can do that. Creating a protective moat around it is much more difficult,” he said.

The CEO acknowledged that AI labs and providers will eventually incorporate security checks and policies to eliminate malicious skill and tool utilization. However, he believes companies will still prefer an independent product that functions across various vendors.

“This is not merely a scanning issue; it’s about continuous re-verification,” remarked Bogomil Balkansky, a partner at Sequoia, in an email to TechCrunch. “Evaluating every skill, plugin, MCP server, and sub-agent that an enterprise’s agents interact with—reevaluating each one whenever it changes, in real time, across the entire agent fleet of the company—is a foundational infrastructure challenge long before it becomes a security problem. AIR has spent the last year creating that pipeline. You can’t catch up by just developing a better scanner.”

Currently, AIR employs about 40 people. Saban stated that the newly acquired capital will primarily be directed toward hiring researchers and expanding the company’s market efforts in the U.S. and Europe.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Leave a Reply

Your email address will not be published. Required fields are marked *