AIR Raises $50M to Secure AI Agents & Their Software Supply Chain
AI security startup AIR has raised $50 million to secure the rapidly growing software supply chain for AI agents, offering a platform that discovers, continuously vets, and blocks unapproved skills and add-ons to mitigate critical enterprise risks. The funding will fuel expansion into the US and European markets and enhance its continuous re-verification technology.

Key Takeaways
- AIR raised $50M to secure the emerging AI agent software supply chain.
- Its platform discovers agents, vets skills/add-ons, and blocks risky behaviors.
- The core value proposition is continuous re-verification of agent components.
- Strong demand observed in regulated industries like finance and pharma.
- Funds will support R&D and market expansion in the U.S. and Europe.
AIR Secures $50M to Bolster AI Agent Security in Emerging Software Supply Chain
As artificial intelligence agents increasingly integrate into enterprise systems, granting them broader access, a new software supply chain is rapidly taking shape. This ecosystem comprises the various skills, plugins, MCP servers, and add-ons that empower AI agents to interact with the internet and perform complex tasks. Recognizing the critical need to secure this evolving landscape, AI security startup AIR has emerged from stealth with an impressive $50 million in seed funding.
According to TechCrunch AI, the capital was raised across two seed rounds, with Sequoia leading the initial $10 million round and Greenoaks heading the subsequent $40 million. Additional investors included Swish, Netz, and a roster of prominent angel investors. Founded by Israeli Unit 8200 intelligence corps veterans Yair Saban (CEO) and Niv Hoffman (CTO), AIR aims to provide a robust platform for monitoring and securing this nascent AI agent supply chain.
Addressing a Nascent Security Challenge
AIR's founders draw parallels between the current state of AI agent tooling and the early days of operating systems, where software drivers lacked proper oversight. Just as unsigned drivers once posed significant risks by loading code directly into a system's kernel, unvetted AI agent skills and plugins can introduce vulnerabilities. As AI agents gain autonomy and connect to diverse enterprise systems and the internet, the risk of attackers "poisoning" the content they consume, rather than directly attacking the agents, becomes a significant concern.
AIR's Comprehensive Security Platform
AIR's platform offers a multi-faceted approach to AI agent security:
- Discovery: It identifies all AI agents operating within a company's environment, including those deployed by employees without IT approval or via personal accounts.
- Enforcement: An enforcement layer intercepts and analyzes agent actions, such as loading new skills or fetching external content, to ensure compliance with security policies.
- Continuous Vetting & Whitelisting: AIR maintains a dynamic whitelist of approved tools, add-ons, and software. It continuously evaluates openly available skills and add-ons for changes and potential malicious behavior, recognizing that even previously approved components can become risky if their underlying packages change or developer accounts are compromised. The company reports that its platform currently filters out approximately 27% of the add-ons and skills it discovers online.
The startup also plans to offer a marketplace of pre-vetted add-ons and skills, simplifying secure adoption for enterprises.
Competitive Landscape and Differentiation
While AIR is carving out its niche, it operates in a competitive space with other well-funded players like Noma Security, Zenity, Astrix Security, and Operant AI, all offering similar security and governance tools for AI agents. However, AIR's CEO, Yair Saban, emphasizes that the company's core differentiator lies in its commitment to continuously vetting the dynamic ecosystem of AI agent skills and add-ons. This ongoing re-verification, rather than static scanning, is what Sequoia partner Bogomil Balkansky describes as an "infrastructure problem long before it is a security problem," highlighting AIR's robust pipeline built to address this.
With over 20 customers, including a quarter being large enterprises, AIR is seeing strong demand, particularly in heavily regulated sectors like financial services and pharmaceuticals. The new capital will primarily support hiring researchers and expanding go-to-market efforts across the U.S. and Europe.
Why This Matters for AI Product Managers
For AI Product Managers, the emergence of companies like AIR underscores a critical evolution in the AI product lifecycle: security and governance for autonomous agents. As agents move from experimental tools to core operational components, their ability to interact with internal systems and external services creates complex attack surfaces. PMs must proactively integrate security-by-design principles into their agent roadmaps, considering how agents will be discovered, monitored, and controlled post-deployment. This includes planning for robust authentication, authorization, and audit trails for agent actions, as well as defining clear policies for skill and tool adoption.
The competitive landscape in AI agent security also highlights the growing enterprise demand for trusted, compliant AI solutions. PMs developing AI agents for regulated industries, such as financial services or healthcare, will find that robust security frameworks are not just "nice-to-haves" but fundamental requirements for market adoption and GTM strategy. Partnering with or integrating solutions like AIR's could become a key differentiator, enabling a safer, more transparent, and auditable deployment of AI agents, thereby accelerating enterprise trust and adoption.
Furthermore, the concept of a "continuous re-verification problem" rather than just a "scanning problem" should influence how PMs think about agent lifecycle management. Agent capabilities and their underlying components are dynamic. PMs need to consider how their products will support ongoing vulnerability assessment, automatic policy enforcement, and adaptation to new threats. This could involve building APIs for security integrations or designing agent architectures that inherently support secure component management and runtime monitoring, ensuring product longevity and mitigating reputational risk.