AIR secures $50M for AI agent skill and add-on oversight

AIR emerges with $50 million for AI agent supply-chain security
AI security startup AIR has emerged from stealth after raising $50 million across two seed rounds to build a platform for monitoring the skills, plugins, MCP servers and add-ons used by enterprise AI agents. The company was founded by chief executive Yair Saban and chief technology officer Niv Hoffman, veterans of Israel’s Unit 8200 intelligence corps.
The first round raised $10 million and was led by Sequoia. Greenoaks led the second, $40 million round, which closed within weeks of the first. AIR says it has more than 20 customers, around a quarter of them large enterprises, and has seen its strongest demand from regulated sectors including financial services and pharmaceuticals.
From agent discovery to runtime enforcement
AIR’s platform is designed to discover AI agents operating across a company environment, including employees using AI tools without IT approval or through personal accounts. It then continuously assesses the skills, tools and components those agents use, while an enforcement layer intercepts actions such as loading a skill or retrieving content from the internet.
The system checks requested tools and add-ons against a whitelist maintained by AIR. Saban said the company evaluates publicly available skills and add-ons for changes and malicious behaviour, because a component that was initially approved can become risky when a downloaded package changes or a developer account is compromised.
AIR says its platform currently filters out about 27% of the add-ons and skills it finds online. Its approach responds to a risk created when agents work autonomously across databases, enterprise systems and internet-connected services: attackers may seek to poison content consumed by an agent rather than attack the agent directly.
Continuous re-verification becomes the central claim
Saban compares the emerging agent ecosystem with the evolution of driver signing. Drivers now show who signed them because they load code into the kernel, while skills, plugins and MCPs do not yet receive comparable oversight. AIR argues that agent components require ongoing review rather than a single approval decision.
Sequoia partner Bogomil Balkansky described the task as a continuous re-verification and infrastructure problem: enterprises must inspect skills, plugins, MCP servers and sub-agents that their agent fleets touch, then inspect them again whenever they change. AIR positions its pipeline for that work as its differentiator.
The company operates in a competitive category. Noma Security provides discovery, access controls and runtime monitoring for agents, MCP servers and skills; Zenity sells related security and governance capabilities; Astrix Security focuses on identity controls; and Operant AI offers agent protections and an MCP gateway. AIR, which has around 40 employees, plans to use the new capital to hire researchers and expand go-to-market activity in the US and Europe.
For businesses, the practical implication is to apply security governance not only to an AI agent itself, but also to every external component and content source the agent can use as those dependencies change.

