IT-PUB NEWS

AIR raises $50M to secure AI agent tool chains

02.09.2026 13:03 • Author: IT-PUB

AIR raises $50M to secure AI agent tool chains

The startup says companies need ongoing checks on AI skills, plugins and MCP servers as agents gain access to internal systems and the web.

AI security startup AIR has emerged from stealth with $50 million in funding, pitching software that helps companies monitor the tools and add-ons used by AI agents. The company argues that as agents get access to more internal systems and internet-connected services, they create a new kind of software supply chain that enterprises will need to watch much more closely. That is the core bet behind AIR’s launch — and the reason investors are backing it now.

Its pitch is fairly simple. If AI agents are going to act more independently inside companies, the software they rely on cannot just be installed and forgotten. Skills, plugins, MCP servers and other add-ons can make agents far more useful, but they can also open security blind spots.

AIR wants continuous oversight of agent tools

AIR was founded by CEO Yair Saban and CTO Niv Hoffman. Both are veterans of Israel’s Unit 8200 intelligence corps, where they worked on offensive cybersecurity.

The company says its platform can discover AI agents running inside an organization, continuously examine the skills, tools and components those agents use, and block access to software or external sources that fail security checks. AIR also offers a marketplace of vetted add-ons and skills for AI agents.

Saban compared the issue to a lesson the software industry learned years ago with drivers. His point is that AI skills and plugins can effectively load code or content into an agent’s environment, yet they do not always go through the kind of signature or verification process companies expect from other software components.

AIR sees a security gap as agents grow more autonomous

AIR’s concern is that AI agents are becoming more autonomous and increasingly able to work across databases, enterprise systems and the open internet. In that setup, attackers may not need to attack the agent directly. They could instead poison the information or content the agent consumes.

To address that, AIR says its platform works in three layers. First, it finds agents across a company’s environment and identifies employees using AI tools that were not approved by IT departments, including personal accounts. Next, it intercepts and analyzes agent actions in real time, such as loading a skill or fetching content from the internet. Finally, it checks the tools, add-ons or software an agent wants to use against a whitelist maintained by AIR.

Saban said that whitelist is updated by evaluating skills and add-ons that are publicly available online for changes or malicious behavior. A tool that was previously approved can become risky if a package it downloads changes or if a developer account is compromised. As IT-PUB News notes, Saban said AIR’s platform currently filters out about 27% of the add-ons and skills it finds online.

The $50 million came in two seed rounds

AIR said the funding came from two seed rounds that closed within weeks of each other. The first brought in $10 million and was led by Sequoia. The second raised $40 million and was led by Greenoaks, according to Saban.

Other participants included Swish, Netz, Zach Frankel, who is president of Cognition, Yinon Costica, co-founder of Wiz, Ofir Erlich, co-founder of Eon, Anne Neuberger, Omer Adam, Varun Anand, co-founder of Clay, and additional angel investors.

The company currently has around 40 employees. Saban said the new capital will mainly go toward hiring researchers and expanding AIR’s go-to-market efforts in the U.S. and Europe.

AIR joins a busy AI security market

AIR is not alone in chasing this problem. The source notes that Noma Security offers discovery, access controls and runtime monitoring for agents, MCP servers and skills. Zenity sells security and governance tools in a similar area. Astrix Security’s identity platform also helps companies discover and control agents and MCP servers, while Operant AI offers agent protections and an MCP gateway.

Investors are clearly paying attention to the category. Zenity raised a $125 million Series C in August, and Noma raised a $100 million Series B last year.

That matters because it suggests enterprises are starting to treat AI agent security as a real budget item rather than a side concern. It also means AIR will need to show that its approach stands apart from broader discovery or monitoring tools.

AIR says repeated verification is the key difference

Saban argues that AIR’s advantage lies in continuously vetting the ecosystem of skills and add-ons that AI agents use. In his view, simply finding agents on endpoints is not enough, especially if companies eventually build more of that discovery capability themselves.

The harder problem, he said, is keeping a trusted list of tools and checking them again and again as they change. AIR is framing that as continuous re-verification, not one-time scanning.

Bogomil Balkansky, a partner at Sequoia, made a similar point in a statement provided to TechCrunch. He said the issue is not just scanning, but continuously re-checking every skill, plugin, MCP server and sub-agent in real time across an enterprise’s agent fleet. Balkansky described that as an infrastructure problem before it is a security problem.

Saban also acknowledged that AI labs and providers are likely to add more built-in security checks over time. Even so, he believes companies will still want an independent product that works across vendors. That is the broader significance of AIR’s funding round: more investors and companies appear to be treating AI agents not just as software that acts, but as software that brings along its own tool chain to secure.


Improve SEO for a small/medium business website for $50