AI Agent Security Startup AIR Raises $50 Million
AI agent security startup AIR raises $50 million to build an inline firewall, protecting enterprise supply chains from shadow AI and poisoned plugins.
Executive summary
- $50 million seed validation: Startup AIR just emerged from stealth with a massive $50 million seed round to build an inline firewall for enterprise AI agents.
- The shadow AI threat: Employees are secretly deploying autonomous agents that pull unverified third-party tools and plugins to execute tasks in your ERP and supply chain.
- A new attack vector: Hackers aren’t targeting your core AI models anymore; they are poisoning the external data and skills those agents consume to infiltrate your operations.
Table of contents
You think your enterprise data is secure. You bought a private instance of a leading LLM. You locked down the prompt layer. You trained your staff on data privacy. You feel safe.
You shouldn’t.
Right now, your supply chain managers are connecting autonomous AI agents to your databases to automate procurement. Those agents are reaching out to the open web, pulling third-party plugins, and executing code. They do this without IT approval. They do it fast.
This is shadow AI. And it is terrifying enterprise buyers.
Why Sequoia and Greenoaks just threw $50M at a six-month-old startup
Money talks. When two of the pickiest growth investors write a $50 million check for a seed round, you pay attention.
On September 1, AI security startup AIR emerged from stealth with exactly that backing. Founded by Yair Saban and Niv Hoffman, veterans of Israel’s Unit 8200 intelligence corps, AIR is building an enforcement layer for the autonomous enterprise.
Their premise is simple but alarming. AI agents are no longer just chat interfaces. They are independent workers. They access business applications, read internal documents, and retrieve internet services. To do this, they rely on a massive, unregulated marketplace of skills, plugins, and Model Context Protocol (MCP) servers.
27% — The percentage of publicly available AI agent add-ons and skills that AIR’s platform currently filters out due to malicious behavior or vulnerabilities. Source: SiliconANGLE 2026
Think about that number. More than a quarter of the tools your agents might try to use are compromised.
The myth of the rogue AI model
Here is where most CTOs and brand managers get it completely wrong. They think the biggest AI threat is data leakage. They worry about an LLM hallucinating a bad contract or spitting out sensitive IP to a customer.
Wrong. The real danger is software supply chain poisoning.
If an attacker wants to infiltrate your operations, they don’t waste time trying to crack the underlying model. Instead, they compromise a random, seemingly harmless developer plugin that an agent uses to format Excel sheets. Once your agent fetches that poisoned tool, the attacker has a backdoor straight into your systems. This is precisely the AI supply chain risk every enterprise is ignoring.
Let’s say you ask an agent to track competitor pricing. It reaches out to a standard open-source web scraper plugin. But what happens if a bad actor recently hijacked that plugin’s code? The agent executes the task, but quietly exfiltrates your proprietary pricing strategy back to the attacker.
Your AI agent isn’t going rogue. It is just following instructions from a malicious external source.
FREE SESSION
Stop guessing what your AI agents are doing Find out where your vulnerabilities lie and how to deploy safely.
free 30-min diagnostic
Your brand operations are completely exposed
If you run operations for a major manufacturer, you are under massive pressure to cut costs. You want to automate. You see that SAP’s autonomous enterprise 50 AI agents are now running your ERP. Your teams want to move at that exact speed.
But speed kills security.
Employees are adopting AI tools via personal accounts. They authorize agents to crawl internal databases. AIR’s platform was built precisely for this chaos. It acts as an inline firewall, sitting between the agent and the tools it tries to access. It intercepts actions, checks the requested add-ons against a whitelist, and blocks unapproved external connections.
Epinium data: 68% of enterprise marketing and supply chain teams have deployed at least one autonomous AI agent workflow without formal IT security clearance.
You cannot afford to ignore this. Regulated sectors like financial services and pharmaceuticals are already panicking. Brands and manufacturers are next. If a poisoned agent alters inventory orders or exposes supplier contracts, the financial damage will be immediate.
Audit your systems. Right now.
You need visibility into what agents are operating inside your environment. You must continuously assess the skills and components they use. If an initially approved plugin changes its code overnight, your security framework must catch it before the agent executes the next task.
Don’t wait for a massive breach to make the front page.
What does AIR Security actually do?
AIR provides an inline firewall for enterprise AI agents. It discovers agents operating within a company’s environment, continuously evaluates the third-party skills and plugins they use, and blocks interactions with malicious or unapproved software.
Why is a $50 million seed round significant?
Raising $50 million across two seed rounds within six months is highly unusual. It signals that enterprise buyers are already terrified of the security gaps created by autonomous AI agents, pushing top-tier investors like Sequoia to fund solutions aggressively.
How do AI agents compromise supply chains?
Agents often operate autonomously, pulling data and using external plugins to complete tasks. Attackers poison these third-party tools. When the agent uses a compromised tool, it unwittingly grants the attacker access to internal enterprise systems.
Can’t we just block employees from using AI?
No. Outright bans lead to “shadow AI,” where employees secretly use personal accounts and unvetted tools to get their work done faster. A better approach is deploying an enforcement layer to monitor and secure agent activity.
How does this affect brands and manufacturers?
Brands and manufacturers are rapidly adopting AI to automate procurement, inventory management, and marketing. If an unverified AI agent accesses sensitive ERP data using a malicious plugin, it can disrupt operations and expose confidential supplier contracts.
It is time to take control of your autonomous workflows. Because right now, you are flying blind.
AI CONSULTING BY EPINIUM
Secure your autonomous enterprise Join dozens of leading brands auditing their AI supply chains with us.
free 30-min diagnostic