AIR’s $50M Seed Bet: AI Agents Are Already a Security Mess

AIR says it filters out roughly 27% of the online add-ons and skills it evaluates. Most companies are still handing AI agents the keys to the business.

AIR’s $50M Seed Bet: AI Agents Are Already a Security Mess

AIR says it filters out roughly 27% of the online add-ons and skills it evaluates. Most companies are handing AI agents the keys to the business, then acting surprised when nobody knows what those agents installed, read or trusted.

That is not innovation. That is letting an intern wire money from your bank account because he watched three YouTube videos on bookkeeping.

AIR, an AI-security startup founded by Yair Saban and Niv Hoffman, has come out of stealth with $50 million raised across two seed rounds. Sequoia led the first $10 million round; Greenoaks led the next $40 million round, which closed only weeks later. For a company with roughly 40 employees, that is a serious pile of ammunition.

The headline is not really the funding. Plenty of startups raise too much money too early and turn it into expensive office furniture and a hiring problem. The important bit is what AIR is betting on: the next enormous cybersecurity market will not be securing the AI model. It will be securing everything an AI agent touches while it is doing work.

That distinction matters more than most founders and executives realise.

The real problem is not the chatbot

A chatbot that writes a bad email is annoying. An agent that can search internal systems, pull data from the web, load a plug-in, call an external tool and take action inside a company is a different beast altogether.

It has access. It has autonomy. And it has a growing supply chain of “skills,” plug-ins, MCP servers, add-ons and external content that can influence what it does next.

That is the hole AIR wants to fill.

The company says its platform can discover agents operating inside an organisation, identify the tools and components those agents use, vet them continuously and block interactions that fail security criteria. Its stated approach is not simply to approve a tool once and move on. It is to keep checking it, because a seemingly safe add-on can become unsafe when a dependency changes, a developer account is compromised, or the external content an agent consumes is poisoned.

That sounds obvious when you say it out loud. Which is precisely why it is valuable.

Businesses learned this lesson the hard way with cloud infrastructure, employee devices, open-source software and SaaS sprawl. First they adopted the shiny thing at pace. Then they realised nobody had proper visibility, access controls or accountability. Then security vendors made fortunes cleaning up the mess.

AI agents are poised to compress that whole cycle into about five minutes.

AIR says it already has more than 20 customers, with around one-quarter of them large enterprises. It says demand has been strongest in financial services and pharmaceuticals — two sectors where “we did not know the agent could access that” is not a charming explanation after a breach. The company also says it filters out roughly 27% of the online add-ons and skills it evaluates. Treat that as a company-reported operating metric, not holy scripture, but it is directionally revealing: the open ecosystem feeding agents is hardly a pristine garden.

Why $50 million arrived so quickly

The two rounds tell you what serious investors think is happening.

Sequoia put in the initial $10 million. Greenoaks followed with $40 million. That is not investors funding a generic dashboard with “AI” pasted over the top. They are funding a land grab around a new control point in enterprise software.

The founders have the sort of background venture investors salivate over in cyber: both Saban, AIR’s chief executive, and Hoffman, its chief technology officer, are veterans of Israel’s Unit 8200 intelligence corps and worked in offensive cybersecurity. Their investor list includes people with operating credibility in cybersecurity and AI, including Wiz co-founder Yinon Costica, Cognition president Zach Frankel, Eon co-founder Ofir Ehrlich, Clay co-founder Varun Anand and former US cybersecurity official Anne Neuberger.

Credentials are not a moat. Plenty of founders with shiny résumés build businesses that go nowhere. But they do matter in cybersecurity, where technical judgement, trust and the ability to recruit very good engineers are not optional extras.

Sequoia’s own account of the investment describes AIR as building security across the lifecycle of agent add-ons: filtering them before use, monitoring agent behaviour while running, and controlling which agents exist, what they can access and how rapidly a bad tool can be revoked. In plain English: know what is connected, decide what is allowed, and be able to pull the pin quickly.

That last bit is the business.

A security product is not impressive because it spots a problem in a slide deck. It is impressive if, at 2:14 on a Friday afternoon, it stops a bad action before it becomes an incident, tells you what happened, and lets you shut down the same exposure across the business without calling six consultants.

The second-order implication: agents create a new software supply chain

Here is what too many people miss: an AI agent is not just software. It is software making choices through other software, based on information it did not create and often cannot properly verify.

Traditional security has clear-ish boundaries. You protect the network. You manage identities. You patch devices. You inspect code. None of this is perfect, but the categories are familiar.

Agents muddy the whole lot.

An agent may have legitimate permission to access a database, use a browser, read an email, load a connector and submit a request. The problem can arrive through the context it consumes rather than through someone breaking its permissions. A dodgy website, a compromised plug-in, a malicious instruction embedded in a document, or a changed dependency can influence an agent with perfectly legitimate credentials to do something stupid or dangerous.

That is why AIR calls its product a firewall for agent context. Whether that becomes the category-defining phrase is beside the point. The underlying problem is real: access controls alone are not enough when the thing with access can be manipulated by what it reads.

Founders should pay attention because this creates a new budget line. At first, companies will experiment with agents through scattered teams: sales wants an agent for research, support wants one for tickets, finance wants one for reconciliation, engineering wants coding agents. Then a chief information security officer will discover the company has dozens or hundreds of agents connected to tools nobody centrally approved.

That moment is when the cheque books come out.

AIR is not alone. TechCrunch notes that Noma Security, Zenity, Astrix Security and Operant AI all have products aimed at parts of the same problem. Zenity reportedly raised a $125 million Series C in August, while Noma raised a $100 million Series B last year. This is not a one-company story. It is a market forming in public.

The contrarian take: security may be the best way to profit from the agent boom

Every second startup pitch now claims to build an agent that will replace a department, automate a workflow or make a knowledge worker ten times faster. Some will work. A lot will be software demos dressed up as companies.

The more dependable opportunity may sit one layer below the glamour.

When a new technology genuinely changes how businesses operate, the boring infrastructure around it often becomes more durable than the flashy application. The winners are not always the firms promising magic. They are often the ones providing the toll roads, the picks and shovels, the audit trail and the emergency brake.

That is AIR’s bet.

There is also a risk in that bet. The major model providers and cloud platforms will build more native guardrails. They have to. If their agents become widely trusted inside enterprises, they cannot leave every control point to startups.

But “native” rarely means “enough” for a big company running multiple models, clouds, agents and software tools. Enterprises tend not to buy one vendor forever. They want an independent layer that can see across the mess. If AIR can become that neutral system of record — rather than just another alert console — it has a proper chance.

The hard part will be proving that continuous vetting is materially better than existing scanning, policy and endpoint-security tools. Big funding gives the team time. It does not give them product-market fit, customer trust or a defensible distribution engine. They still have to earn those.

What this means for you

If you are a founder or operator, stop asking only, “Which AI agent should we deploy?” Ask these five questions before the agent gets near a critical workflow:

1. What systems can it read, write to or trigger? List the permissions in plain English. “It has broad access” is not an answer; it is an admission.

2. What external tools, skills, plug-ins and MCP servers can it use? If nobody owns that inventory, you do not have governance. You have hope.

3. Who approves a new connection — and what happens when it changes later? One-off approval is lazy security. Set a review process for changes in dependencies, ownership and behaviour.

4. Can you see the agent’s actions and revoke access immediately? Run the ugly test: if a connector turns bad at 2am, can someone contain the problem in minutes rather than days?

5. Is the agent doing something valuable enough to justify the risk? Not every task needs autonomy. Start with narrow, measurable workflows where you can quantify upside and limit the blast radius.

This is not an argument to avoid AI agents. That ship has sailed. It is an argument to deploy them like an adult.

AIR’s $50 million raise is a reminder that the next wave of startup value will not come only from building agents that can do more. It will come from building the controls that make companies brave enough to let them.

The businesses that win will move fast, yes. But they will know exactly what their machines are allowed to touch before those machines start touching everything.

Sources