Skip to main content

AIR Security Raises $50M to Build a Firewall for Enterprise AI Agents

Wednesday 2 September 2026|AIR Security|
Secure AI BrainAI Growth EngineEmployee Amplification Systems

AIR Security emerged from stealth on September 1 with $50 million in funding to build a security platform for AI agent supply chains. The platform discovers every AI agent running inside a company, vets the skills and tools those agents use, and blocks interactions with unapproved software or external sources. Sequoia Capital and Greenoaks co-led the two rounds.

Operator Insight

Most operators deploying AI agents have no idea what those agents are actually connecting to. An agent built on a third-party framework inherits every plugin, tool, and external call that framework makes. AIR's debut signals that the industry now treats the agent supply chain as a distinct attack surface, and if Sequoia and Greenoaks are backing a company to solve it at seed stage, the problem is already real and already widespread in enterprises larger than yours.

30-Second Summary

AIR Security, founded in February 2026, emerged from stealth on September 1 with $50 million in total funding to build what it calls a firewall for AI agents. The platform discovers every agent running inside a company, continuously vets the skills, tools, and add-ons those agents use, and blocks agents from interacting with software or external sources that fail its security criteria. Sequoia Capital led a $10 million first round; Greenoaks led a $40 million follow-on, with both rounds closing within weeks of each other.

At a Glance

  • Topic: AI Security
  • Company: AIR Security
  • Date: September 1, 2026
  • Announcement: $50M funding debut from stealth; enterprise AI agent security platform launch
  • What Changed: A dedicated security layer for the AI agent supply chain now exists and is backed by Tier 1 venture capital
  • Why It Matters: Enterprises deploying autonomous agents have had no systematic way to discover what those agents connect to, or to block unapproved interactions in real time
  • Who Should Care: Any operator deploying AI agents, any IT or security team responsible for AI governance, any business handling sensitive client or customer data with AI tools

Key Facts

  • Total funding: $50 million across two rounds
  • Round 1: $10 million, led by Sequoia Capital
  • Round 2: $40 million, led by Greenoaks Capital
  • Founded: February 2026 by Yair Saban and Niv Hoffman
  • Team size: Approximately 40 employees
  • Notable angels: Zach Frankel (President, Cognition), Yinon Costica (Co-founder, Wiz), Ofir Ehrlich (Co-founder, Eon), Varun Anand (Co-founder, Clay)
  • Platform capabilities: Agent discovery, supply chain vetting, real-time blocking, vetted skills marketplace
  • Expansion plans: Hiring researchers; U.S. and European go-to-market

What Happened

AIR Security launched publicly on September 1, 2026, having raised $50 million in seed financing without announcing either round until the debut. The company was founded in February 2026 by Yair Saban and Niv Hoffman, both with military intelligence backgrounds, after they identified the AI agent supply chain as a security gap with no dedicated solution.

The company's platform operates at the layer between AI agents and the services they connect to. It discovers all agents running inside an enterprise, not just the ones the security team knows about, and continuously monitors every tool, skill, and external call those agents make. When an agent attempts to interact with software or a data source that has not been approved, AIR blocks the interaction in real time.

AIR also offers a marketplace of pre-vetted agent skills and add-ons, designed to give enterprises a curated catalogue of approved components rather than requiring security teams to evaluate every third-party capability from scratch.

The funding represents one of the largest seed rounds in the enterprise AI security category to date (Source: TechCrunch, September 1, 2026). The participation of Yinon Costica, co-founder of Wiz, a company that reached a $32 billion valuation in 2024 by targeting a comparable infrastructure security gap, signals serious strategic conviction from practitioners who have seen this playbook succeed before.

Why It Matters

The agent supply chain is the new software supply chain risk. When developers import open-source packages, they accept every dependency that package pulls in. The same dynamic applies to AI agents: a framework or tool an agent uses may call external services, store outputs, or access systems the operator never explicitly authorised. AIR's launch is a formal recognition that this risk is now material for enterprises.

Enterprise AI deployment is accelerating faster than governance. Most organisations deploying AI agents in 2026 do not have a complete inventory of which agents are running or what those agents can reach. AIR's discovery capability alone addresses a gap that audit and compliance teams will increasingly flag as a liability.

Sequoia and Greenoaks backing a six-month-old company signals urgency. Two premier venture capital firms closing two rounds within weeks of each other, at seed stage, indicates both firms identified the same urgent enterprise problem independently. Enterprise security categories with this backing profile typically see rapid market formation in the following 12 to 24 months (Source: SiliconANGLE, September 1, 2026).

The vetted marketplace model is likely to become standard. AIR's marketplace of pre-approved skills follows the same pattern as mobile app stores and software composition analysis tools. If this model takes hold, enterprises will eventually require agent components to carry security certifications before procurement approval, much like software vendors today must pass SOC 2 audits.

Small and mid-size operators are more exposed than large enterprises. Large organisations have dedicated security and compliance teams to investigate agent behavior. Operators running AI agents across a 20 to 200 person company typically do not. The risk is proportionally higher, not lower, for lean teams running powerful autonomous systems.

Data liability is the most immediate concern. An AI agent with access to client files, CRM records, or financial data that makes unauthorised calls to an external service creates a data breach, regardless of intent. As privacy regulation in Australia and Europe tightens around AI data handling, the failure to monitor agent behavior will carry increasing legal exposure.

The David and Goliath View

The timing of AIR's launch is not coincidental. Enterprise AI agent deployment has reached the point where it is now running ahead of the governance frameworks designed to manage it. Operators who adopted Claude, ChatGPT, or similar tools twelve months ago were largely using them as assistants, supervised by humans in each interaction. The shift to autonomous agents, systems that take actions across multiple tools without human review at each step, has introduced a category of risk that standard IT security tools were not built to address.

What AIR is building is not a niche product. It is infrastructure for the agent era, the equivalent of the network firewall for the cloud era. The strategic validators on their cap table, people who built Wiz and Cognition and Clay, are not angels who write cheques out of goodwill. They back companies solving the next unavoidable problem. Enterprise AI governance is that problem for 2026 and 2027.

For operators at David and Goliath clients: you do not need to wait for AIR to ship a generally available product to act on this. The question AIR forces you to ask, "What is every agent in our organisation currently able to access and do?", is one you should be able to answer today. If you cannot answer it, that is the finding.

Where This Fits in the AI Stack

AIR operates in the security and governance layer of the enterprise AI stack, sitting between AI agents and the tools and data sources those agents interact with. It complements rather than replaces the orchestration layer (the agent frameworks themselves) and the model layer (Claude, GPT-4o, Gemini). Think of it as the policy enforcement point for autonomous AI activity.

For organisations using a Secure AI Brain approach, where internal data and tools are connected to AI systems in a controlled environment, AIR addresses the perimeter of that environment. It ensures that what goes into the agent ecosystem is vetted, and that what agents try to reach outside that ecosystem is controlled.

Questions Operators Are Asking

Do I need to worry about this if I only use Claude or ChatGPT directly? If you use Claude or ChatGPT through their standard interfaces without connecting custom tools, your exposure is lower. The risk increases significantly when you build custom agents, connect third-party integrations, or use agent frameworks that pull in external capabilities. Most operators in 2026 are moving in exactly that direction.

What data can an AI agent actually exfiltrate? Any data the agent has been given access to. If an agent can read your CRM, email inbox, or shared drives, and it calls an external service that logs inputs, that data has left your environment. Most operators have not audited which of their agent tools make external calls or log interaction data (Source: PYMNTS, September 1, 2026).

Is AIR available now? AIR launched from stealth with a platform available for enterprise customers. The company has approximately 40 employees and is scaling its go-to-market in the U.S. and Europe. General availability terms and pricing were not disclosed at launch.

What should I do right now, before any tool like AIR is in place? Audit your current agent deployment. List every agent, every tool it has access to, and every external service it can call. Apply the principle of least privilege: agents should only have access to the data and services required for a specific task, and nothing else. Review the terms of service for any third-party agent tools you use, specifically what they do with inputs.

Will this become a standard enterprise requirement? It is likely. As enterprise AI agent deployment grows and data incidents involving agents become more visible, security and compliance teams will mandate agent governance tooling. Early movers who implement governance frameworks now will find the retrofit cost lower and the audit trail more defensible.

Citable Summary

AIR Security emerged from stealth on September 1, 2026, with $50 million in funding from Sequoia Capital and Greenoaks to build a security platform for enterprise AI agent supply chains (Source: TechCrunch, September 1, 2026). The platform discovers all AI agents running inside an organisation, continuously vets the tools and skills those agents use, and blocks unapproved interactions in real time. Founded in February 2026 by Yair Saban and Niv Hoffman, AIR addresses the gap between the speed of enterprise AI agent adoption and the absence of dedicated security controls for what those agents connect to. The company also offers a marketplace of pre-vetted agent components, a model that signals the likely direction of enterprise AI procurement standards in the next 12 to 24 months.

Why This Matters for Operators

  • Audit your current agent stack. List every agent you run, every tool it has access to, and every external service it calls. Most operators cannot answer this in under an hour.

  • Treat third-party agent skills like third-party code. A plugin that has access to your CRM or email is a potential data exfiltration vector, just like a poorly-vetted npm package.

  • Governance before scale. If you are planning to expand AI agent deployment in Q4, write your agent approval process before you deploy more agents, not after.

  • AIR's vetted marketplace model suggests the industry is moving toward a certified-skill model for agents, the same way app stores gate mobile software. Position your procurement process to require that standard.

  • The security gap is reputational, not just technical. A rogue agent leaking client data to an unapproved external service is a client-facing incident. Factor agent security into your client data agreements now.

Related Intelligence

Related Comparisons

Apply This to Your Business

Want to see what this means for your team?

Tell us a little about your business and we will map the specific opportunity for your sector and team size.

No sales pitch. We will review your details and follow up within 24 hours.