As enterprises expand the use of AI agents that access core systems and external resources, new risks are emerging around the supply chain of skills, plugins, and add-ons these agents deploy. Security startup AIR has stepped into this breach, emerging from stealth with $50 million raised across two seed rounds to help organizations monitor, validate, and control the components their AI agents use.
What AIR Offers
Founded by Yair Saban (CEO) and Niv Hoffman (CTO), both former members of Israel’s Unit 8200 with offensive cybersecurity backgrounds, AIR provides a platform that delivers visibility, enforcement, and curation of AI agent ecosystems.
This platform can discover agents operating inside an organization, continuously vet the skills and tools they load, and block interaction with software or external content that fails to meet security criteria. Moreover, there’s a marketplace in the offering, where only vetted add-ons and skills are made available.
Funding & Competitive Landscape
AIR raised $10 million in its first seed round (led by Sequoia) and $40 million in its second (led by Greenoaks). Other participants include angels and founders of several security-focused companies.
The startup already has more than 20 customers, including some large enterprises. Highest demand so far comes from regulated sectors such as finance and pharmaceuticals.
There are rivals in this space: Noma Security provides discovery, access controls, and runtime monitoring for agents; Zenity offers similar governance tools; Astrix Security focuses on identity; and Operant AI builds protections and agent gateways too. Deal flow in the area has been strong—Zenity pulled in a $125 million Series C in August, while Noma secured a $100 million Series B last year.
Why It Matters
According to AIR, about 27% of the skills and add-ons available online fail its security filters—these are being blocked or removed because they don’t adhere to AIR’s criteria. That highlights the danger of unvetted components being injected into AI workflows.
AI agents are gaining more autonomy: they’re accessing enterprise databases, integrating with internal systems, and fetching resources from the internet. Without oversight, malicious actors could target those vectors indirectly—by poisoning a data source or compromising a third-party skill—rather than attacking systems directly. AIR’s continuous vetting layer seeks to defend against precisely those threats.
The new capital will go toward scaling up the team—especially researchers—and expanding AIR’s go-to-market in the U.S. and Europe. The company is about 40 employees now.
In a space where many are building visibility tools, AIR believes its differentiator lies in continuously re-verifying skills, plugins, and sub-agents every time they change rather than relying on static scanning. That repeat oversight, the company argues, will be key to preventing sloppy or dangerous add-ons from slipping through.
Analytical Perspective: As AI agents proliferate inside enterprises, the attack surface shifts—not just toward model integrity, but toward the peripheral components that agents depend on. AIR’s strategy—continuous vetting and curated add-on marketplaces—reflects a deeper trend in AI security toward securing the entire supply chain. Organizations should watch whether regulatory frameworks in finance, healthcare, and cybersecurity start mandating these kinds of controls. If so, platforms like AIR may move from “nice to have” to essential infrastructure.