As AI agents gain increased access to corporate systems and the internet, a new software supply chain is emerging, consisting of the skills, plugins, MCP servers and other tools these agents use. AIR, a cybersecurity startup founded by Yair Saban and Niv Hoffman, who served in Israel’s Unit 8200 intelligence unit, has emerged from stealth to oversee this ecosystem and raised a total of $50 million in two seed funding rounds. The first round, worth $10 million, was led by Sequoia, while the second, worth $40 million, was led by Greenoaks. Swish, Netz, Zach Frankel, Yinon Costica, Ofir Ehrlich, Anne Neuberger, Omer Adam, Varun Anand and other angel investors also participated in the rounds.
AIR’s platform discovers agents within a company and continuously monitors the skills, tools and components they use; it blocks interactions with software or external resources that do not meet security criteria. The system also determines whether employees are using AI tools or personal accounts that have not been approved by information technology departments. It includes an enforcement layer that analyzes agents’ activities, such as loading plugins or fetching content from the internet. The company compares the tools and software that agents want to use against its own allowlist; it reassesses skills and plugins found online for changes and malicious behavior. AIR says it filters approximately 27% of the plugins and skills it finds online.
According to Saban, agents operating more autonomously in databases and enterprise systems could allow attackers to poison the content they consume instead of targeting the agent directly. AIR has more than 20 customers, approximately one quarter of which are large enterprises. The strongest demand is coming from highly regulated industries, particularly financial services and pharmaceutical companies.
Noma Security, Zenity, Astrix Security and Operant AI also offer similar products in the market. Zenity raised a $125 million Series C in August, while Noma raised a $100 million Series B last year. Saban argues that AIR differentiates itself through its ability to continuously revalidate. The company has approximately 40 employees; the new capital will be used to hire researchers and expand into markets in the US and Europe.
Why it matters
As AI agents act more independently within organizations, security boundaries extend beyond the model itself to the plugins, skills and external resources they use. This makes the issue directly relevant, particularly in regulated industries such as financial services and pharmaceutical companies, to how employees’ use of unauthorized tools and the content agents retrieve from the internet will be monitored. AIR’s disclosure that it filters approximately 27% of components found online indicates that security assessments in this ecosystem need to be conducted continuously. However, the extent to which the company’s approach differs from those of its competitors and how the blocks imposed will affect organizations’ day-to-day workflows remain open questions. As agents’ access permissions increase, this area is creating a new supply chain oversight issue for companies.
Term: agent
An AI agent is software that calls tools and carries out multi-step tasks to achieve a goal, rather than producing a single response.