On 1 September 2026, AIR Security emerged from stealth with $50 million in funding and a proposition that cuts straight to the most urgent question in enterprise AI today: who is watching the agents? The New York-based startup is building an inline firewall that sits between an organisation's agent fleet and the growing ecosystem of third-party skills, plugins and Model Context Protocol (MCP) servers those agents reach for on their own. For enterprise buyers, the message is clear: the perimeter is no longer the network. It is the agent's context.

The funding itself tells a story. Sequoia Capital led a $10 million seed round. Greenoaks Capital Partners then led a $40 million follow-on. Both rounds closed inside the company's first six months. Additional investors include Swish Ventures, Netz Capital, and a roster of individual angels that includes Wiz co-founder Yinon Costica and former White House deputy national security adviser Anne Neuberger. This is not speculative capital. It is conviction from firms that back infrastructure companies with genuine enterprise pull.

What AIR does

AIR's product sits in the path between AI agents and every external or internal tool they might call. Before an agent touches a skill, plugin or MCP server, AIR performs deep analysis against known agentic attack patterns. It screens for external instruction sources, hidden behaviours, and typo-squatted packages masquerading as official developer tools. If a component is malicious, vulnerable or not approved, security teams can trace every agent and workflow that depends on it and revoke it across the organisation. The check is continuous, not one-off: a skill that passed review in March can be rewritten in June, and AIR will catch it.

The platform also offers a marketplace of pre-vetted, certified add-ons, giving enterprises a safe route to expand agent capabilities without introducing unmanaged risk.

More than twenty companies already use the platform, with roughly a quarter of them large enterprises. Demand is strongest in financial services and pharmaceuticals, two sectors where regulated data and high-stakes decisions leave little margin for error.

Why the numbers matter

AIR's research team has put hard figures on a problem that many security teams suspect but struggle to quantify. They identified more than 17,800 public AI add-ons, representing 6.7 million installations, that drew instructions from untrusted external sources. They also found AI skills impersonating Anthropic and OpenAI that were designed to bypass security reviews and execute arbitrary code. Approximately 27% of the add-ons and skills AIR finds online get filtered out.

These are not edge-case vulnerabilities. They are supply-chain compromises in a new software category that most enterprises do not yet know how to audit. Coding agents — Claude Code, Cursor, Codex and their equivalents — are being adopted at a pace that security teams have not matched. Every time an agent autonomously installs a tool or reaches for a third-party MCP server, the organisation's attack surface grows without the security team knowing it.

Yair Saban, AIR's chief executive and co-founder, put it plainly: "Every enterprise has a firewall protecting its network. Now they need one protecting their AI agents." Saban and his co-founder Niv Hoffman, the chief technology officer, both spent years in Unit 8200, the Israeli military intelligence corps, doing offensive cybersecurity work. Ryan Knisley, the former chief information security officer at The Walt Disney Company and Costco Wholesale, serves as chief strategy officer. The team's background is relevant because the problem AIR is solving is fundamentally an adversarial one, and the founders have spent their careers thinking from the attacker's perspective.

What it means for enterprise buyers

AIR's launch carries three direct implications for organisations deploying or evaluating agentic platforms.

The agent supply chain is a new attack surface. Most enterprises already run software composition analysis and vulnerability scanning on application dependencies. Few have equivalent capability for the skills, plugins and MCP servers their agents consume. AIR's discovery of 17,800 untrusted add-ons is a wake-up call: if your agents can install tools autonomously, your supply-chain risk programme needs to cover agentic components specifically. Buyers should ask any agent vendor whether the platform can enumerate every third-party skill or plugin the agent has access to, and whether that list is continuously re-validated.

Continuous re-verification replaces point-in-time approval. Bogomil Balkansky, a partner at Sequoia Capital, described the problem as "not a scanning problem" but one of continuous re-verification. This distinction matters for procurement. A security review conducted at contract signing is worthless if the agent later pulls in a compromised skill update. Buyers need to understand whether their agent platform supports runtime inspection, whether third-party tools are sandboxed before approval, and what the update cadence is for re-evaluating already-allowed components.

Coding agents need the same controls as production agents. AIR's strongest demand currently comes from enterprises running coding agents at scale. These tools have write access to repositories, build pipelines and cloud infrastructure, and they are often deployed by development teams without passing through central security review. AIR treats coding agents as a high-risk category deserving the same runtime scrutiny as customer-facing autonomous systems. Buyers should evaluate whether their coding-agent deployment has visibility into installed extensions, model context and third-party tool calls, or whether developers are effectively flying blind.

What it means for suppliers

For companies building agentic products, AIR's launch signals both competitive pressure and market validation.

The agent security tooling market is heating up. In the past two weeks alone, CrowdStrike launched Falcon Guardian to police AI agents at the endpoint, JFrog introduced agent security controls for software supply chains, and Anthropic announced Enterprise Frontier Safeguards for zero-data-retention privacy. AIR adds the inline firewall layer to this stack. Suppliers should expect that enterprise buyers will soon require multi-layer agent security as a baseline, not a premium add-on. The vendor that can articulate its security posture across runtime, endpoint, supply chain and data residency will have a meaningful advantage.

Third-party extensibility is now a risk vector. Many agent platforms market their marketplace of skills and plugins as a competitive advantage. That extensibility is exactly what AIR targets. Suppliers should consider whether their marketplace has vetting, continuous monitoring and revocation capability, and whether they can offer enterprise customers an audit trail of every skill their agents have installed, updated or removed. If the answer is no, a competitive platform with AIR integration may win the deal.

Standards adoption accelerates sales. AIR integrates with existing security stacks rather than replacing them. Its approach of mapping, scoring and continuously re-validating components can be layered on top of current identity, endpoint and SIEM tooling. Suppliers that adopt open standards for agent identity, tool interoperability and telemetry will find it easier to integrate with emerging security layers like AIR. Those that build proprietary, opaque agent architectures will face friction as security teams demand visibility they cannot provide.

The broader context

AIR's emergence fits a clear pattern. In the past month, Broadcom launched AgentMinder, a runtime governance control plane; CrowdStrike expanded from detection to active agent control at the endpoint; and JFrog added agent-specific guardrails to its software supply-chain platform. The cumulative message is that the infrastructure layer for agent security is being built in real time, and the companies that get there first will shape the procurement criteria for everyone else.

The $50 million figure is also worth noting in context. In the first half of 2026, agentic AI startups raised more than $2.3 billion across venture, growth and corporate rounds. AIR is one of the largest early-stage fundings in the security subcategory, and its investor list includes some of the most selective firms in technology. That capital will go toward hiring researchers, building out United States and European sales, and deepening the threat-intelligence capability that powers the platform's filtering engine. The arms race between agent builders and agent defenders has begun, and AIR has just raised the stakes.

The Agentic Expo angle

Agentic Expo exists because the gap between agent capability and enterprise trust is where the real commercial value lives. AIR's $50 million round is further evidence that the market agrees. The question for buyers is no longer whether to deploy agents, but whether they can deploy them without expanding the attack surface faster than security can keep up.

By March 2027, when Agentic Expo opens at Olympia London, agent security will be a standard conversation, not a niche concern. The exhibitors and speakers on our floor will be the teams that have built, sold and defended agentic systems at scale. The visitors will be the procurement, security and engineering leaders trying to decide which platforms they can trust. AIR Security has just given us a preview of the conversation that will dominate our halls. Our job is to bring both sides into the same room.

Get Tickets Exhibit at Agentic Expo

Sources: SiliconANGLE, AIR Security launches with $50M to build a firewall for AI agents, 1 September 2026; SecurityWeek, AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million, 1 September 2026; TechCrunch, AIR raises $50M to help companies vet the skills and add-ons AI agents use, 1 September 2026; Bank Info Security, Air Launches With $50M to Keep Enterprise AI Agents Safe, 1 September 2026; SecurityBrief, AIR launches AI firewall with USD $50 million backing, September 2026; SiliconANGLE, CrowdStrike launches Falcon Guardian to police AI agents at the endpoint, 1 September 2026; MarkTechPost, Anthropic Introduces Enterprise Frontier Safeguards, 2 September 2026.