As artificial intelligence agents become increasingly integrated into the operational fabric of businesses, a critical new cybersecurity frontier is emerging: the AI software supply chain. This burgeoning ecosystem comprises the diverse array of tools, skills, plug-ins, and specialized servers that empower AI agents to interact with internal systems and the external world. Recognizing the inherent risks and the urgent need for oversight, AI security startup AIR has officially emerged from stealth, announcing a significant $50 million in seed funding to build a comprehensive platform for securing this evolving landscape.
The substantial capital infusion, raised across two distinct seed rounds within weeks of each other, signals strong investor confidence in AIR’s mission. The initial $10 million round was led by venture capital powerhouse Sequoia, with the subsequent $40 million round spearheaded by Greenoaks. The participation of notable investors such as Swish, Netz, Zach Frankel (president of Cognition), Yinon Costica (co-founder of Wiz), Ofir Ehrlich (co-founder of Eon), Anne Neuberger, Omer Adam, Varun Anand (co-founder of Clay), and a cohort of other angel investors underscores the perceived urgency and market potential of AI supply chain security.
From Intelligence to Innovation: The Genesis of AIR
AIR was founded by Yair Saban, serving as CEO, and Niv Hoffman, the Chief Technology Officer. Both founders are seasoned veterans of Israel’s elite Unit 8200 intelligence corps, a unit renowned for its expertise in offensive cybersecurity operations. Their background in developing and understanding advanced cyber threats provides a unique perspective on the vulnerabilities inherent in the rapid adoption of AI technologies within enterprise environments. This deep understanding of the offensive landscape informs AIR’s defensive strategy, aiming to preemptively address threats before they can materialize.
The company’s core offering is a sophisticated platform designed to provide comprehensive visibility and control over AI agents operating within an organization. AIR’s solution focuses on three key pillars: discovery, continuous vetting, and enforcement. The platform can autonomously identify all AI agents deployed across a company’s infrastructure, meticulously scrutinize the integrity and security posture of every skill, tool, and component these agents utilize, and proactively block any unauthorized or insecure interactions with internal software or external data sources. Furthermore, AIR is cultivating a curated marketplace of pre-vetted add-ons and skills, offering businesses a trusted source for augmenting their AI agent capabilities.
The Parallel to Operating Systems: A Growing Vulnerability
Saban draws a compelling parallel between the current trajectory of AI agent deployment and the evolution of operating systems in the early days of computing. "In the early 2000s, whenever you installed a driver, the driver didn’t need to be signed," Saban explained to TechCrunch. "Today, every time you install a driver, you see a signature saying who signed it, because the driver is actually loading code into the kernel. You don’t have that with skills or plug-ins or MCPs, and it’s a shame, because it’s the same mechanism, it’s the same lesson, but we haven’t learned it.”
This analogy highlights a critical gap in current security practices. While operating system components and applications have undergone decades of scrutiny and evolved security protocols, the tools and extensions being rapidly adopted by AI agents are largely operating in a less regulated environment. This lack of established security paradigms creates significant risk as AI agents gain broader access to sensitive enterprise systems and external data.
The primary concern, according to Saban, is the potential for sophisticated attackers to exploit this nascent supply chain. Instead of directly attacking a company’s core infrastructure, threat actors can target the AI agents themselves by "poisoning" the data or tools they consume. As AI agents operate with increasing autonomy, accessing databases, interacting with enterprise systems, and connecting to the internet, the integrity of their inputs becomes paramount. Maliciously crafted data or compromised third-party skills could lead to data breaches, unauthorized system modifications, or the exfiltration of sensitive information, all initiated by an agent acting on seemingly legitimate, but ultimately compromised, instructions.
AIR’s Multi-Layered Security Approach
AIR’s platform is engineered to address these emerging threats through a robust, multi-layered approach. The initial layer focuses on visibility, providing an exhaustive inventory of all AI agents active within an organization’s environment. This includes identifying instances where employees might be using unauthorized AI tools or personal accounts for work-related tasks, often bypassing official IT oversight.
The second layer is enforcement. AIR’s solution integrates directly with AI agents, enabling it to intercept and meticulously analyze critical actions, such as the loading of new skills or the fetching of data from external sources. This real-time monitoring allows for immediate detection of suspicious activities.
The final, and perhaps most crucial, layer is continuous vetting. AIR maintains a dynamic whitelist of approved tools, add-ons, and software components that AI agents are permitted to use. This whitelist is not static; it is continuously updated through rigorous evaluation of publicly available resources. AIR actively monitors these external resources for any changes, signs of malicious behavior, or compromise of developer accounts. Saban highlighted the dynamic nature of this threat, noting that a previously secure skill could become a vector for attack if a package it relies on is altered or if its developer’s account is compromised. He revealed that AIR’s current filtering process proactively identifies and blocks approximately 27% of the add-ons and skills it encounters online, underscoring the prevalence of potentially risky components.
Market Traction and Competitive Landscape
AIR claims to have already secured more than 20 customers, with approximately a quarter of these being large enterprises. The company has observed particularly strong demand in highly regulated sectors such as financial services and the pharmaceutical industry, where data security and compliance are paramount. This early traction suggests that the market is acutely aware of the risks associated with unsecured AI agents.
However, AIR is not operating in a vacuum. The AI security space is rapidly attracting significant attention and venture capital. Competitors such as Noma Security, which offers discovery, access controls, and runtime monitoring for AI agents, and Zenity, providing security and governance tools, are also making significant strides. Astrix Security’s identity platform focuses on discovering and controlling AI agents and MCP servers, while Operant AI offers agent protection and an MCP gateway.
The competitive intensity is further underscored by the substantial funding rounds secured by these players. Zenity recently raised a $125 million Series C, and Noma Security garnered $100 million in a Series B round last year. This influx of capital into the AI security sector highlights the perceived strategic importance and growth potential of these solutions.
AIR’s Differentiator: Continuous Re-verification
Saban believes AIR’s key competitive advantage lies in its unwavering focus on the continuous re-verification of the AI agent ecosystem. "Continuously vetting skills and plug-in websites, this is a hard mission to do," he stated. "Gaining visibility over the endpoint, that is easy. Everybody’s going to do it. It’s hard to create a moat around that.” This suggests that while discovering and controlling agents might become a commodity, the ongoing, dynamic security assurance of the tools they employ is a far more complex and defensible challenge.
While acknowledging that AI labs and providers will eventually integrate more robust security checks into their offerings, Saban anticipates that enterprises will continue to seek independent, vendor-agnostic solutions. This preference stems from a desire for comprehensive oversight that transcends the specific AI platforms being used.
Bogomil Balkansky, a partner at Sequoia, echoed this sentiment, emphasizing the fundamental nature of AIR’s approach. "This is not a scanning problem, it is a continuous re-verification problem," Balkansky commented in a statement to TechCrunch. "Inspecting every skill, plugin, MCP server and sub-agent an enterprise’s agents touch, re-inspecting each one every time it changes, in real time and across an entire company’s agent fleet, is an infrastructure problem long before it is a security problem. Air has spent the last year building that pipeline. You do not catch up to it by writing a better scanner." This perspective positions AIR’s solution not merely as a security tool, but as a foundational element of secure AI operations.
Future Growth and Strategic Expansion
With a current team of approximately 40 employees, AIR plans to strategically deploy its newly acquired capital. The primary focus will be on expanding its research and development capabilities, particularly by hiring additional security researchers. Concurrently, the company aims to bolster its go-to-market efforts, with a significant emphasis on expanding its presence in the key markets of the United States and Europe. This strategic investment in both talent and market penetration signals AIR’s ambition to become a leader in the critical domain of AI supply chain security.
The rapid evolution of AI technology presents both unprecedented opportunities and significant challenges. As AI agents become more deeply embedded in business processes, ensuring the security and integrity of their operational environment is no longer an afterthought but a fundamental necessity. AIR’s substantial funding and its focused approach to securing the nascent AI software supply chain position it to play a pivotal role in shaping the future of secure AI adoption. The coming years will likely see a significant race among cybersecurity firms to establish dominance in this critical and rapidly expanding sector, with AIR aiming to be at the forefront of that charge.







