The archive · Developer & Business Tools · Strategic decision · 2026
AIR bets AI agents need a driver-signing moment; $50M from Sequoia, Greenoaks
Unit 8200 vets turned the driver-signing lesson on AI agents: discover, vet, block. Exited stealth with $50M and 20+ customers.
AIR
What the business is
An AI security platform that discovers agents running inside a company, continuously vets the skills, plug-ins and MCP servers they load, blocks what fails security checks, and sells a whitelisted add-on marketplace.
Starting capital:$50M across two seed rounds closed within weeks of each other: $10M led by Sequoia, then $40M led by Greenoaks, with angels including Wiz co-founder Yinon Costica, Eon co-founder Ofir Ehrlich, Cognition president Zach Frankel and Clay co-founder Varun Anand.
How it started
Founded by Yair Saban and Niv Hoffman, veterans of Israel's Unit 8200 intelligence corps who worked on offensive cyberattacks. They watched enterprises wire AI agents into their databases and systems while nobody audited what those agents could install, and reached for a solved precedent: in the early 2000s a driver loading code into a kernel needed a signature; a skill loading code into an agent doesn't. AIR spent about a year in stealth building the pipeline.
What happened
AIR says its platform filters out about 27% of the add-ons and skills it finds online, an enforcement layer hooks into agents to intercept and analyze actions such as loading a skill or fetching web content, and it flags employees using unapproved AI tools or personal accounts. Sequoia partner Bogomil Balkansky framed the bet: 'This is not a scanning problem, it is a continuous re-verification problem… You do not catch up to it by writing a better scanner.'
How it ended up
Came out of stealth on 1 September 2026 claiming more than 20 customers, roughly a quarter of them large enterprises, with the strongest demand in financial services and pharma; the $50M will go toward hiring researchers and expanding US and Europe go-to-market. The company enters a crowded, well-funded category — Zenity raised a $125M Series C in August 2026 and Noma raised a $100M Series B last year.
Background
AIR was founded by Yair Saban and Niv Hoffman, veterans of Israel's Unit 8200 intelligence corps, on a hunch about the tech industry's least-supervised boundary: companies are giving AI agents access to their systems, but nothing audits the skills, plug-ins and MCP servers those agents can install. Their analogy is the driver-signing moment of the early 2000s — drivers that load code into a kernel must be signed; skills that load code into an agent are not.
The product is a visibility and enforcement layer: it discovers agents running across a company's environment (and employees using unapproved AI tools), hooks into agents to intercept actions like loading a skill or fetching internet content, and checks every tool an agent wants to use against a whitelist AIR maintains by continuously re-evaluating publicly available skills and add-ons for malicious changes. AIR says its filter currently rejects about 27% of what it finds online.
The financing followed the conviction: a $10M seed led by Sequoia, then a $40M seed led by Greenoaks, both closing within weeks, with angels that read like a who's who of the security-agent world. Sequoia's Bogomil Balkansky argued the moat is the pipeline: 'Inspecting every skill, plugin, MCP server and sub-agent an enterprise's agents touch, re-inspecting each one every time it changes, in real time and across an entire company's agent fleet, is an infrastructure problem long before it is a security problem.'
As of 1 September 2026 AIR claims more than 20 customers, about a quarter of them large enterprises, with demand strongest in regulated industries like financial services and pharma, where agent adoption is gated by compliance. Its ~40 employees are being grown with money earmarked for researchers and US/Europe go-to-market — entering a category where Zenity has already raised a $125M Series C and Noma a $100M Series B.
What has to be true
- AIR borrowed a solved precedent — signed drivers — to make an unproven product category instantly understandable to buyers.
- It chose continuous re-verification as the moat rather than endpoint visibility, which Saban admits every rival will also build.
- Two seeds weeks apart from Sequoia then Greenoaks stacked institutional names before launch, signalling category leadership early.
- It aimed first at regulated buyers (finance, pharma) where agent adoption is already compliance-gated, making security the purchase driver rather than an afterthought.
- Enforcement is built into the agent runtime (intercept and block actions), not delivered as a report, so blocking is part of the loop agents run in.
What can be applied
Every new software layer repeats driver-signing: value becomes a market when someone owns trust. AIR built a continuous re-verification pipeline — infrastructure compounds, scanners get copied.
Aftermath
As of 2 September 2026 AIR is out of stealth with ~40 employees and $50M raised at seed. Public numbers are early — 20+ customers, about a quarter large enterprises, strongest in financial services and pharma — and the category is crowded: Zenity's $125M Series C (August 2026) and Noma's $100M Series B predate AIR's launch. The open question is whether AI labs and agent platforms absorb security; AIR says enterprises will still want an independent cross-vendor layer, the same argument that let security vendors take root around operating systems.
Sources
- AIR raises $50M to help companies vet the skills and add-ons AI agents use
- AI Agent Security Startup AIR Raises $50 Million to Guard Enterprise Supply Chains
spotted an error? The archive wants to know.
Your turn
You just read one. Describe what you are building, and see who is betting on the same thing.
Free account · 3 free questions · no card