Key Takeaways
- AIR Security has raised $50 million across two seed rounds led by Sequoia Capital and Greenoaks.
- AIR Security’s inline firewall discovers enterprise AI agents, vets their extensions, and blocks activity that fails security checks.
- A planned marketplace of approved add-ons could help regulated businesses manage the expanding AI agent supply chain.
Enterprise AI agents are moving beyond answering questions. They can browse websites, execute code, access business systems, and take actions with limited human involvement. That creates a thorny security issue: What happens when an approved agent connects to an untrustworthy tool?
Israeli cybersecurity startup AIR Security is building its business around that gap. AIR Security emerged from stealth on September 1 after raising a total of $50 million across two seed rounds led by Sequoia Capital and Greenoaks. Swish Ventures, Netz, and angel investors from cybersecurity and artificial intelligence also participated, according to TechCrunch.
AIR Security describes its product as an inline firewall for autonomous agents. The platform discovers agents operating inside an enterprise, identifies the skills, plugins, add-ons, and MCP servers connected to them, and evaluates those components against security criteria. It then monitors agent activity in real time, tracing actions and blocking behavior deemed malicious or unauthorized.
Traditional security reviews often happen before an application is deployed, while agent behavior can change as new tools are added or external services are updated. An extension that appeared acceptable during procurement could later connect to another data source, request broader permissions, or produce unexpected code. AIR Security is betting that periodic reviews will not offer enough visibility for this more fluid environment.
The startup reports that roughly 27% of the skills and agent add-ons discovered online are rejected by its whitelist, according to Relve. These figures illustrate the scale of potentially unsafe extensions within the broader AI agent ecosystem.
An autonomous agent is only as trustworthy as the services it can call. Securing the underlying model does not automatically secure every plugin, credential, workflow, and external server attached to it. This dynamic resembles software supply-chain security, but with a faster-moving collection of components and an autonomous system deciding when to invoke them.
AIR Security also plans to operate a marketplace of pre-vetted and certified agent add-ons. The model is closer to a curated enterprise app store than an unrestricted plugin directory. Financial services and pharmaceutical businesses are among the early target markets, as both sectors face substantial regulatory oversight, sensitive data requirements, and a low tolerance for software taking unexplained actions.
Governance standards are evolving alongside the market. The NIST AI Risk Management Framework gives businesses a foundation for identifying, measuring, and managing AI risks, while proposed agent-focused extensions are beginning to address tool use and autonomy more specifically. AIR Security could provide a technical enforcement layer beneath those policies, although buyers will still need to define acceptable behavior, permissions, and escalation procedures.
AIR Security was co-founded by veterans of the Israeli military. The company operates a dedicated research lab focused on AI and agent behavior, supported by an executive team bringing enterprise security experience to the emerging platform.
Competition will likely intensify as AI security and LLMOps governance converge. Wiz and Cognition are among the vendors investing in guardrails and runtime controls, while established cybersecurity suppliers are also positioned to extend existing identity, network, and application controls toward agents. AIR Security’s challenge is to prove that a dedicated agent firewall catches risks broader platforms miss, without slowing legitimate automation or overwhelming security teams with alerts. The $50 million gives the startup room to make that case.
⬇️