cd /news/ai-safety/air-raises-50-million-to-secure-the-… · home topics ai-safety article
[ARTICLE · art-121585] src=mlq.ai ↗ pub= topic=ai-safety verified=true sentiment=· neutral

AIR raises $50 million to secure the tools AI agents use

AIR Security raised $50 million in two seed rounds—$10 million led by Sequoia Capital and $40 million led by Greenoaks Capital—to secure the tools and add-ons used by AI agents in enterprises. The startup, founded by Unit 8200 veterans Yair Saban and Niv Hoffman, emerged from stealth on September 1, 2026, and reports more than 20 customers, with about 27% of online add-ons filtered as unsafe. AIR competes with Noma Security, Zenity, Astrix Security, and Operant AI in the emerging agent-security market.

read4 min views2 publishedSep 4, 2026
AIR raises $50 million to secure the tools AI agents use
Image: Mlq (auto-discovered)
  • AIR raised $50 million in two rounds: a $10 million Sequoia-led round and a $40 million Greenoaks-led round. <sup>[1]</sup>
  • The platform discovers enterprise agents, vets the skills and tools they use, and can block unsafe installations or runtime actions. <sup>[2]</sup><sup>[3]</sup>
  • AIR says it has more than 20 customers, about one-quarter of them large enterprises, and filters about 27% of the add-ons and skills it finds online. <sup>[1]</sup>
  • The company is competing with Noma Security, Zenity, Astrix Security and Operant AI in an emerging agent-security market. <sup>[1]</sup>

AIR Security has raised $50 million to monitor the software components that AI agents use to browse the web, access company systems and take actions without a person approving every step. The startup emerged from stealth on September 1, 2026, after closing two seed rounds within weeks of each other. Sequoia Capital led a $10 million round, while Greenoaks Capital led a later $40 million round. [1]

Founded by Yair Saban and Niv Hoffman, veterans of Israel’s Unit 8200 intelligence corps, AIR says its platform can find agents operating across an enterprise, inspect the skills, plugins, Model Context Protocol servers and other components they use, and block interactions that fail a company’s security policies. [1][2]

What AIR is selling #

AIR describes its product as a “context firewall” that sits between an agent and the material entering its working context. That material can include skills, plugins, MCP servers, websites and internal data. The company’s current product suite includes AIR Control for agent discovery and policy, AIR Filter for vetting add-ons, AIR Defend for monitoring agent actions, and AIR Marketplace for distributing approved components. [2]

AIR describes a skill as a reusable set of instructions that teaches an agent how to perform a task. Its broader add-on category includes plugins, MCP servers, sub-agents, commands and hooks. The company says plugins can package several of those elements together, while MCP servers provide external capabilities, including tools, data and actions. [2]

The security concern is that an add-on can do more than the files initially downloaded by an employee. AIR’s research describes skills that fetch external instructions, download scripts or change behavior after installation. The company argues that a skill therefore has to be checked for what it points to and what it does over time, rather than scanned only once at installation. [4]

How the blocking works #

AIR says its filtering process uses static analysis, dependency checks and sandbox detonation before an add-on is approved. The platform can then intercept unsafe installations and monitor agent activity at runtime. AIR says its enforcement layer analyzes actions such as a skill or fetching content from the internet, and checks tools and add-ons against a company whitelist. [1][3]

The company says it continuously re-evaluates components after deployment. That matters because a previously approved skill can become risky when a dependency changes, a developer account is compromised or the skill begins pulling new instructions from elsewhere. AIR says its platform currently filters roughly 27% of the skills and add-ons it finds online. [1]

AIR’s Defend product is intended to detect and respond to agent behavior, while Control handles posture and policy, including what agents exist, what they can access and whether a skill can be revoked across the fleet. Those are company-described capabilities; the sources reviewed for this article do not provide independent performance testing or a false-positive rate. [2][3]

Customers, competition and unanswered figures #

AIR says it has more than 20 customers, with roughly one-quarter classified as large enterprises. Saban told TechCrunch that financial-services and pharmaceutical companies have shown the strongest demand. AIR currently has about 40 employees and plans to use the new capital primarily to hire researchers and expand its go-to-market efforts in the United States and Europe. [1]

The startup is entering a market that already includes Noma Security, Zenity, Astrix Security and Operant AI. TechCrunch described overlapping capabilities including agent discovery, access controls, runtime monitoring and MCP gateways. AIR’s stated point of differentiation is continuous vetting of the add-on ecosystem rather than discovery alone. [1]

The company has not disclosed revenue or valuation in the funding announcement or the reporting reviewed for this article. Its commercial traction and technical claims remain largely company-reported. Independent research published this year found that 26.1% of 31,132 analyzed agent skills contained at least one potentially dangerous pattern, though the researchers cautioned that most flagged examples reflected insecure development practices rather than confirmed malware. [5]

Further sources #

The stories that matter, in one email. Free — unsubscribe anytime.

── more in #ai-safety 4 stories · sorted by recency
── more on @air security 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/air-raises-50-millio…] indexed:0 read:4min 2026-09-04 ·