AIR Security Raises $50M to Build Firewall for AI Agents
AIR Security has emerged from stealth with $50 million in funding to launch what it calls the first firewall purpose-built for AI agents. The round was led by Sequoia Capital and Greenoaks, with participation from several prominent industry angels. Founded by CEO Yair Saban and CTO Niv Hoffman, the startup is staffed by former enterprise security leaders including Ryan Knisley, previously CISO at both The Walt Disney Company and Costco Wholesale, who joins as chief strategy officer. The company positions AI agents as the new operating system and AI add-ons as the new applications — a paradigm shift that demands a fundamentally new security layer.
The funding follows research from AIR Security that surfaced alarming statistics about the AI agent supply chain. The firm identified more than 17,800 public AI add-ons representing approximately 6.7 million installations that rely on untrusted external instruction sources. Even more concerning, AIR discovered AI skills in the wild actively impersonating companies like Anthropic and OpenAI, designed to bypass security reviews and execute arbitrary code. As coding agents such as Claude Code, Cursor, and Codex are adopted at unprecedented rates inside enterprises, Saban warns that organizations are "afraid to deploy them without a seatbelt — and rightfully so." Adversaries can exploit this growing autonomy through poisoned content or direct compromise, opening paths to data theft, fraud, and unauthorized access while leaving security teams with limited visibility — a gap that standard network firewalls cannot close. Security teams can audit their own exposure by running a privacy checkup and verifying identity controls with a password checker to reduce credential-related attack surface.
The AIR firewall discovers and evaluates every skill, plugin, MCP server, and add-on across an organization's AI agent supply chain — both before and after deployment. Before any third-party or internal add-on is permitted to interact with an enterprise agent, AIR performs deep analysis across known agentic attack patterns, screening for external instruction sources, hidden behaviors, and typo-squatted packages masquerading as legitimate tools. "Every enterprise has a firewall protecting its network. Now they need one protecting their AI agents," Saban said. "Today, agents are autonomously installing tools, connecting to internal systems, and making decisions — and in most organizations, nobody knows what's running, what's trusted, or how to shut it off."
The startup is betting that as AI agents become as fundamental to knowledge work as reading, writing, and using Excel, enterprises will require dedicated agentic security infrastructure rather than repurposed traditional defenses. With MCP servers, skills, and plugins emerging as a new class of supply-chain dependency, AIR's approach signals a shift toward treating AI agent ecosystems with the same rigor applied to software bills of materials and third-party risk management.