AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million
AI Security startup AIR Security raises $50 million for its AI agent firewall.
Summary
AIR Security has emerged from stealth, securing $50 million in funding to develop its AI agent firewall. The company's research revealed over 17,800 public AI add-ons with potential security risks, including those impersonating major companies to bypass reviews and execute malicious code. AIR's firewall aims to protect AI agents by evaluating their skills, plugins, and servers for malicious instructions, excessive permissions, and supply chain vulnerabilities.
Full text
If AI agents are the new operating system, then AI add-ons are the new applications; and a new type of AI firewall is required to maintain security. AIR Security is emerging from stealth with $50 million funding and a firewall, also called AIR, built for AI agents. The funding is led by Sequoia Capital and Greenoaks together with a range of prominent individual industry angels. This follows AIR Security’s research that found more than 17,800 public AI add-ons (representing 6.7M installations) relying on untrusted external instruction sources. The firm also discovered AI Skills in the wild impersonating companies like Anthropic and OpenAI and designed to bypass security reviews and execute arbitrary code. AI agents are increasingly connecting to more tools, data and third-party services; browsing websites, accessing files and emails and acting on behalf of employees. Their growing autonomy is problematic when influenced and directed by adversaries through poisoned content or direct compromise. This opens a path to data theft, fraud, or unauthorized access while providing little visibility to the security team. AIR describes AI agents as the new operating system, with AI add-ons the new applications. “We’re entering a new era where using AI agents will become as elementary to knowledge work as reading, writing, and using Excel. Agents will become a fundamental part of how enterprises build, operate, and make decisions – unlocking entirely new levels of speed, productivity, and what’s possible,” says AIR. Of particular concern is the new and increasing output from coding agents: Claude Code, Cursor, Codex, and everything around them. Enterprises have started adopting these tools at an unprecedented pace. But they’re also afraid to deploy them without a seatbelt – and rightfully so, suggests AIR.Advertisement. Scroll to continue reading. “Every enterprise has a firewall protecting its network. Now they need one protecting their AI agents. AI agents need a new kind of firewall – one that protects what enters their context,” says Yair Saban, co-founder and CEO of AIR. “Today, agents are autonomously installing tools, connecting to internal systems, and making decisions – and in most organizations, nobody knows what’s running, what’s trusted, or how to shut it off.” Saban (CEO) partnered with Niv Hoffman (CTO) to found AIR in order to provide such an AI-specific firewall. They were joined by Ryan Knisley, former CISO at The Walt Disney Company and Costco Wholesale, as chief strategy officer. The firewall discovers and evaluates every skill, plugin, MCP server, and add-on across an organization’s AI agent supply chain, both before and after deployment. Before any third-party or internal add-on is allowed to touch an enterprise agent, AIR performs deep analysis across known agentic attack patterns. It screens for external instruction sources, hidden behaviors, and typo-squatted packages masquerading as official developer tools. If an add-on is malicious, vulnerable or not approved, security teams can trace every agent and workflow that depends on it — and revoke it across the organization. This process is continuous. If a maintainer pushes a malicious update or an existing integration is compromised later, trust is automatically revoked. “Like a black box, AI Add-ons reveal less than they hide. Some stay the same. Some evolve. Others hide external instructions, excessive actions, sensitive data access, or vulnerable supply chains,” says AIR. Through its continuous evaluation of agentic activity across many customers, AIR also offers a marketplace of pre-vetted, certified add-ons, providing a safe route to expand agent capabilities without introducing unmanaged risk, for all its customers. Related: OpenLeash Adds a Human Check to Risky AI Agent Actions Related: UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge Related: Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection Related: Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend Sevii Targets AI-Speed Attacks With Preemptive Autonomous DefenseThink You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco SaysCISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-SuiteIran-Linked Hackers Shut Down UK Power Plant for Four DaysEncrypted Prompts Bypass AI Safety Guardrails in Grok and GeminiNew Phishing Toolkit Uses Passkeys to Maintain Access After Password ResetsSurveillance – Everything You Wanted to Know, But Were Afraid to AskCISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW Latest News 153 Million Driver License Images Offered on Dark WebOver 3 Million WordPress Sites Affected by Migration Plugin VulnerabilityCisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch VulnerabilitiesOpenLeash Adds a Human Check to Risky AI Agent ActionsUK Moves to Block High-Risk Tech Suppliers From Critical InfrastructureRockwell Automation Patches Over a Dozen Vulnerabilities Across ProductsExploit Published for Fresh Cleo Harmony VulnerabilityAnthropic Details Response to Security Incidents, Unveils Enterprise Safeguards Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveTom Bonos has been named Chief Revenue Officer at Sumo Logic.Axonius has appointed Chris Jones as CTSO and Dan Schoenbaum as SVP of Business Development.Optiv has appointed Sean Forkan as Chief Revenue Officer (CRO).More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- malware — AI Skills impersonating companies