AIR has raised $50 million to monitor AI-agent tools and block risky add-ons, targeting a growing security gap as enterprises automate more work.

AIR has emerged from stealth with $50 million in seed funding to help companies identify the AI agents operating in their environments and assess the tools those agents use. The startup is targeting a security gap created by skills, plugins, MCP servers and other add-ons that give agents access to enterprise systems and the internet.
The company raised the money through two rounds that closed within weeks of each other, according to TechCrunch. Sequoia led a $10 million round, while Greenoaks led a subsequent $40 million round. AIR was founded by CEO Yair Saban and CTO Niv Hoffman, who previously served in Israel’s Unit 8200 intelligence corps, according to the report.
AIR says its platform can discover agents across a company, inspect the components they rely on, and intervene when an agent attempts to use an unapproved tool or access an external source that fails security checks. The funding will support additional research hiring and go-to-market expansion in the United States and Europe.
The company’s premise is that AI agents are becoming a new software layer inside businesses, but the components they load are not yet governed like conventional applications or system drivers. A business may deploy an agent for customer support, coding, research or internal operations, while the agent independently invokes a skill, connects to an MCP server or retrieves content from the web.
That flexibility creates a supply-chain problem. A tool that appears safe when approved can later change, download a compromised dependency or be affected by an account takeover. Attackers may also try to manipulate the information an agent consumes rather than directly attacking the underlying model.
AIR’s reported product approach has three parts. A discovery layer looks for agents and identifies employees using AI services outside IT approval, including personal accounts. An enforcement layer intercepts agent actions such as loading a skill or fetching internet content. The platform then compares tools and add-ons against a company policy or AIR’s own catalogue of evaluated components.
TechCrunch reported that AIR maintains a marketplace of vetted skills and add-ons. CEO Yair Saban told the publication that the company’s system currently filters out about 27% of the components it finds online. That figure is a company-reported operating claim; the available evidence does not specify the size of the sample, the testing methodology or how “risky” components are classified.
AIR is entering a market that already includes several vendors focused on agent visibility and control. TechCrunch identified Noma Security, Zenity, Astrix Security and Operant AI as companies offering overlapping capabilities around AI agents, MCP servers, access controls or runtime protection.
The category is attracting substantial venture investment. Zenity raised a reported $125 million Series C in August, while Noma Security previously raised a $100 million Series B. Those financings suggest that investors see agent governance as a distinct enterprise software market, although funding levels do not establish product effectiveness or customer demand.
AIR’s stated differentiation is continuous re-evaluation of the components agents use, rather than a one-time scan. Sequoia partner Bogomil Balkansky described the challenge, in a statement provided to TechCrunch, as an infrastructure problem requiring repeated inspection whenever a skill, plugin or MCP server changes. That is an investor’s assessment of the company’s approach, not independent validation of AIR’s technical advantage.
AIR says it has more than 20 customers, with approximately one-quarter classified as large enterprises, according to Saban’s comments to TechCrunch. The company also said demand has been strongest among financial services and pharmaceutical companies, sectors where data controls, auditability and third-party risk management are already major procurement concerns.
These adoption figures are vendor-reported and were not independently verified in the source material. The report does not name customers, disclose revenue, or provide deployment results showing how often AIR blocks malicious or policy-violating behavior. That leaves open important questions about how the product performs in large, heterogeneous agent environments.
The company has about 40 employees, TechCrunch reported. Its new capital gives AIR room to build a larger research operation and sell into Europe and the U.S., but it also raises the execution challenge: the startup must keep pace with rapidly changing agent frameworks, tool protocols and model-provider policies while integrating with systems that enterprises already use.
For AI product teams, the issue is practical. An agent that can call a database, execute code, send an email or browse the web may have a larger attack surface than a conventional chatbot. Teams building internal agents will need inventories of available tools, clear approval policies, logs of agent actions and a way to revoke access when a component changes.
AIR’s model could appeal to enterprises that use several model providers or build agents through multiple platforms. An independent control layer may be useful when security teams do not want to rely on each AI vendor to implement compatible checks. It could also help organizations address shadow AI, where employees connect unapproved services to company data.
The trade-off is operational. Aggressive blocking can prevent useful workflows, while permissive policies can leave organizations exposed to prompt injection, malicious dependencies or accidental data disclosure. Buyers will need evidence that AIR can distinguish genuinely dangerous behavior from unusual but legitimate agent activity, and that its enforcement layer does not create unacceptable latency or reliability problems.
For developers, continuous verification may become part of the release process for agent skills and integrations. Tool authors could face demands for signed packages, transparent dependencies, change notifications and clearer permission scopes. Those requirements would add friction, but they could also make agent ecosystems easier for enterprise security teams to adopt.
The next signals will be more detailed customer evidence, including named deployments, measurable reductions in risky tool use and independent testing of AIR’s detection claims. Buyers should also watch whether the company publishes technical information about its evaluation pipeline, update monitoring and policy controls.
Competition will be another indicator. The market will likely separate products that primarily discover agents from platforms that continuously inspect and enforce actions across vendors. Developments from Noma Security, Zenity, Astrix Security and Operant AI may clarify whether continuous component verification becomes a standard feature or remains AIR’s central positioning.
AI model providers and agent platforms may also add native controls for tool approval, package signing and runtime monitoring. If those controls become interoperable, AIR could become an independent coordination layer. If they remain fragmented, the startup may find a stronger opening with enterprises that operate mixed agent stacks.
AIR’s funding reflects a real change in enterprise AI deployment: the security boundary is moving beyond the model and into the tools an agent can discover, install and invoke. The company is addressing a concrete operational problem, but its differentiation depends on proving that continuous re-checking produces better protection than existing application security and identity controls.
The most important test will not be the size of AIR’s funding or its early customer count. It will be whether security teams can use the platform without slowing legitimate automation, and whether AIR can maintain accurate, current assessments as agent components change faster than traditional software review cycles.