EN
Back to the archive

The archive · AI & Models · Product decision · 2026

AIR raises $50M to build a firewall for AI agents' skills and add-ons

Unit 8200 veterans Yair Saban and Niv Hoffman built AIR to continuously vet what AI agents install and use; Sequoia and Greenoaks led $50M in two seed rounds.

AIR

The betThat enterprises will pay for an independent firewall that continuously re-vets the skills, plugins, and MCPs their AI agents use — trust for agent context, not code.Live

What the business is

AIR sells an inline firewall for enterprise AI agents: it discovers agents running across a company, continuously vets every skill, plugin, MCP server, and add-on they touch, and blocks anything that fails its security checks.

How it started

Saban and Hoffman, veterans of Israel's Unit 8200 who worked on offensive cybersecurity, concluded that AI agents had created a new attack surface: tools load code and instructions into an agent's context with none of the signed-driver-style oversight PCs got in the early 2000s. They spent roughly a year building before emerging from stealth on September 1, 2026.

What happened

Two seed rounds closed within weeks of each other: $10 million led by Sequoia, then $40 million led by Greenoaks, with Swish, Netz, and angels including Cognition president Zach Frankel and Wiz co-founder Yinon Costica. AIR says its platform filters out about 27% of the add-ons and skills it finds online, and claims more than 20 customers, roughly a quarter of them large enterprises in regulated industries such as financial services and pharma.

How it ended up

Still early: about 40 employees, with the capital earmarked for researchers and US and Europe go-to-market, competing against Noma, Zenity, Astrix, and Operant in an agent-security category that has drawn nine-figure rounds.

Background

AIR is an AI-security startup betting that enterprise AI agents have created a software supply chain that no one is watching. Its platform discovers agents running inside a company, continuously vets the skills, plugins, MCP servers, and add-ons those agents use, and blocks anything that fails security criteria — an inline firewall for what enters an agent's context.

The company emerged from stealth on September 1, 2026, announcing $50 million raised across two seed rounds that closed within weeks of each other: $10 million led by Sequoia and $40 million led by Greenoaks, with Swish, Netz, and angels including Cognition president Zach Frankel and Wiz co-founder Yinon Costica. Founders Yair Saban and Niv Hoffman are Unit 8200 veterans who worked on offensive cybersecurity.

AIR's launch was backed by original security research: one study found more than 17,800 public AI add-ons representing 6.7 million installations relied on untrusted external instruction sources, and another uncovered skills impersonating trusted brands like Anthropic and OpenAI to bypass platform reviews and execute arbitrary code. The startup says its platform currently filters out about 27% of add-ons and skills it finds online.

With about 40 employees and more than 20 customers — roughly a quarter of them large enterprises in financial services and pharma — AIR is competing with Noma, Zenity, Astrix, and Operant in a category drawing nine-figure venture rounds, and plans to spend the new capital on researchers and US and European go-to-market.

What has to be true

  • Agents are autonomously installing tools and connecting to internal systems, but organizations have no visibility into what is running or what is trusted.
  • Attackers can poison the content an agent consumes — skills, plugins, MCP servers — instead of attacking the agent directly, a mechanism analogous to unsigned drivers loading into a kernel.
  • The vetting problem is continuous: a previously approved skill can turn malicious when a dependency changes or a developer account is compromised.
  • Regulated industries with the strongest demand, like financial services and pharma, are exactly the buyers willing to pay for an independent cross-vendor trust layer.

What can be applied

A new software layer creates a new trust layer: AIR treated skills and add-ons as a supply chain and made continuous re-verification its product, betting that scanners alone cannot keep up.

Aftermath

As of September 2026 AIR is live with a shipped platform, about 40 employees, and more than 20 customers, but the $50M is seed-stage money and the category is crowded — Zenity raised a $125M Series C and Noma a $100M Series B in the same period. The bet that continuous re-verification of the agent add-on ecosystem becomes mandatory enterprise infrastructure is still being tested.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases