SecurityWeek

AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million


If AI agents are the new operating system, then AI add-ons are the new applications; and a new type of AI firewall is required to maintain security.

AIR Security is emerging from stealth with $50 million funding and a firewall, also called AIR, built for AI agents. The funding is led by Sequoia Capital and Greenoaks together with a range of prominent individual industry angels.

This follows AIR Security’s research that found more than 17,800 public AI add-ons (representing 6.7M installations) relying on untrusted external instruction sources. The firm also discovered AI Skills in the wild impersonating companies like Anthropic and OpenAI and designed to bypass security reviews and execute arbitrary code.

AI agents are increasingly connecting to more tools, data and third-party services; browsing websites, accessing files and emails and acting on behalf of employees. Their growing autonomy is problematic when influenced and directed by adversaries through poisoned content or direct compromise. This opens a path to data theft, fraud, or unauthorized access while providing little visibility to the security team. 

AIR describes AI agents as the new operating system, with AI add-ons the new applications. “We’re entering a new era where using AI agents will become as elementary to knowledge work as reading, writing, and using Excel. Agents will become a fundamental part of how enterprises build, operate, and make decisions – unlocking entirely new levels of speed, productivity, and what’s possible,” says AIR.

Of particular concern is the new and increasing output from coding agents: Claude Code, Cursor, Codex, and everything around them. Enterprises have started adopting these tools at an unprecedented pace. But they’re also afraid to deploy them without a seatbelt – and rightfully so, suggests AIR.

Advertisement. Scroll to continue reading.

“Every enterprise has a firewall protecting its network. Now they need one protecting their AI agents. AI agents need a new kind of firewall – one that protects what enters their context,” says Yair Saban, co-founder and CEO of AIR. “Today, agents are autonomously installing tools, connecting to internal systems, and making decisions – and in most organizations, nobody knows what’s running, what’s trusted, or how to shut it off.”

Saban (CEO) partnered with Niv Hoffman (CTO) to found AIR in order to provide such an AI-specific firewall. They were joined by Ryan Knisley, former CISO at The Walt Disney Company and Costco Wholesale, as chief strategy officer.

The firewall discovers and evaluates every skill, plugin, MCP server, and add-on across an organization’s AI agent supply chain, both before and after deployment. Before any third-party or internal add-on is allowed to touch an enterprise agent, AIR performs deep analysis across known agentic attack patterns. It screens for external instruction sources, hidden behaviors, and typo-squatted packages masquerading as official developer tools.

If an add-on is malicious, vulnerable or not approved, security teams can trace every agent and workflow that depends on it — and revoke it across the organization. This process is continuous. If a maintainer pushes a malicious update or an existing integration is compromised later, trust is automatically revoked.

“Like a black box, AI Add-ons reveal less than they hide. Some stay the same. Some evolve. Others hide external instructions, excessive actions, sensitive data access, or vulnerable supply chains,” says AIR.

Through its continuous evaluation of agentic activity across many customers, AIR also offers a marketplace of pre-vetted, certified add-ons, providing a safe route to expand agent capabilities without introducing unmanaged risk, for all its customers.

Related: OpenLeash Adds a Human Check to Risky AI Agent Actions

Related: UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge

Related: Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection

Related: Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed



Source link