AI agents are no longer a demo. They’re running inside real companies, connecting to real internal tools, and making real decisions with real access. AIR, a security startup that emerged from stealth on September 1, 2026, is betting that vetting exactly what those agents are allowed to touch is about to become its own dedicated security category, and it just raised $50 million to build the infrastructure for it.

Who actually built it

AIR was founded by CEO Yair Saban and Chief Technology Officer Niv Hoffman, both veterans of Unit 8200, the Israeli intelligence corps’ signals-intelligence and cyber unit widely known as a pipeline for Israeli cybersecurity founders. That background is directly relevant to what AIR builds. Unit 8200 alumni have founded a disproportionate share of major Israeli cybersecurity companies over the past two decades, and the pattern shows up again here: a technical, security-first product built by people whose prior training was specifically in identifying and closing exploitable gaps in complex systems, applied now to the newest kind of system with exactly that problem, autonomous AI agents.

What the company actually does

AIR’s platform discovers AI agents already running inside a company’s infrastructure, continuously vets the skills, tools, and third-party components those agents rely on, including plug-ins and MCP servers, and can block an agent from interacting with anything that doesn’t pass its security criteria. It also runs a marketplace of pre-vetted add-ons and skills, giving companies a safer default set of components to build agents from rather than pulling from an unvetted open ecosystem. The specific problem this targets is a genuinely new one: a traditional software supply chain has known, auditable dependencies, while an AI agent’s “supply chain” of tools, skills, and connected services can expand dynamically and unpredictably as the agent operates, often without a human explicitly approving each new connection.

How the funding actually came together

AIR closed its $50 million across two separate seed rounds within weeks of each other rather than a single round, an unusual structure that reflects how fast investor interest in AI-agent infrastructure moved this year. Sequoia Capital led an initial $10 million round, and Greenoaks Capital led a subsequent $40 million round, with participation from enterprise security founders and angel investors. Having two of the more selective venture firms in the industry lead sequential rounds within weeks of each other is a strong signal of how urgently investors currently view the AI-agent security gap, rather than treating it as a speculative future problem.

AIR isn’t securing AI models themselves. It’s securing everything an AI agent is allowed to plug into once it’s already running inside a real company, the newer and less understood half of the problem.

Real, paying customers already

AIR reports more than 20 customers already, with roughly a quarter of them large enterprises. The strongest early demand has come from heavily regulated industries specifically, financial services and pharmaceutical companies, both sectors where a poorly vetted AI agent connecting to the wrong internal system carries genuine regulatory and liability consequences, not just a reputational risk. That customer concentration is a useful signal on its own: the earliest, most motivated buyers for a genuinely new security category tend to be the industries with the most to lose from getting it wrong, and AIR’s traction maps directly onto that pattern.

Why this specific problem is a real, growing category

The AI-agent security gap AIR is targeting is structural, not hypothetical. As more companies deploy agents that can independently call external tools, query internal databases, or take actions on a user’s behalf, the traditional security model of vetting a fixed, known set of software dependencies breaks down. An agent’s actual capabilities can be extended at runtime by whatever tools and skills it’s connected to, which means the attack surface isn’t fixed at deployment time the way a traditional application’s is. That’s a genuinely different problem from either traditional application security or AI model safety, and it’s part of why a dedicated company built specifically around it, rather than a feature bolted onto an existing security product, has drawn this level of early investor and customer interest.

What to watch next

The AI-agent security space is young enough that no single company has established itself as the definitive standard yet, and AIR’s early traction in regulated industries positions it as one of the more closely watched entrants. Whether the category consolidates around a small number of specialized vendors like AIR, gets absorbed into broader existing security platforms, or splits into narrower sub-categories (agent discovery, tool vetting, runtime blocking) as the market matures is still an open question worth tracking over the next year.

Frequently asked questions

Who founded AIR?
Yair Saban (CEO) and Niv Hoffman (CTO), both veterans of Israel’s Unit 8200 intelligence unit.

How much has AIR raised, and from whom?
$50 million total across two seed rounds: $10 million led by Sequoia Capital, followed by $40 million led by Greenoaks Capital.

What problem does AIR actually solve?
It discovers AI agents running inside a company, vets the tools, skills, and third-party components those agents connect to, and can block connections that don’t meet security criteria.

Who is actually using AIR right now?
More than 20 customers as of its September 2026 launch, roughly a quarter of them large enterprises, with the strongest demand from financial services and pharmaceutical companies.

For more on how AI is reshaping enterprise security and infrastructure, see our cybersecurity threats actually worth losing sleep over in 2026. More coverage like this lives in our AI News archive and the broader Tech & AI Evolution desk.