A quiet but significant shift is underway in how businesses deploy artificial intelligence. As organizations hand AI agents broader access to internal systems, a new kind of software supply chain is taking shape around the tools those agents depend on - skills, plug-ins, MCP servers, and add-ons that allow them to interact with external services and the wider internet. That expanding ecosystem is creating security blind spots that few companies have yet addressed in any structured way.
Into that gap steps AIR, an AI security startup that has now emerged from stealth mode with $50 million in funding spread across two seed rounds. The company is building a platform designed to give enterprises visibility into the AI agents operating within their environments, along with the ability to vet and control the tools those agents use.
Founders With an Intelligence Background
AIR was co-founded by Yair Saban, who serves as CEO, and Niv Hoffman, who serves as CTO. Both are veterans of Unit 8200, the elite signals intelligence division of the Israel Defense Forces, where they focused on offensive cybersecurity operations. That background informs the company's threat modeling approach, which centers on anticipating how attackers will target AI infrastructure rather than reacting after the fact.
The two funding rounds closed within weeks of each other. The first, a $10 million raise, was led by Sequoia. The second, a $40 million round, was led by Greenoaks. Additional participants included Swish, Netz, and a notable group of angel investors: Zach Frankel, president of Cognition; Yinon Costica, co-founder of Wiz; Ofir Ehrlich, co-founder of Eon; Anne Neuberger; Omer Adam; and Varun Anand, co-founder of Clay, among others.
The Core Argument: AI Agents Are the New Operating System
AIR's central thesis draws a direct parallel between how AI agents are being used today and how operating systems functioned in the early days of computing. Saban argues that the tools and software AI agents can install and interact with are receiving far less scrutiny than the equivalent components in traditional computing environments.
"In the early 2000s, whenever you installed a driver, the driver didn't need to be signed. Today, every time you install a driver, you see a signature saying who signed it, because the driver is actually loading code into the kernel. You don't have that with skills or plug-ins or MCPs, and it's a shame, because it's the same mechanism, it's the same lesson, but we haven't learned it."
The risk, as Saban frames it, is not necessarily a direct attack on an AI agent itself. Rather, as agents operate more autonomously across enterprise databases and connect to external internet sources, adversaries can corrupt the content an agent consumes - poisoning inputs rather than breaching systems head-on. This indirect attack surface is one that most enterprise security tooling was not built to address.
What the Platform Does
AIR's product operates across three main functions. The first is visibility: the platform scans a company's environment to identify which AI agents are active, and also flags employees who may be using AI tools that have not been approved by IT departments or who are accessing those tools through personal accounts rather than corporate ones.
The second function is enforcement. The platform hooks directly into agents to intercept and analyze their actions in real time - for example, when an agent attempts to load a new skill or retrieve content from an external source. This layer allows security teams to block interactions that do not meet predefined criteria before they occur.
The third function is a curated whitelist of vetted tools, add-ons, and software components that agents are permitted to use. AIR maintains this list by continuously monitoring skills and add-ons that are publicly available online, checking for changes in behavior, alterations to underlying packages, or signs that a developer's account may have been compromised. According to Saban, the platform currently filters out approximately 27% of the add-ons and skills it identifies online as failing to meet its security standards.
In addition to these security functions, the company also operates a marketplace where businesses can find pre-vetted skills and add-ons for their AI agents.
Early Customers and Market Demand
AIR says it has already signed more than 20 customers, with roughly a quarter of those being large enterprise organizations. Saban noted that demand has been strongest in heavily regulated sectors, particularly financial services and pharmaceuticals - industries where compliance requirements and risk sensitivity tend to drive earlier adoption of security tooling.
A Competitive and Well-Funded Space
AIR is not operating in an empty field. Several other companies are pursuing similar problems from different angles. Noma Security provides discovery, access controls, and runtime monitoring for agents, MCP servers, and skills. Zenity offers security and governance tools with comparable capabilities and raised a $125 million Series C round in August. Astrix Security has built an identity-focused platform that allows organizations to discover and manage agents and MCP servers. Operant AI also provides agent protections alongside an MCP gateway product. Noma, for its part, raised a $100 million Series B last year.
The volume of venture capital flowing into this category reflects how seriously investors are taking the emerging threat surface around AI agent infrastructure. Despite that competition, Saban believes AIR has built a durable advantage that rivals will find difficult to replicate quickly.
"Continuously vetting skills and plug-in websites, this is a hard mission to do. Gaining visibility over the endpoint, that is easy. Everybody's going to do it. It's hard to create a moat around that."
Re-Verification, Not Just Scanning
Saban also addressed the question of whether AI labs and major platform providers might eventually build these security capabilities directly into their own products. While he acknowledged that is likely to happen over time, he argued that enterprises will still seek out independent solutions that function consistently across multiple vendors and platforms rather than relying on each provider's proprietary controls.
Sequoia partner Bogomil Balkansky offered a pointed articulation of why the firm backed AIR at this stage, framing the problem as one of infrastructure rather than security tooling alone.
"This is not a scanning problem, it is a continuous re-verification problem. Inspecting every skill, plugin, MCP server and sub-agent an enterprise's agents touch, re-inspecting each one every time it changes, in real time and across an entire company's agent fleet, is an infrastructure problem long before it is a security problem. AIR has spent the last year building that pipeline. You do not catch up to it by writing a better scanner."
What Comes Next
AIR currently employs around 40 people. Saban said the newly raised capital will be directed primarily toward expanding the company's research capabilities and scaling its go-to-market operations across the United States and Europe. As enterprises continue accelerating their adoption of AI agents and the tooling ecosystems around them grow more complex, the startup is betting that demand for continuous, independent oversight of that supply chain will only intensify.



