AIR Raises $50M to Build a Firewall for AI Agents
AIR emerged from stealth with $50M raised across 2 Seed rounds to secure the expanding supply chain around enterprise AI agents. Sequoia Capital led an initial $10M round, and Greenoaks led a $40M follow-on that closed within weeks, according to TechCrunch.
The Tel Aviv cybersecurity company was founded in February 2026 by CEO Yair Saban and CTO Niv Hoffman, veterans of Israel's Unit 8200 with backgrounds in offensive security, enterprise infrastructure, and AI security research. AIR is building what it calls a context firewall, a control layer that evaluates the skills, plugins, MCP servers, sub-agents, websites, and internal data entering an agent's working context.
The financing matters because enterprise security is being asked to govern software that can assemble part of its own operating environment. A conventional application arrives through a procurement and deployment path. An agent can discover a useful component, load it, follow an external instruction, and act across company systems before the component has a familiar vendor name.
What Happened
AIR raised $50M across 2 Seed rounds that closed within weeks. Sequoia led the first $10M financing, while Greenoaks led the next $40M. Swish, Netz, Cognition president Zach Frankel, Wiz co-founder Yinon Costica, Eon co-founder Ofir Ehrlich, Anne Neuberger, Omer Adam, Clay co-founder Varun Anand, and other angel investors also participated.
AIR did not disclose a valuation or investor ownership percentages. The $50M is the total of the 2 Seed rounds, not a separate third financing. The company says the proceeds will primarily support hiring researchers and expanding go-to-market work in the U.S. and Europe.
AIR was incorporated in Israel in February 2026 and operates from 34 Yehuda HaLevi Street in Tel Aviv. Sequoia's account of the partnership says its team met Saban and Hoffman before the company had a name or product, then backed their plan to build supply-chain defenses for AI agents.
Why AI Agents Create a Different Security Handoff
An AI agent becomes useful by connecting to tools. Skills package instructions, plugins bundle capabilities, MCP servers expose tools and data, and sub-agents divide work. Each connection expands the agent's reach, but each also introduces a dependency whose code, owner, domain, package, or external instructions can change after approval.
That timing problem is AIR's central argument. Static scanning answers whether a component looked acceptable when it was reviewed. Enterprise operations need to know whether the same component is still acceptable after its repository moves, a package changes, a domain expires, or an attacker replaces an external instruction source.
AIR's official launch post frames the product as a firewall for agent context. Instead of focusing only on what an agent is permitted to access, AIR examines what enters the context that shapes the agent's decisions and actions. The company describes pre-runtime filtering as its main advantage, with runtime controls providing another layer once the agent begins acting.
How AIR's Platform Works
AIR Control discovers approved and shadow agents, then governs configuration, identity, and permissions. AIR Filter evaluates skills, plugins, MCP servers, and sub-agents before installation. AIR Defend monitors the actions an agent takes at runtime, while AIR Marketplace supplies a managed catalog of vetted internal and external components.
The customer is buying a continuously updated trust decision rather than another one-time scanner result. If a security team discovers that one dependency has become unsafe, the operating value comes from locating every agent and workflow that depends on it, then revoking or blocking the component before the problem spreads.
The company is entering a market with active competition. Noma Security, Zenity, Astrix Security, and Operant AI all address parts of AI-agent discovery, governance, runtime protection, identity, or MCP security. AIR's differentiation depends on whether its continuously updated component intelligence becomes durable infrastructure across multiple agent platforms.
Research Evidence and Early Traction
AIR has used offensive research to demonstrate the gap it wants to sell against. In The Circus of Skills, the company reported finding 17,822 open-source skills tied to untrusted external instruction sources, representing 6.7M installations. Its researchers said the issue affected 12.4% of the GitHub open-source skills they examined, with installation totals based on the 9,500 most popular skills on skills.sh.
In a separate skill-hijacking experiment, AIR said one malicious skill reached more than 26,000 agents after ordinary scanners and reputation signals treated it as safe. These are company-produced research results, not independent audits, but they show why a component that remains technically unchanged can still become dangerous when something it trusts changes elsewhere.
AIR reports more than 20 customers, roughly one-quarter of them large enterprises. The company says demand is strongest in regulated industries, particularly financial services and pharmaceuticals, and that its platform filters out about 27% of the add-ons and skills it evaluates. Those traction and filtering metrics remain company-reported.
Leadership and the Capital Behind the Bet
Saban serves as co-founder and CEO, while Hoffman serves as co-founder and CTO. Both founders worked in offensive cybersecurity after meeting through military service. AIR's current team also includes Chief Strategy Officer Ryan Knisley, a former CISO of The Walt Disney Company and Costco Wholesale, according to CTech and AIR's current company profile.
The investor sequence is notable because the second round was 4 times the size of the first and closed only weeks later. Sequoia partner Bogomil Balkansky described the problem as continuous re-verification across every skill, plugin, MCP server, and sub-agent touching an enterprise fleet. Greenoaks' participation places another large technology investor behind the view that agent supply-chain security can become its own infrastructure category.
What This Funding Signals
Enterprise AI security is moving from model behavior toward the environment around the model. Prompt injection, unsafe tools, shadow agents, compromised packages, and changing external sources can all influence what an agent sees and does. The more autonomy companies grant agents, the more expensive an untracked trust decision becomes.
AIR now has enough capital to build a research-heavy product and sell it into cautious enterprise security teams. The unanswered commercial question is whether companies will buy an independent control layer before agent platforms make equivalent safeguards part of their standard stack.
That answer will develop in the dependency graph itself. Every new skill, MCP server, plugin, and agent adds utility, and each adds another relationship security teams may eventually need to discover, verify, and revoke without waiting for the agent's next action to explain what went wrong.
Frequently Asked Questions
Why did AIR raise $50M across 2 Seed rounds?
AIR says the capital will primarily support security research and go-to-market expansion in the U.S. and Europe. The company is building controls for the skills, plugins, MCP servers, sub-agents, and external content used by enterprise AI agents.
What is a context firewall for AI agents?
AIR uses the term for a security layer that analyzes what enters an agent's context and controls what the agent may trust, access, or execute. Its platform combines discovery, pre-installation vetting, runtime protection, governance, and a managed marketplace.
Who led AIR's funding rounds?
Sequoia Capital led AIR's initial $10M Seed round, and Greenoaks led a $40M follow-on that closed within weeks. Swish, Netz, and several cybersecurity and AI operators also participated.
What evidence supports AIR's security thesis?
AIR reports finding 17,822 open-source skills tied to untrusted external instruction sources, representing 6.7M installations. It also demonstrated how a malicious skill could reach more than 26,000 agents after conventional reputation and scanning signals cleared it; these results are company-produced research.
What should enterprise buyers watch next?
The important proof is whether AIR can continuously identify risky dependencies across different agent platforms, locate every affected workflow, and enforce revocation without adding impractical friction. Independent validation of detection quality, false positives, and customer outcomes will matter as the category develops.
Where the Money Moved
The intelligence briefing of the innovation economy. Funding, M&A, debt and fund closes, read as market signal rather than deal announcements.
Subscribe to Where the Money Moved