As companies begin to give AI agents access to more and more parts of their systems, a nascent software supply chain appears to be forming around the new tools used by AI agents: skills, plugins, MCP servers, and add-ons that allow them to interact with the internet.
AI security startup AIR believes businesses will need a way to monitor their supply chains, and is now coming out of stealth after raising $50 million in two seed rounds to build its product.
Founded by Yair Saban (CEO) and Niv Hoffman (CTO), veterans of Israel’s 8200 Unit Intelligence Unit, which worked on offensive cybersecurity, AIR provides a platform that can discover agents running within enterprises, continually scrutinize the skills, tools, and components they use, and block interactions with software and external sources that do not meet security standards. We also provide a marketplace of vetted add-ons and skills for AI agents.
Saban told TechCrunch that each funding round closed within a few weeks of each other, with the first round raising $10 million and the second raising $40 million. Saban said Sequoia led in the first round and Green Oaks led in the second round. Swish, Netz, Zach Frankel (President of Cognition), Inon Kostica (Co-founder of Wiz), Ofir Ehrlich (Co-founder of Eon), Ann Neuberger, Omar Adam, Varun Anand (Co-founder of Clay), and other angel investors also participated.
AIR’s pitch is: Although the way AI agents are being used extensively in enterprises is becoming more similar to operating systems, the tools they use and the software they can install have not yet been given the same oversight that drivers and applications are given.
“In the early 2000s, you didn’t have to sign your driver every time you installed it. Now, every time you install a driver, you see a signature saying who signed it, because the driver is actually loading the code into the kernel,” Saban said. “Skills and plugins and MCPs don’t have that, and that’s a shame because it’s the same mechanics and the same lessons. But we haven’t learned that.”
The big risk, he argues, is that as AI agents begin to operate more autonomously across databases and enterprise systems and become connected to the internet, attackers could contaminate the content they consume rather than directly attacking them.
The company says it can solve this problem with a visibility product that finds active agents across a company’s environment and identifies employees who are using AI tools or personal accounts that are not approved by IT. It then uses an enforcement layer that connects to the agent to intercept and analyze actions such as loading a skill or retrieving content from the internet. Finally, AIR checks the tools, add-ons, or software that the agent wants to use against a whitelist maintained by the startup.
Saban said the startup maintains this whitelist by evaluating publicly available skills and add-ons on the internet for changes or malicious behavior, since previously approved skills could be at risk if a downloaded package is modified or a developer’s account is compromised. He added that AIR’s platform currently excludes about 27% of add-ons and skills found online.
AIR claims to have more than 20 customers, of which Saban said about a quarter are large corporations. He said the company has so far seen the strongest demand from highly regulated industries, particularly financial services and pharmaceutical companies.
However, AIR is not alone in this field. Noma Security provides discovery, access control, and runtime monitoring for agents, MCP servers, and skills, and Zenity sells security and governance tools that do the same. Astrix Security’s identity platform also allows enterprises to discover and control agents and MCP servers, and Operant AI provides agent protection and MCP gateways.
There’s also a lot of venture capital chasing this category. Zenity raised $125 million in Series C in August, and Norma raised $100 million in Series B last year.
Saban believes AIR’s moat lies in its ability to continually vet the growing ecosystem of skills and add-ons around AI agents. “Continually vetting skills and plugin websites is a difficult mission to perform. Gaining endpoint visibility is easy. Everyone is trying to do it. It’s hard to build a moat around it,” he said.
The CEO also acknowledged that AI labs and providers will eventually build in security checks and policies to filter out the use of malicious skills and tools, but believes companies still want to buy independent products that work across vendors.
“This is not a scanning issue, but a continuous revalidation issue,” Sequoia partner Bogomil Balkansky told TechCrunch in an emailed statement. “Inspecting every skill, plugin, MCP server, and subagent that an enterprise’s agents touch, and re-examining each one as it changes, is an infrastructure issue long before it’s a security issue. Air has spent the last year building that pipeline. Just because we create a better scanner, we’re not going to catch up.”
AIR currently has approximately 40 employees. Saban said the new funding will be used primarily to hire researchers and expand the company’s go-to-market efforts in the United States and Europe.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.
