AI agent firewall startup AIR Security comes out of stealth with $50 million

AI agent firewall startup AIR Security comes out of stealth with  million

If AI agents are the new operating system, then AI add-ons are the new applications; and a new type of AI firewall is needed to maintain security.

Aviation security comes out of stealth with $50 million in funding and a firewall, aka AIR, built for AI agents. The financing is led by Sequoia Capital and Greenoaks, along with a number of prominent individual industry angels.

This follows AIR Security’s research which found that more than 17,800 public AI add-ons (equivalent to 6.7 million installs) rely on untrusted external command sources. The company also discovered AI capabilities in the wild by posing as companies like Anthropic and OpenAI, designed to bypass security reviews and execute arbitrary code.

AI agents are increasingly connecting to more third-party tools, data and services; Browse websites, access files and email, and act on behalf of employees. Their growing autonomy is problematic when they are influenced and controlled by opponents through toxic content or direct compromises. This opens the door to data theft, fraud, or unauthorized access and provides little visibility to the security team.

AIR refers to AI agents as the new operating system and AI add-ons as the new applications. “We are entering a new era in which the use of AI agents for knowledge work will be as fundamental as reading, writing and using Excel. Agents will become a fundamental part of the way companies build, work and make decisions – unlocking entirely new levels of speed, productivity and possibility,” says AIR.

Of particular concern is the new and increasing release of coding agents: Claude Code, Cursors, Codex and everything around them. Companies have begun adopting these tools at an unprecedented pace. But they’re also afraid of using them without a seatbelt – and rightly so, suggests AIR.

Advertising. Scroll to continue reading.

“Every company has a firewall that protects their network. Now they need one that protects their AI agents. AI agents need a new kind of firewall – one that protects what enters their context,” he says Yair SabanCo-founder and CEO of AIR. “Today, agents install tools, connect to internal systems, and make decisions on their own—and in most organizations, no one knows what’s running, what’s trustworthy, or how to turn it off.”

Saban (CEO) is a partner of Niv Hoffman (CTO) AIR to provide such an AI-specific firewall. They were joined by Ryan Knisleyformer CISO at The Walt Disney Company and Costco Wholesale, to Chief Strategy Officer.

The firewall detects and evaluates all capabilities, plugins, MCP servers and add-ons in an organization’s AI agent supply chain, both before and after deployment. Before allowing a third-party or internal add-on to attack an enterprise agent, AIR conducts a thorough analysis of all known agent attack patterns. It looks for external command sources, hidden behaviors, and typo-filled packages masquerading as official developer tools.

If an add-on is malicious, vulnerable, or unapproved, security teams can track every agent and workflow that depends on it – and revoke it across the organization. This process is continuous. If a maintainer releases a malicious update or an existing integration is later compromised, trust will be automatically revoked.

“Like a black box, AI add-ons reveal less than they hide. Some stay the same. Some evolve. Others hide external instructions, excessive actions, access to sensitive data or vulnerable supply chains,” says AIR.

By continuously assessing agent activity across many customers, AIR also provides a marketplace of pre-vetted, certified add-ons, providing all customers with a safe path to expanding agent functionality without introducing uncontrolled risks.

Related: OpenLeash adds human control to risky AI agent actions

Related: In addition to the industry’s commitment, the British government is also introducing a plan to counter agent AI

Related: Critical vulnerability exposes GitHub Agentic workflows to the possibility of immediate injection

Related: Agentic AI Security: Wrong context, wrong decisions at machine speed

Leave a Reply

Your email address will not be published. Required fields are marked *