AIR Secures $50 Million to Help Businesses Assess AI Agents’ Capabilities and Improvements
As organizations increasingly allow AI agents access to a broader range of their systems, a new software supply chain is evolving around the tools used by these AI agents: skills, plug-ins, MCP servers, and add-ons that facilitate their interactions with the internet.
According to AI security startup AIR, companies must monitor this emerging supply chain. The startup has recently come out of stealth mode after raising $50 million through two seed funding rounds to develop a solution for this need.
Founded by Yair Saban (CEO) and Niv Hoffman (CTO), both former members of Israel’s Unit 8200 intelligence corps with a background in offensive cybersecurity, AIR offers a platform designed to identify agents operating within organizations. It rigorously assesses any skills, tools, and components utilized by these agents, preventing them from interfacing with software or external resources that do not meet security standards. Additionally, a marketplace for vetted skills and add-ons specifically designed for AI agents is available.
The two funding rounds occurred in close succession, as Saban informed TechCrunch, with the first round securing $10 million and the second obtaining $40 million. The initial round was led by Sequoia, while Greenoaks led the second, as Saban noted. Other investors included Swish, Netz, Zach Frankel (president of Cognition), Yinon Costica (co-founder of Wiz), Ofir Ehrlich (co-founder of Eon), Anne Neuberger, Omer Adam, Varun Anand (co-founder of Clay), and various angel investors.
AIR’s premise is that the extensive adoption of AI agents in organizations is beginning to parallel operating systems; however, the tools they utilize and the software they can install lack the oversight typically associated with drivers or applications.
“In the early 2000s, when you would install a driver, a signature wasn’t necessary. Nowadays, any driver you install must be signed, as it actually loads code into the kernel,” Saban explained. “We don’t have that requirement for skills, plug-ins, or MCPs—which is unfortunate because the principle remains applicable; the lesson is still unlearned.”
He noted that significant risks emerge as AI agents operate more independently across databases and enterprise systems while connecting to the internet, allowing malicious actors to compromise the content consumed by an AI agent instead of conducting direct attacks.
The startup claims it can resolve this issue with a visibility product that detects active agents within a company’s environment and identifies employees using AI tools that have not received IT department approval or involve personal accounts. It integrates an enforcement layer that works with agents to monitor and analyze activities, such as loading skills or accessing internet content. AIR also cross-references the tools, add-ons, or software an agent wishes to use against a whitelist that the startup maintains.
Saban explained that the whitelist is maintained by monitoring skills and add-ons publicly available online for any modifications or malicious behavior, as a previously approved skill could become harmful if its downloaded package changes or if the developer’s account is compromised. Currently, AIR filters out about 27% of the add-ons and skills it encounters online.
AIR reports having over 20 clients, with Saban indicating that roughly a quarter of these are large enterprises. The company has noted increased demand in heavily regulated industries, particularly in financial services and pharmaceuticals.
However, AIR is not the only company operating in this space. Noma Security offers discovery, access controls, and real-time monitoring for agents, MCP servers, and skills, while Zenity provides security and governance tools with similar functionality. Additionally, Astrix Security’s identity platform assists companies in discovering and managing agents and MCP servers, and Operant AI offers protections for agents along with an MCP gateway.
There is significant venture capital interest in this area. Zenity raised $125 million in Series C funding in August, while Noma secured $100 million in Series B funding last year.
Saban believes AIR’s competitive advantage lies in its ability to continuously evaluate the expanding ecosystem of skills and add-ons associated with AI agents. “The ongoing assessment of skills and plug-in websites is a challenging endeavor. Achieving visibility over the endpoint is relatively simple; anyone can do that. Developing a protective barrier around it is far more complex,” he remarked.
The CEO acknowledged that AI labs and providers will eventually implement security checks and policies to prevent the use of malicious skills and tools. However, he believes companies will still prefer an independent product that operates across multiple vendors.
“This is not just a scanning issue; it’s about continuous re-verification,” stated Bogomil Balkansky, a partner at Sequoia, in an email to TechCrunch. “Evaluating every skill, plugin, MCP server, and sub-agent that interacts with an enterprise’s agents—reassessing each one whenever it changes, in real-time, across the entire company’s agent fleet—is a foundational infrastructure challenge long before it becomes a security concern. AIR has spent the past year building that essential pipeline. You cannot catch up by merely creating a better scanner.”
Currently, AIR employs roughly 40 individuals. Saban mentioned that the newly acquired funds will primarily be allocated towards recruiting researchers and enhancing the company’s market initiatives in the U.S. and Europe.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.


