
Six-month-old AIR Security raises $50 million to build a firewall for AI agents
The Israeli startup emerged from stealth with research showing thousands of AI add-ons rely on untrusted sources, as companies give autonomous agents access to more data, tools and systems.
Cybersecurity company AIR Security, which develops a security platform for the supply chain of AI agents, has raised $50 million in funding led by Sequoia Capital and Greenoaks.
Swish Ventures and Netz also participated, alongside private investors including Zach Frankel (President, Cognition), Yinon Costica (Co-founder, Wiz), Ofir Ehrlich (Co-founder, Eon), Anne Neuberger, Omer Adam, Varun Anand (Co-founder, Clay); and other senior figures from the cybersecurity and AI industries.
AIR emerged from stealth alongside the funding. The company was founded in February 2026 by Yair Saban and Niv Hoffman, who met about a decade ago in the military. The two have backgrounds in offensive cybersecurity, enterprise infrastructure and AI security research.
The company currently employs 40 people in Israel, with a focus on building a research laboratory dedicated to AI and the behavior of AI agents. Ryan Knisley, the former chief information security officer of The Walt Disney Company and Costco Wholesale, has also joined AIR as chief strategy officer.
The size of the round is notable given how recently the company was founded. AIR is betting that as companies move from experimenting with AI agents to relying on them for increasingly important tasks, a new security layer will be needed to protect the tools, information and instructions those agents encounter.
The company describes that layer as an “inline firewall” for AI agents, a system designed to protect what enters an agent’s context rather than simply restricting what the agent is allowed to do.
As enterprises deploy more AI agents, those systems can connect to an expanding range of tools, information and third-party services. Agents can browse websites, read emails and files and perform actions on behalf of employees. They can also install AI plugins and use Skills, MCP servers and subagents to extend their capabilities.
That creates a different kind of security challenge. Malicious content or a compromised tool could influence an agent and cause it to take an action it was not intended to take, potentially creating risks ranging from data theft and fraud to unauthorized access.
Unlike traditional software, AI agents make decisions based on information they encounter while carrying out their tasks. That can make it harder for security teams to understand what is influencing an agent, what systems it can access and what actions it may ultimately take.
“Every enterprise has a firewall protecting its network. Now they need one protecting their AI agents,” Saban, AIR’s co-founder and CEO, told Calcalist. “AI agents need a new kind of firewall, one that protects what enters their context.”
Saban argues that the problem is not simply that companies are giving AI agents too many permissions.
“We believe that AI agents are a hedged risk,” he said. “Organizations are gaining trust in agents and companies are counting on them to deliver products. There is more and more trust, and they are granting increased permissions.”
But Saban argues that permissions are not the only, or even the primary, source of danger.
“We think it becomes dangerous when it is exposed to malicious information,” he said.
According to Saban, there are three main sources of that risk: extensions and tools installed on an agent, websites it encounters online, including fraudulent or fake sites, and internal organizational information.
“We think that this is the source of the risk, not unnecessary permissions,” he said. “There are new challenges today and you need to know that everything it encounters is filtered.”
AIR's launch follows a series of security studies conducted by the company into what it describes as the supply chain surrounding AI agents.
In one study, AIR found more than 17,800 public AI add-ons representing approximately 6.7 million installations that relied on untrusted external sources for instructions.
In another, the company identified AI Skills impersonating trusted brands, including Anthropic and OpenAI, in an attempt to bypass platform security reviews. One of the Skills was capable of executing arbitrary code on enterprise systems, according to AIR.
The research points to a problem that could become more significant as agents gain greater autonomy: the software and information surrounding an agent can become a means of influencing its behavior.
AIR has developed a real-time firewall designed to protect the information entering an AI agent's context and block malicious instructions, untrusted information and compromised tools before they can influence the agent's decisions or actions.
The platform continuously discovers and evaluates Skills, plugins, MCP servers and other add-ons across an organization's AI-agent supply chain, both before and after deployment.
When an add-on is found to be malicious, vulnerable or unapproved, AIR allows security teams to trace the agents and workflows that depend on it and revoke its use across the organization.
The company is also developing a marketplace of pre-vetted and certified add-ons, giving enterprises a way to expand the capabilities of their agents without introducing tools that have not been reviewed.
“We started selling to big companies and we have some big customers,” Saban said. “We started hiring employees in the United States and one of them was a senior executive at Disney and is now a senior executive with us.”
The company is entering a market in which the competitive landscape is likely to change quickly. AI security has attracted a growing number of startups, while the underlying technology itself is evolving rapidly.
Saban acknowledges that AIR cannot assume its lead will last.
“In principle, it was also very easy to copy in the past. The seriousness of developing software has dropped significantly. Many companies are emerging today,” he said.
His argument for differentiation is that AIR is concentrating specifically on prevention rather than detection after an agent has already been compromised.
“There are many AI companies today and many focus on other areas and we focus on prevention, and this differentiates us from our competitors,” Saban said.
He also believes the technology behind AIR's security engine will be difficult to replicate.
“The engine that we developed will be very difficult to develop. We have accumulated expertise over time. We have a significant difference from the others and it is the focus on prevention,” he said.
The company intends to use the new capital to expand its operations and accelerate its commercial activity.
“We have raised a lot of money and are using it and will raise more rounds,” Saban said. “I am optimistic that we will be able to raise additional rounds. I expect that we will reach significant sales in the coming year.”














