AIR, a security startup founded by two veterans of Israel's 8200 intelligence unit, has raised $50 million across two seed rounds closed within weeks of each other. The product is narrower than the usual agent-security pitch: it watches what AI agents inside a company install. Skills, plugins, MCP servers and the software agents pull in get checked against an allowlist AIR maintains by continuously scanning what is published on the open internet, and anything that fails the check is blocked. About 27% of the extensions and skills AIR finds online are currently filtered out.
The rounds were structured oddly. The first was $10 million led by Sequoia; the second, weeks later, was $40 million from Greenoaks. Swish, Netz, Zach Frankel, president of Cognition, Yinon Costica, co-founder of Wiz, Ofir Ehrlich, co-founder of Eon, Anne Neuberger, Omer Adam, Varun Anand, co-founder of Clay, and other private investors also took part. Yair Saban is chief executive and Niv Hoffman chief technology officer; both worked in offensive cybersecurity before founding the company.
Saban's framing is a driver analogy. In the early 2000s, installing a driver usually did not require a digital signature. Now the operating system tells you who signed it, because the driver loads code into the kernel. For skills, plugins and MCP servers, he argues, no equivalent mechanism exists yet, even though the principle is identical. AIR's internal thesis is that agent deployments inside companies increasingly resemble operating systems, while the software those agents install and run receives nothing like the scrutiny an OS applies.
The threat model is not agent hijacking. As agents start working on their own against databases, internal systems and the open web, an attacker does not need to break the agent at all. Poisoning the content the agent retrieves and acts on is enough.
The platform has three parts. A discovery layer finds active agents across a corporate environment. A second layer identifies employees using AI tools the IT department never approved, or running on personal accounts. A control loop sits between agents and their actions and intercepts them — a skill being loaded, data being fetched from the internet. What the agent wants is then matched against AIR's list of permitted components.
That list is the actual asset. AIR builds it by continuously inspecting publicly available skills and extensions for changes and for malicious behavior, on the theory that approval does not hold: a skill cleared last month becomes dangerous the moment the package it downloads changes or the developer's account is compromised. AIR says it has more than 20 customers and roughly 40 employees, and will spend most of the new money on hiring researchers and on sales in the US and Europe.
The category is already occupied. Noma Security offers discovery, access control and monitoring across agents, MCP servers and skills. Zenity sells security and governance tooling with a similar shape. Astrix Security uses its identity platform to find and control agents and MCP servers. Operant AI sells agent protection and an MCP gateway. Capital has followed: Zenity raised $125 million in a Series C in August, and Noma took $100 million in a Series B last year.
Saban's answer to all of that is that agent discovery and chokepoint control will become table stakes for every vendor, and that the hard part is continuously verifying the skills and extension registries themselves. Sequoia's Bogomil Balkansky puts it as an infrastructure problem before a security one: every skill, plugin, MCP server and sub-agent that a corporate agent touches has to be re-checked after every change, in real time, for every agent in the company. AIR spent a year building that pipeline, and a better scanner, he argues, does not let a competitor reproduce it quickly.
Here is where I would push back. The 27% figure is the only performance number in the announcement, and it measures the supply, not the product. It says what share of publicly available skills AIR declines to approve — not how many attacks it stopped, not how many shadow agents it found running where they should not have been. The screen bundles two very different findings, a skill that merely changed and a skill that is hostile, into one rejection rate. As stated, 27% is a claim about the hygiene of the open skill ecosystem, not about AIR's precision, and those are the numbers that matter to a buyer weighing false positives.
The moat claim deserves the same scrutiny. A year of data-pipeline work is real, but it is a lead measured in engineer-months, and $125 million buys engineer-months. Saban's own concession points the same direction: he expects the labs and agent vendors to ship their own policy checks against malicious skills, and rests his case on customers wanting something independent that spans vendors. That is a reasonable bet, and it is also the argument every cross-vendor security company makes right up until the platform's built-in control becomes good enough for the median buyer. Fifty million dollars against 20-plus customers is money running well ahead of traction, which is what the funding pace in this category now produces.
Notably absent from the announcement is anything about the other side of a blocklist. Nothing says how a developer whose skill was filtered gets re-examined, how quickly a legitimate update clears, or what a security team does when the allowlist rejects a tool the business already depends on. A control loop that intercepts skill loads is a safety mechanism and a throttle on internal velocity at the same time, and a 27% rejection rate pointed at the tools employees actually want is also a support queue.
Which is the real stake in this round. Whoever decides which skills an agent may load holds more authority over what employees can build with AI than the agent vendor does. AIR is asking its customers to hand that position to a 40-person startup now, before the vendors claim it — and by Saban's own account, the vendors are coming for it.