AI security startup AIR has emerged from stealth with $50 million in funding to help companies monitor and secure the growing ecosystem of skills, plugins, and add-ons that AI agents rely on. The company, founded by Israeli intelligence veterans, aims to address a critical gap in enterprise AI adoption: the lack of oversight for the software components that agents use to interact with systems and the internet.
Why the AI agent supply chain needs scrutiny
As companies increasingly deploy AI agents to automate tasks across databases, enterprise software, and web services, these agents are essentially becoming operating systems for business processes. However, the skills, MCP servers, and plugins they depend on are not subject to the same security checks as traditional software drivers or applications. AIR CEO Yair Saban draws a parallel to the early 2000s, when unsigned drivers posed a kernel-level risk; today, similar risks exist with AI agent components, but without equivalent safeguards.
Attackers can poison the content an agent consumes rather than attacking the agent directly, making the supply chain a prime vector for compromise. AIR’s platform provides visibility into which agents are running across a company, continuously vets the skills and tools they use against a whitelist, and blocks interactions with unapproved or malicious components. The company claims it currently filters out about 27% of the add-ons and skills it finds online.
Funding and competitive landscape
The $50 million was raised in two seed rounds, with Sequoia leading a $10 million round and Greenoaks leading a $40 million round. Other investors include Swish, Netz, and prominent angels such as Zach Frankel, Yinon Costica, and Anne Neuberger. AIR says it has more than 20 customers, with strong demand in financial services and pharmaceuticals.
The space is becoming crowded, with competitors like Noma Security, Zenity, Astrix Security, and Operant AI all offering similar agent security capabilities. However, AIR believes its continuous vetting pipeline—rather than a one-time scan—is its moat. Sequoia partner Bogomil Balkansky emphasized that this is an infrastructure problem, not just a security one, and that AIR’s year-long investment in building that pipeline is difficult to replicate.
What this means for enterprises
For enterprises, the rise of AI agents introduces a new class of risk that traditional security tools are not designed to handle. The ability to discover shadow AI usage, vet third-party components, and enforce security policies across an agent fleet will become essential as agent adoption scales. AIR’s approach—combining visibility, enforcement, and a continuously updated whitelist—offers a blueprint for how organizations can maintain control without stifling innovation.
Conclusion
As AI agents become more autonomous and integrated into critical business processes, securing the software supply chain they depend on is no longer optional. AIR’s funding and early traction signal that the market recognizes this need, but the competitive landscape suggests that differentiation will come down to execution and the depth of the vetting pipeline. With $50 million in fresh capital, AIR is positioned to expand its research and go-to-market efforts, but it will need to prove that its approach can scale as the ecosystem evolves.
FAQs
Q1: What is the AI agent software supply chain?
The AI agent software supply chain refers to the skills, plugins, MCP servers, and add-ons that AI agents use to interact with other software and the internet. These components can introduce security risks if not properly vetted, similar to how third-party libraries can introduce vulnerabilities in traditional software.
Q2: How does AIR’s platform work?
AIR’s platform discovers AI agents running across a company’s environment, continuously evaluates the skills and tools they use against a whitelist, and blocks interactions with unapproved or malicious components. It also provides visibility into shadow AI usage by employees.
Q3: Why is continuous vetting important?
A previously approved skill can become risky if its underlying code changes or if a developer’s account is compromised. Continuous vetting ensures that any changes are re-evaluated in real time, reducing the window of exposure to potential attacks.
Disclaimer: The information provided is not trading advice, Bitcoinworld.co.in holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

