Agents now install code from the open internet, and about a quarter of it fails basic checks.
AIR says it filters out roughly 27% of the AI agent add-ons and skills it finds online. That is more than one in four pieces of code an agent might pull into a company’s systems. The company is now out of stealth with $50 million raised across two seed rounds that closed weeks apart.
Yair Saban, AIR’s CEO, points back to the early 2000s. Drivers loaded code straight into the kernel, and nobody signed them. Today every install shows you a signature and a name. Skills, plug-ins and MCP servers do something similar inside an agent. None of them carry that signature. Saban founded AIR with CTO Niv Hoffman. Both served in Unit 8200, Israel’s intelligence corps, on offensive security work.
Three layers. Discovery finds agents running across a company’s environment and flags staff using tools IT never approved, or personal accounts. An enforcement layer hooks into the agents themselves and intercepts actions: loading a skill, fetching a page from the web. Then a whitelist check against a list AIR maintains by watching public skills and add-ons for changes.
- Advertisement -
That last piece carries the weight. A skill that passed review once can turn hostile later if a package it downloads gets swapped, or its developer’s account is compromised. AIR also runs a marketplace of components it has already cleared.
The attack Saban worries about is indirect. Nobody breaks the agent. They poison what the agent reads.
Sequoia led the first round at $10 million. Greenoaks led the second at $40 million. Angel backers include Wiz co-founder Yinon Costica and Clay co-founder Varun Anand. AIR counts more than 20 customers, roughly a quarter of them large enterprises, with the sharpest demand from financial services and pharmaceutical firms.
The category is already crowded and already funded:
- Zenity closed a $125 million Series C in August
- Noma Security raised a $100 million Series B last year
- Astrix and Operant sell overlapping agent and MCP controls
Saban’s answer on defensibility is blunt. Endpoint visibility is easy, he says, and everyone will ship it. Vetting a live ecosystem over and over is the hard part. Sequoia’s Bogomil Balkansky calls it an infrastructure problem before a security one: re-inspecting every skill, plug-in and MCP server each time it changes, across a whole fleet. The team is 40 people. New money goes to researchers and to sales in the U.S. and Europe.
- Advertisement -
Drivers waited most of a decade for signatures, and agents are unlikely to get that long.
If you are rolling out agents, the thing to audit is the install surface, not the model. Ask who approved the last skill one of your agents loaded, and whether anyone has checked it since. Most teams cannot answer either question today. That gap is the actual buying decision: close it with a vendor, a policy, or a whitelist you keep yourself.
