AIR, an AI security startup, has emerged from stealth with EUR 43 million raised across two seed rounds to help companies monitor the software supply chain forming around AI agents. As businesses grant AI agents access to more of their internal systems, a new ecosystem of skills, plugins, MCP servers, and add-ons has taken shape, and AIR aims to bring oversight to it.
The company was founded by CEO Yair Saban and CTO Niv Hoffman, both veterans of Israel’s Unit 8200 intelligence corps, where they worked on offensive cybersecurity. Their platform discovers AI agents running inside organizations, continuously vets the skills, tools, and components those agents use, and blocks interactions with software or external sources that fail to meet security criteria. AIR also operates a marketplace of pre-vetted add-ons and skills for AI agents.
Two Rounds, Backed by Sequoia and Greenoaks
The two funding rounds closed within weeks of each other. The first raised EUR 9 million and was led by Sequoia, while the second brought in EUR 34 million and was led by Greenoaks. Additional participants included Swish, Netz, Zach Frankel (president of Cognition), Yinon Costica (co-founder of Wiz), Ofir Erlich (co-founder of Eon), Anne Neuberger, Omer Adam, Varun Anand (co-founder of Clay), and other angel investors.
Saban compares the current moment to the early 2000s, when installing a driver didn’t require a signature. Today, driver signatures identify who signed the code loading into the kernel, but no equivalent safeguard exists for skills, plugins, or MCPs, even though the underlying mechanism is similar.
How AIR Vets AI Agent Tooling
According to Saban, the primary risk is that autonomous AI agents working across databases, enterprise systems, and the internet can be compromised indirectly. Attackers can poison the content an agent consumes rather than targeting the agent itself.
AIR addresses this with a visibility layer that locates active agents across a company’s environment and flags employees using unapproved AI tools or personal accounts. An enforcement layer then hooks into agents to intercept and analyze actions, such as loading a skill or fetching content from the internet. Finally, AIR checks any tool, add-on, or software an agent wants to use against a whitelist it maintains.
The company keeps this whitelist current by evaluating openly available skills and add-ons for changes and malicious behavior. A previously approved skill can become dangerous if a package it downloads changes or if its developer’s account is compromised. AIR says its platform currently filters out roughly 27% of the add-ons and skills it finds online.
The startup reports more than 20 customers, with about a quarter of them being large enterprises.
Source
Image: techcrunch.com