Breaking
UKIsraeli forces capture Hamas internal security head in Gaza raid, killing four PalestiniansPLGermany responds to Russian drone attack on Leipzig/Halle airportTRGalatasaray transferred Deniz Gül from Porto for 10 million EurosESPartial collapse of the Hurtado de Mendoza Palace in Almazán (Soria)ESIran attacks US bases in Jordan, Iraq and Bahrain in retaliation for US bombingsFRBouches-du-Rhône: a BAC police officer between life and death after a fall in Aix-en-ProvenceKRSouth Korean stocks open sharply lower amid U.S.-Iran military tensions and rising oil pricesTR1 Dead, 4 Injured in Car Accident That Hit a Family in ÇanakkaleITFlavio Cobolli celebrates victory after an epic comeback at the US OpenINIran's IRGC warns US strikes will tighten Strait of Hormuz amid mutual attacksUKIsraeli forces capture Hamas internal security head in Gaza raid, killing four PalestiniansPLGermany responds to Russian drone attack on Leipzig/Halle airportTRGalatasaray transferred Deniz Gül from Porto for 10 million EurosESPartial collapse of the Hurtado de Mendoza Palace in Almazán (Soria)ESIran attacks US bases in Jordan, Iraq and Bahrain in retaliation for US bombingsFRBouches-du-Rhône: a BAC police officer between life and death after a fall in Aix-en-ProvenceKRSouth Korean stocks open sharply lower amid U.S.-Iran military tensions and rising oil pricesTR1 Dead, 4 Injured in Car Accident That Hit a Family in ÇanakkaleITFlavio Cobolli celebrates victory after an epic comeback at the US OpenINIran's IRGC warns US strikes will tighten Strait of Hormuz amid mutual attacks
BackAI Security Startup AIR Raises $50 Million to Monitor AI Agent Supply Chain
AI Security Startup AIR Raises $50 Million to Monitor AI Agent Supply Chain
Developing
TechCrunch1 hour agoTech2 min readUnited States

AI Security Startup AIR Raises $50 Million to Monitor AI Agent Supply Chain

Quick Look

  • AI security startup AIR has raised $50 million across two seed rounds to build a platform that monitors and secures the software supply chain for AI agents, including skills, plug-ins, and MCP servers.
  • Founded by former Unit 8200 veterans Yair Saban and Niv Hoffman, the company offers discovery, continuous vetting, and enforcement tools to block unauthorized agent interactions.
  • With over 20 customers and strong demand in regulated industries, AIR aims to address risks from poisoned content consumed by autonomous AI agents.

AI-generated summary

Why It Matters

As AI agents gain broader access to corporate systems, concerns are growing about the security of the tools they use — such as skills, plug-ins, and MCP servers — which currently lack the same oversight as traditional software like drivers. AIR was founded by veterans of Israel's Unit 8200 intelligence corps to address this emerging supply chain risk.

Font size

As companies start giving AI agents access to an increasing portion of their systems, a nascent software supply chain seems to be forming around the new tooling AI agents are using: skills, plug-ins, MCP servers, and add-ons that let them interact with the internet.

AI security startup AIR believes companies will need a way to monitor that supply chain, and it’s now coming out of stealth with $50 million raised across two seed rounds to build that product.

Founded by Yair Saban (CEO) and Niv Hoffman (CTO), veterans of Israel’s Unit 8200 intelligence corps, where they worked on offensive cybersecurity, AIR offers a platform that can discover agents running inside companies, continuously vet any skills, tools, and components those agents use, and block them from interacting with software or external sources that don’t pass security criteria. It also offers a marketplace of vetted add-ons and skills for AI agents.

The funding rounds closed within weeks of each other, Saban told TechCrunch, with the first round raising $10 million, and the second $40 million. Sequoia led the first round, while Greenoaks led the second, Saban said. Swish, Netz, and Zach Frankel (president of Cognition), Yinon Costica (co-founder of Wiz), Ofir Ehrlich (co-founder of Eon), Anne Neuberger, Omer Adam, Varun Anand (co-founder of Clay), and other angel investors also participated.

AIR’s pitch goes thusly: The way AI agents are used wholesale at companies is beginning to resemble operating systems, but the tools they use, or the software they can install, aren’t yet being given the kind of oversight we give to drivers or applications.

“In the early 2000s, whenever you installed a driver, the driver didn’t need to be signed. Today, every time you install a driver, you see a signature saying who signed it, because the driver is actually loading code into the kernel,” Saban said. “You don’t have that with skills or plug-ins or MCPs, and it’s a shame, because it’s the same mechanism, it’s the same lesson, but we haven’t learned it.”

The big risk, he argues, is that as AI agents start working more autonomously across databases and enterprise systems, and connecting to the internet, attackers can poison the content an AI agent consumes instead of attacking it directly.

The startup says it can solve that with a visibility product that finds agents active across a company’s environment, as well as identifies employees who use AI tools unapproved by IT departments or those who use personal accounts. Then, it uses an enforcement layer that hooks into agents to intercept and analyze actions, like loading a skill or fetching content from the internet. Lastly, AIR also checks the tools, add-ons, or software an agent wants to use against a whitelist the startup maintains.

Saban says the startup maintains this whitelist by evaluating skills and add-ons openly available on the internet for changes and malicious behavior, as a previously approved skill could become risky if a package it downloads changes, or its developer’s account is compromised. He added that AIR’s platform currently filters out about 27% of the add-ons and skills it finds online.

AIR claims it has more than 20 customers, and Saban said roughly a quarter of these are large enterprises. He said the company has so far seen the strongest demand in heavily regulated industries, particularly financial services and pharmaceutical companies.

However, AIR is hardly alone in this space. Noma Security offers discovery, access controls, and runtime monitoring for agents, MCP servers, and skills, while Zenity sells security and governance tools that work similarly. Astrix Security‘s identity platform also lets companies discover and control agents and MCP servers, and Operant AI offers agent protections as well as an MCP gateway.

There is significant venture money chasing the category, too. Zenity raised a $125 million Series C in August, while Noma raised a $100 million Series B last year.

Saban thinks AIR’s moat lies in its ability to continuously vet the skills and add-ons ecosystem growing around AI agents. “Continuously vetting skills and plug-in websites, this is a hard mission to do. Gaining visibility over the endpoint, that is easy. Everybody’s going to do it. It’s hard to create a moat around that,” he said.

And while the CEO acknowledged that AI labs and providers will eventually build in security checks and policies to filter out malicious skill and tool usage, he thinks companies will still want to buy an independent product that works across vendors.

“This is not a scanning problem, it is a continuous re-verification problem,” Bogomil Balkansky, partner at Sequoia, told TechCrunch in an emailed statement. “Inspecting every skill, plugin, MCP server and sub-agent an enterprise’s agents touch, re-inspecting each one every time it changes, in real time and across an entire company’s agent fleet, is an infrastructure problem long before it is a security problem. Air has spent the last year building that pipeline. You do not catch up to it by writing a better scanner.”

AIR currently has around 40 employees. Saban said the new capital will primarily go toward hiring researchers and expanding the company’s go-to-market efforts in the U.S. and Europe.

What to Watch

AI outlook — possibilities, not facts

  • AIR will expand its customer base significantly in the U.S. and Europe over the next 6-12 months

    Likely · Within months

  • Demand for AI agent security tools will grow in regulated industries beyond financial services and pharmaceuticals

    Possible · Within months

  • AIR's continuous vetting model will become a key differentiator as the AI agent security market matures

    Likely · Within months

Open Questions

  • How does AIR's whitelist evaluation process work in practice?
  • What specific security criteria does AIR use to vet skills and add-ons?
  • How does AIR's platform integrate with existing enterprise IT and security stacks?
  • What are the pricing and deployment models for AIR's platform?

Related Topics

This article was originally published by TechCrunch.

Related Stories

Fambot Launches AI Chief of Staff for Parents to Manage Family Logistics
Developing·2 hours ago

Fambot Launches AI Chief of Staff for Parents to Manage Family Logistics

Fambot, a startup founded by former Instagram and Uber executives, introduces an AI chief of staff for parents to manage children's activities, school events, and family logistics by integrating email, calendar, and WhatsApp. Backed by $3.5 million in pre-seed funding, it offers a proactive daily checklist and plans to expand integrations with school and sports apps, aiming to become a central hub for family communications beyond text-based AI agents.

TechCrunch
2 min read
OpenAI Integrates ChatGPT Health with Epic EHR and Launches Healthcare Data Plugin
Developing·5 hours ago

OpenAI Integrates ChatGPT Health with Epic EHR and Launches Healthcare Data Plugin

OpenAI announced integration of ChatGPT Health with Epic's EHR system covering 325 million patients, enabling clinicians to access patient data and use AI for summaries and clinical workflows. The company also launched a Healthcare Public Data plugin pulling from sources like ClinicalTrials.gov and PubMed, and confirmed that ChatGPT for Health is now available to all U.S. consumers, with physicians reporting 99.1% safety in over 4,300 responses across 27 use cases.

TechCrunch
2 min read
Microsoft 365 Outage Continues Into Second Day as Mitigation Efforts Progress
Developing·7 hours ago

Microsoft 365 Outage Continues Into Second Day as Mitigation Efforts Progress

Microsoft's multi-day Outlook and Microsoft 365 service outage entered its second day on Tuesday, with the company reporting ongoing mitigation efforts after a core authentication configuration issue caused email delays, authentication failures, and degraded functionality across Outlook, SharePoint, Teams, Copilot, Purview, Defender XDR, Admin Center, and Universal Print services. While mail flow and search functionality showed gradual improvement, Microsoft had not declared full service restoration.

TechCrunch
2 min read
Google launches AI-powered image creation tool Google Pics for Workspace and AI subscribers
Developing·9 hours ago

Google launches AI-powered image creation tool Google Pics for Workspace and AI subscribers

Google is introducing Google Pics, an AI-driven image creation and editing tool powered by its Nano Banana model, to Google Workspace and Google AI Pro/Ultra subscribers. The tool, designed for everyday design tasks like posters and social media visuals, will roll out over the coming weeks, starting with Docs and Slides before expanding to Drive. Unlike Canva or Adobe Express, Google Pics focuses on AI-generated content from prompts rather than template marketplaces or manual design from scratch.

TechCrunch
1 min read
Anthropic releases Fable and Mythos 5.1 AI models with performance upgrades and new privacy controls
Developing·9 hours ago

Anthropic releases Fable and Mythos 5.1 AI models with performance upgrades and new privacy controls

Anthropic released Fable and Mythos 5.1, twin versions of its most advanced AI model, featuring performance improvements, reduced token costs, and relaxed safeguards. Mythos 5.1 remains restricted to registered partners in cybersecurity and life sciences, while Fable 5.1 is publicly available via cloud platforms and API. The release includes a new high-privacy service, Enterprise Frontier Safeguards, launching in June, allowing clients to run models on their own infrastructure with controlled monitoring. Anthropic confirmed no unauthorized access to enterprise data and highlighted benchmark records in Terminal-Bench 4.0 and Humanity’s Last Exam, along with three novel scientific findings generated by the models. The system card rates Mythos as 'low-risk' for automated AI development but notes a slight regression in misaligned behavior compared to Opus 5, while improving over prior Mythos and Claude Sonnet versions.

TechCrunch
2 min read
More on this topicai agents