As autonomous AI agents tap enterprise databases and internet-connected systems, a volatile software supply chain is forming. AIR, a cybersecurity startup fresh out of stealth, secured $50 million to vet the skills, plugins, and Model Context Protocol (MCP) servers these agents depend on.
Securing the New "Agentic" Operating System
AI agents are reshaping how software talks to enterprise environments. Like an operating system, they load “skills” and add-ons to get work done. Traditional drivers carry digital signatures; most AI components lack any formal verification.
Yair Saban (CEO) and Niv Hoffman (CTO)—both veterans of Israel’s Unit 8200—built AIR to stop “poisoned” content. When agents act on compromised data, they can trigger unauthorized actions or data breaches.
A Multi-Layered Approach to Agent Governance
AIR’s platform does more than scan. It enforces policies continuously across three pillars:
- Discovery – hunts every active AI agent, even hidden “Shadow AI” tools employees spin up.
- Enforcement – intercepts actions in real time, flagging skill loads or external web fetches.
- Continuous Vetting – runs a pipeline that checks each skill and add-on against a whitelist. Because a once-safe skill can turn malicious if its developer is compromised, AIR re-verifies it constantly. So far, the system blocks about 27 % of online add-ons it encounters.
Funding and Market Competition
AIR raised $50 million in two seed rounds: $10 million led by Sequoia and $40 million led by Greenoaks. Investors include Zach Frankel (President, Cognition), Yinon Costica (Co-founder, Wiz), and several cybersecurity and AI angels.
The market is crowded. Zenity, Noma Security, Astrix Security, and Operant AI all chase the same space. AIR’s founders claim their edge lies in solving the “continuous re-verification” problem. Sequoia partner Bogomil Balkansky summed it up: securing an agent fleet demands a real-time inspection pipeline, not just a better scanner.
With more than 20 customers—several large firms in finance and pharmaceuticals—AIR will use the new capital to grow research teams and expand sales across the U.S. and Europe.
Key Takeaways
- New Attack Vectors: AI skills, plugins, and MCP servers create a software-supply-chain risk where attackers inject poisoned data.
- Continuous Re-verification: AIR monitors agent components continuously, spotting behavior changes or malicious updates as they happen.
- Enterprise Demand: Regulated sectors such as financial services and pharma are pushing for strict governance of autonomous agents.
Bottom line
AIR’s $50 million raise signals that companies see autonomous agents as needing the same supply-chain safeguards that traditional software has long required. By offering discovery, real-time enforcement, and nonstop re-checking of every skill and plugin, the startup turns a vague risk into a concrete control. Whether enterprises can deploy the solution at scale—and whether AIR can outpace rivals racing to solve the same problem—will decide if the agentic supply chain becomes a hardened part of corporate infrastructure or stays a lingering vulnerability.
