EN
Back to the archive

The archive · AI & Models · Product decision · 2025

AegisAI bets AI agents, not rules, stop AI spear phishing; ex-Google execs raise $36M

Google security execs built AegisAI on the bet that rule-based filters can't catch AI-crafted email; a $36M Battery-led Series A says yes

AegisAI

The betThat email security must switch from if-then rules to AI agents that read intent and identity — and that 'defending AI with AI' can displace Proofpoint-class incumbents.Scaling

What the business is

AegisAI is a San Francisco email-security startup whose autonomous AI agents analyze every inbound message for intent and identity, catching AI-crafted spear phishing, malicious PDFs and account-takeover attacks that rule-based filters miss.

Starting capital$49M total: $36M Series A led by Battery Ventures (July 2026), with existing backers Accel and Foundation Capital participating

How it started

Cy Khormaee and Ryan Luo, who helped build reCAPTCHA, Safe Browsing and Web Risk inside Google's core security group, founded AegisAI in 2025 after a decade of preventing email hacks. They concluded AI had changed the attack itself, and launched the product publicly in September 2025.

What happened

By July 2026 AegisAI had dozens of customers across fintech and tech, including crypto payments company Mesh, AI developer platform LangChain, and privacy firm Lokker. Research it presented at the M3AAWG conference — drawn from 20,000+ malicious emails — showed AI spear phishing growing from 2.8% to 13.9% of observed phishing during 2025, with the attacks reaching inboxes at nearly twice the rate of human-written ones. In March 2026 it introduced Vanguard, a threat-hunting agent that follows suspicious links and attachments onto the open web.

How it ended up

Still running. The July 2026 Series A funds scaling its roster of defense agents and moving Vanguard toward general availability; the founders plan to expand beyond email into data security.

Background

AegisAI is an email-security startup founded in 2025 by Cy Khormaee and Ryan Luo, the former Google security executives behind reCAPTCHA, Safe Browsing and Web Risk. Their bet: AI-crafted spear phishing has made rule-based defenses obsolete, so the defense has to be AI agents that read each message the way a human investigator would.

The company launched publicly in September 2025 and built a network of autonomous agents that analyze intent and identity behind every inbound message, catching linguistically flawless attacks that clear every technical check. It claims the approach cuts false positives by up to 90% against legacy tools, and cites a Lokker customer case where agents caught an attack routed through a vendor's compromised Salesforce systems.

Research AegisAI presented at the M3AAWG conference — from a pool of more than 20,000 malicious emails — showed AI-generated spear phishing rising from 2.8% of observed phishing in early 2025 to 13.9% by year-end, with nearly 73% of the AI notes that reached inboxes sent from real, compromised accounts. That trend is the product's evidence base: an attacker now needs about the price of a cup of coffee to build a bespoke lure.

In July 2026 AegisAI raised a $36M Series A led by Battery Ventures, with Accel and Foundation Capital participating, bringing total funding to $49M less than a year after public launch. The money funds scaling its defense agents and moving Vanguard, a threat-hunting agent that follows suspicious links and attachments onto the open web, toward general availability; the founders plan to expand into data security next.

What has to be true

  • The story is a clean thesis-tested-by-market case: founders saw AI change the attack, built a different detection model, and got validated by customers and a $36M round within a year.
  • The M3AAWG data — 2.8% to 13.9% of observed phishing in 2025 — gives the bet concrete, citable evidence rather than vibes.
  • Traction is specific and verifiable: dozens of named customers (Mesh, LangChain, Lokker), $49M raised, and same-day coverage by TechCrunch and SiliconANGLE.
  • It is a transferable lesson for any incumbent-facing startup: when the threat changes category, matching patterns from the past is a liability, not an asset.

What can be applied

When AI changes the attack itself, the incumbent's detection logic becomes the liability: the wedge is a different inference model — agents that investigate intent, not rules that match patterns.

Aftermath

As of 2026-09-02 AegisAI is scaling post-Series A: it continues signing email-security customers, is pushing Vanguard (its threat-hunting agent introduced in March 2026) toward general availability, and plans to expand beyond email into data security. Khormaee's stated thesis is that customized, highly advanced investigation agents will decide which company becomes the next dominant security vendor.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases