AIR has emerged from stealth and announced a $50 million funding round led by Sequoia Capital and Greenoaks. Swish Ventures and Netz Capital also participated in the financing, alongside private investors from the cybersecurity and AI industries. The company is developing an inline firewall designed to protect enterprise AI agents from malicious instructions, untrusted information and compromised tools.
A Growing Security Gap for AI Agents
As enterprises deploy AI agents, those systems connect to a widening range of tools, data and third-party services. Agents can browse websites, read emails and files and take actions on behalf of employees, which exposes them to malicious content or compromised tools that can cause unintended actions. This autonomy creates new risks because agents make decisions based on information they encounter, often leaving security teams with limited visibility into what influences their behavior.
Research Exposes Supply Chain Vulnerabilities
AIR's launch follows original security research that highlights the scale of the emerging problem and shows how surrounding software can influence agent behavior. One study found that more than 17,800 public AI add-ons representing about 6.7 million installations relied on untrusted external instruction sources. Another investigation uncovered AI Skills impersonating trusted brands such as Anthropic and OpenAI to bypass platform security reviews and execute arbitrary code.
Inline Firewall for Agent Context
AIR continuously discovers and evaluates every skill, plugin, MCP server and add-on across an organization's AI agent supply chain before and after deployment. The platform protects what enters an agent's context rather than simply restricting what the agent is allowed to do. When an add-on is found to be malicious, vulnerable or unapproved, security teams can trace every agent and workflow that depends on it and revoke access across the organization.
Supply Chain Discovery and Governance
The company is also developing a marketplace of pre-vetted, certified add-ons to help enterprises expand agent capabilities without introducing unmanaged risk. This marketplace gives security teams a safe path to approve new tools while maintaining visibility into their supply chain. AIR argues that discovery and continuous evaluation are essential because agents increasingly install tools and connect to internal systems autonomously.
Prevention Rather Than Detection
Chief executive officer Yair Saban said every enterprise has a firewall protecting its network but AI agents now need a firewall that protects what enters their context. He explained that agents face danger when exposed to malicious information from extensions, websites or internal organizational sources. AIR's focus on prevention rather than detection after a compromise is central to its differentiation in the AI security market.
Leadership and Investor Conviction
The company was founded by Yair Saban and Niv Hoffman, who bring backgrounds in offensive security, enterprise infrastructure and AI security research. Ryan Knisley, former chief information security officer at The Walt Disney Company and Costco Wholesale, has joined as chief strategy officer. Sequoia Capital partner Bogomil Balkansky said the founders identified the problem earlier than most, while Greenoaks partner Patrick Backhouse said this layer will become mandatory to enterprise cybersecurity.
Company Growth and Market Trajectory
AIR currently employs around 40 people in Israel and is building a research laboratory dedicated to AI and the behavior of AI agents. The company has started selling to large organizations and has begun hiring employees in the United States. It plans to use the new capital to expand operations, accelerate commercial activity and deepen its research capabilities.
The $50 million round is notable for a company that only recently exited stealth, and the funding will support expanded operations and accelerated commercial activity. AIR is concentrating on prevention rather than detection after an agent has already been compromised, an approach it argues distinguishes it in a crowded AI security market. As AI agents gain more autonomy, demand for real-time protection of their supply chains is likely to keep growing.