Six-month-old AIR raised $50M from Sequoia and Greenoaks to vet and block the plugins, skills, and MCP servers that enterprise AI agents install and run.
Key Takeaways
- Sequoia led a $10M seed; Greenoaks followed with $40M, both closing within weeks ahead of AIR's September 1, 2026 public launch.
- AIR discovers enterprise AI agents, vets their plugins and MCP servers for malicious instructions or excess permissions, and blocks threats at runtime.
- The startup counts 20+ customers with early traction in financial services and pharma, and plans to expand its 40-person team across the U.S. and Europe.
Lead
AI agent security startup AIR emerged from stealth on September 1, 2026, disclosing $50 million raised across two seed rounds in its first six months of operation. Sequoia Capital led an initial $10 million round; Greenoaks Capital Partners followed with $40 million, both closing within weeks of each other. Founded in February 2026 and headquartered in the U.S., AIR is betting that enterprises deploying AI agents will need continuous oversight of the third-party tools those agents rely on - skills, plugins, and Model Context Protocol servers - in the same way security teams audit software libraries today.
What Does AIR Actually Build?
AIR's platform maps every AI agent running inside a company, then continuously evaluates the skills, plugins, MCP servers, and sub-agents those agents call. Tools carrying malicious instructions, excessive permissions, or supply chain risks get blocked at runtime before the agent can act on them. The company also operates a marketplace of pre-vetted add-ons, giving enterprises an alternative to pulling arbitrary tools from the open internet.
The product model mirrors software composition analysis - scanning third-party code libraries for vulnerabilities before they ship into production - applied to a newer and largely unmonitored layer of enterprise infrastructure. Ryan Knisley, former CISO at both The Walt Disney Company and Costco Wholesale, joined as Chief Strategy Officer. The hire signals where AIR sees its primary buyers: large regulated organizations already running mature security programs and now asking how agents fit into their risk posture.
Why Is AI Agent Security Drawing This Much Capital So Fast?
The pressure point is adoption speed outpacing tooling. Enterprises are granting AI agents access to internal systems, external APIs, and web browsing faster than security teams have developed frameworks to manage the exposure. Plugin ecosystems built atop agents - especially MCP servers since Anthropic introduced the protocol in late 2024 - are expanding without coordinated vetting standards. A compromised or misconfigured plugin can quietly grant an agent permissions the deploying organization never intended to extend.
Investors are treating that gap as immediate. The agentic AI security category has attracted over $3.6 billion in disclosed funding through early 2026, with multiple startups targeting different parts of the agent stack. AIR's narrower focus on the tool and plugin supply chain, rather than prompt injection or agent identity management more broadly, is a specific bet. Whether that focus proves to be precision or constraint depends on how enterprise buyers eventually define the category.
Who Is Behind AIR?
Yair Saban (CEO) and Niv Hoffman (CTO) co-founded AIR after serving in Israel's Unit 8200 intelligence corps, where both worked on offensive cybersecurity. That background is directly relevant: the attack vectors AIR defends against - supply chain compromise through third-party tools - are precisely the techniques offensive teams develop and exploit. Swish Ventures and Netz Capital participated alongside Sequoia and Greenoaks. Angel investors include founders of Wiz, Clay, and Cognition, plus former senior U.S. government cybersecurity officials. Valuation was not disclosed.
What Do the Customer Numbers Actually Reveal?
Twenty customers, roughly five of them large enterprises, is genuine early traction - not proof of scale. Financial services and pharmaceutical companies represent the strongest current demand, sectors where regulatory obligations around system access create urgency that other verticals have not yet developed. AIR intends to direct the new capital toward security research and go-to-market expansion in the U.S. and Europe, growing a team currently at about 40 people.
Outlook
AIR enters public view with substantial capital, a credible founding team, and a problem growing faster than existing solutions address it. The real test over the next 12 months is timing: whether regulated enterprises accelerate agent deployment quickly enough to create procurement cycles that match AIR's growth targets. If adoption in financial services and pharma moves at its current pace, the market will be there. If large organizations slow-walk agents specifically because of the security concerns AIR is trying to resolve, the category may take longer to develop than the funding pace implies.



