{"id":158574,"date":"2026-09-02T00:46:20","date_gmt":"2026-09-02T00:46:20","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/158574\/"},"modified":"2026-09-02T00:46:20","modified_gmt":"2026-09-02T00:46:20","slug":"air-raises-50m-to-help-companies-vet-the-skills-and-add-ons-ai-agents-use","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/158574\/","title":{"rendered":"AIR raises $50M to help companies vet the skills and add-ons AI agents use"},"content":{"rendered":"<p id=\"speakable-summary\" class=\"wp-block-paragraph\">As companies start giving AI agents access to an increasing portion of their systems, a nascent software supply chain seems to be forming around the new tooling AI agents are using: skills, plug-ins, MCP servers, and add-ons that let them interact with the internet.<\/p>\n<p class=\"wp-block-paragraph\">AI security startup <a href=\"https:\/\/www.air.security\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">AIR<\/a> believes companies will need a way to monitor that supply chain, and it\u2019s now coming out of stealth with $50 million raised across two seed rounds to build that product.<\/p>\n<p class=\"wp-block-paragraph\">Founded by Yair Saban (CEO) and Niv Hoffman (CTO), veterans of Israel\u2019s Unit 8200 intelligence corps, where they worked on offensive cybersecurity, AIR offers a platform that can discover agents running inside companies, continuously vet any skills, tools, and components those agents use, and block them from interacting with software or external sources that don\u2019t pass security criteria. It also offers a marketplace of vetted add-ons and skills for AI agents.<\/p>\n<p class=\"wp-block-paragraph\">The funding rounds closed within weeks of each other, Saban told TechCrunch, with the first round raising $10 million, and the second $40 million. Sequoia led the first round, while Greenoaks led the second, Saban said. Swish, Netz, and Zach Frankel (president of Cognition), Yinon Costica (co-founder of Wiz), Ofir Ehrlich (co-founder of Eon), Anne Neuberger, Omer Adam, Varun Anand (co-founder of Clay), and other angel investors also participated.<\/p>\n<p class=\"wp-block-paragraph\">AIR\u2019s pitch goes thusly: The way AI agents are used wholesale at companies is beginning to resemble operating systems, but the tools they use, or the software they can install, aren\u2019t yet being given the kind of oversight we give to drivers or applications. <\/p>\n<p class=\"wp-block-paragraph\">\u201cIn the early 2000s, whenever you installed a driver, the driver didn\u2019t need to be signed. Today, every time you install a driver, you see a signature saying who signed it, because the driver is actually loading code into the kernel,\u201d Saban said. \u201cYou don\u2019t have that with skills or plug-ins or MCPs, and it\u2019s a shame, because it\u2019s the same mechanism, it\u2019s the same lesson, but we haven\u2019t learned it.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The big risk, he argues, is that as AI agents start working more autonomously across databases and enterprise systems, and connecting to the internet, attackers can poison the content an AI agent consumes instead of attacking it directly.<\/p>\n<p class=\"wp-block-paragraph\">The startup says it can solve that with a visibility product that finds agents active across a company\u2019s environment, as well as identifies employees who use AI tools unapproved by IT departments or those who use personal accounts. Then, it uses an enforcement layer that hooks into agents to intercept and analyze actions, like loading a skill or fetching content from the internet. Lastly, AIR also checks the tools, add-ons, or software an agent wants to use against a whitelist the startup maintains.<\/p>\n<p class=\"wp-block-paragraph\">Saban says the startup maintains this whitelist by evaluating skills and add-ons openly available on the internet for changes and malicious behavior, as a previously approved skill could become risky if a package it downloads changes, or its developer\u2019s account is compromised. He added that AIR\u2019s platform currently filters out about 27% of the add-ons and skills it finds online.<\/p>\n<p class=\"wp-block-paragraph\">AIR claims it has more than 20 customers, and Saban said roughly a quarter of these are large enterprises. He said the company has so far seen the strongest demand in heavily regulated industries, particularly financial services and pharmaceutical companies.<\/p>\n<p class=\"wp-block-paragraph\">However, AIR is hardly alone in this space. <a href=\"https:\/\/www.noma.security\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Noma Security<\/a> offers discovery, access controls, and runtime monitoring for agents, MCP servers, and skills, while <a href=\"https:\/\/zenity.io\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Zenity<\/a> sells security and governance tools that work similarly. <a href=\"https:\/\/astrix.security\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Astrix Security<\/a>\u2018s identity platform also lets companies discover and control agents and MCP servers, and <a href=\"https:\/\/www.operant.ai\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Operant AI<\/a> offers agent protections as well as an MCP gateway.<\/p>\n<p class=\"wp-block-paragraph\">There is significant venture money chasing the category, too. Zenity raised a $125 million Series C in August, while Noma raised a $100 million Series B last year.<\/p>\n<p class=\"wp-block-paragraph\">Saban thinks AIR\u2019s moat lies in its ability to continuously vet the skills and add-ons ecosystem growing around AI agents. \u201cContinuously vetting skills and plug-in websites, this is a hard mission to do. Gaining visibility over the endpoint, that is easy. Everybody\u2019s going to do it. It\u2019s hard to create a moat around that,\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">And while the CEO acknowledged that AI labs and providers will eventually build in security checks and policies to filter out malicious skill and tool usage, he thinks companies will still want to buy an independent product that works across vendors. <\/p>\n<p class=\"wp-block-paragraph\">\u201cThis is not a scanning problem, it is a continuous re-verification problem,\u201d Bogomil Balkansky, partner at Sequoia, told TechCrunch in an emailed statement. \u201cInspecting every skill, plugin, MCP server and sub-agent an enterprise\u2019s agents touch, re-inspecting each one every time it changes, in real time and across an entire company\u2019s agent fleet, is an infrastructure problem long before it is a security problem. Air has spent the last year building that pipeline. You do not catch up to it by writing a better scanner.\u201d<\/p>\n<p class=\"wp-block-paragraph\">AIR currently has around 40 employees. Saban said the new capital will primarily go toward hiring researchers and expanding the company\u2019s go-to-market efforts in the U.S. and Europe.<\/p>\n<p>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\" rel=\"nofollow noopener\" target=\"_blank\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/p>\n","protected":false},"excerpt":{"rendered":"As companies start giving AI agents access to an increasing portion of their systems, a nascent software supply&hellip;\n","protected":false},"author":2,"featured_media":158575,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[405,1710,7537,77157,6020],"class_list":["post-158574","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-ai-agents","tag-ai-security","tag-artificial-intelligence-agents","tag-greenoaks-capital","tag-sequoia-capital"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/158574","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=158574"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/158574\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/158575"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=158574"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=158574"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=158574"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}