AIR has come out of stealth with $50 million in seed funding to build a firewall for AI agents. The round came in two parts closed within weeks of each other, a $10 million round led by Sequoia Capital, then a $40 million round led by Greenoaks. The company announced the funding and its public launch on September 1, 2026.
AIR secures the software supply chain forming around AI agents. As agents take on more work, they install skills, plug-ins, and Model Context Protocol servers to connect to systems and the internet. Most of those add-ons are never reviewed by a security team. AIR sits between a company’s agents and those tools, checking each one before it is allowed to act. It fits the wider wave of AI security funding we have been tracking, including the security funding surge and companies like Zenity and Alice.
The round at a glance
| Detail | Info |
|---|---|
| Amount | $50 million, two seed rounds |
| Structure | $10M led by Sequoia, then $40M led by Greenoaks |
| Date | September 1, 2026 (out of stealth) |
| Founded | February 2026 |
| Founders | Yair Saban (CEO), Niv Hoffman (CTO) |
| Product | An inline firewall for AI agents |
The round drew a notable list of angels alongside the lead funds. They include Zach Frankel, president of Cognition, Wiz co-founder Yinon Costica, Clay co-founder Varun Anand, Eon co-founder Ofir Ehrlich, and Anne Neuberger, plus Swish Ventures and Netz. At $50 million, it ranks among the largest security seed rounds of the past four years.
What AIR does
AIR builds what it calls an inline firewall for agents. It continuously discovers every AI agent running inside a company, then evaluates each skill, plug-in, MCP server, and add-on those agents use, both before and after deployment. If a tool carries hidden instructions, asks for too many permissions, or looks like a supply chain risk, AIR blocks it. The company also runs a marketplace of vetted add-ons.
The pitch rests on a simple analogy. An operating system will not load a driver into its core without a signature. AI agents, the founders argue, should not run third-party skills without the same kind of check. As one co-founder put it, if agents are the new operating system, their add-ons are the new applications, and they need a new kind of firewall.
The problem AIR found
AIR’s own research shows why this matters. The company says it found more than 17,800 public AI add-ons, representing 6.7 million installations, that rely on untrusted external instruction sources. It also found AI skills in the wild impersonating companies like Anthropic and OpenAI, built to slip past security reviews and run arbitrary code.
That is a real attack surface hiding in plain sight. Every unreviewed skill an agent installs is a door into a company’s systems, and most organizations have no idea what their agents are running.
Why it matters
This is a new front in the AI security boom. Companies like Zenity govern what agents do, and Alice tests the models underneath. AIR targets a different layer, the tools and add-ons agents pull in to get work done. As the MCP ecosystem grows, that layer expands fast, and it has had almost no security around it.
The team
AIR was founded in February 2026, making it about six months old at launch. Its founders, CEO Yair Saban and CTO Niv Hoffman, are veterans of Israel’s Unit 8200 intelligence corps, where they worked on offensive cybersecurity. They are joined by Ryan Knisley, a former chief information security officer at The Walt Disney Company and Costco, as chief strategy officer.
What is next
AIR plans to use the funding to build out its platform and grow its team as it defines the agent supply chain security category. The bet is that vetting agent tools becomes a standard control for every company running agents at scale, much like antivirus and firewalls became standard for earlier waves of software.
Frequently asked questions
AIR builds a firewall for AI agents. It discovers the agents running inside a company and vets every skill, plug-in, MCP server, and add-on they use, blocking anything that carries hidden instructions, excessive permissions, or supply chain risk.
AIR raised $50 million in seed funding across two rounds, a $10 million round led by Sequoia Capital and a $40 million round led by Greenoaks, announced on September 1, 2026.
Sequoia Capital and Greenoaks led the funding, with angels including Cognition president Zach Frankel, Wiz co-founder Yinon Costica, Clay co-founder Varun Anand, and Anne Neuberger.
An AI agent firewall sits between a company’s agents and the third-party tools they use, checking each skill, plug-in, and MCP server for risk before allowing it to run, much like a network firewall controls traffic.
Agents install skills and add-ons from sources no one has reviewed. AIR found more than 17,800 public add-ons relying on untrusted instructions, and some impersonating major AI companies, which makes each unvetted tool a potential way into a company’s systems.
