Every enterprise has a firewall protecting its network. As of September 1, 2026, the argument is that every enterprise deploying AI agents also needs one protecting what those agents read, install and act on.
AIR Security emerged from stealth on September 1 with $50 million in seed funding to build exactly that: an inline firewall for AI agents that sits between your agent fleet and the expanding ecosystem of third-party skills, plugins and Model Context Protocol (MCP) servers those agents want to use. Sequoia Capital and Greenoaks led the rounds. The company is six months old.
What Happened
AIR Security, founded in February 2026 by CEO Yair Saban and CTO Niv Hoffman, announced a two-round seed raise totaling $50 million alongside its public launch. The first round of $10 million was led by Sequoia Capital; the second of $40 million was led by Greenoaks Capital Partners and closed within weeks, according to TechCrunch. Both Saban and Hoffman are veterans of Unit 8200, the Israeli military intelligence corps known for producing security founders including the team behind Wiz.
Ryan Knisley joined as chief strategy officer. He previously served as CISO at both The Walt Disney Company and Costco Wholesale, which are two of the most demanding enterprise security environments in the world.
Angel investors include Yinon Costica (co-founder of Wiz), Varun Anand (co-founder of Clay), Ofir Ehrlich (co-founder of Eon), Zach Frankel (president of Cognition), and Anne Neuberger, the former White House deputy national security adviser for cyber and emerging technology.
The Funding at a Glance
| Round | Amount | Lead Investor |
|---|---|---|
| Seed 1 | $10M | Sequoia Capital |
| Seed 2 | $40M | Greenoaks Capital Partners |
| Total | $50M |
The two rounds closing within weeks of each other, at 4x the check size on the follow-on, signals fast internal conviction from two top-tier firms rather than a drawn-out diligence process.
The Product: An Inline Firewall for Agent Context
The core insight behind AIR is a distinction that most enterprise security teams have not yet internalized: permissions tell you what an agent can reach; the information entering its context determines what it actually does.
Traditional endpoint security controls what software can run. AIR controls what content, tools and instructions reach the agent’s reasoning process before the agent acts. SecurityWeek described the architecture as a firewall that “discovers and evaluates every skill, plugin, MCP server, and add-on across an organization’s AI agent supply chain, both before and after deployment.”
The platform works in three layers:
- Discovery. AIR maps every agent running across endpoints, cloud accounts and SaaS applications, including agents employees spin up using personal accounts outside IT’s view.
- Pre-runtime vetting. Before any third-party add-on reaches an agent, AIR performs static analysis, dependency analysis, sandbox analysis and ongoing credibility analysis. A skill that looks clean at installation can later become dangerous if its developer account is compromised or a package it depends on changes.
- Enforcement. At runtime, AIR intercepts actions, like loading a skill or fetching content from the internet, and blocks anything that fails its trust criteria. Security teams can trace every agent and workflow depending on a flagged add-on and revoke it across the organization instantly.
AIR also runs a marketplace of pre-vetted, certified add-ons, giving enterprises a safe path to expand agent capabilities without introducing components no one has audited.
What the Research Found
Before launching, AIR ran a series of studies to quantify the problem it is selling against.
In one study, AIR scanned 142,836 live AI skills gathered from a public marketplace and GitHub. Its researchers classified 17,822, or 12.4%, as dependent on at least one untrusted external resource. Those skills collectively represented approximately 6.7 million installations, according to AIR. The methodology used signals including young domains, lightly used GitHub accounts, look-alike brands and abandoned hosting.
In a second study, AIR found AI Skills in the wild that impersonated trusted brands including Anthropic and OpenAI, designed to bypass platform security reviews and execute arbitrary code. In a controlled experiment, the team created a skill that passed available security scanners, reached more than 26,000 agents, and could have accessed conversations and connected systems.
The company says its scanner currently filters out roughly 27% of the add-ons and skills it finds online.
Saban framed the governance gap using a software driver analogy: “In the early 2000s, whenever you installed a driver, the driver didn’t need to be signed. Today, every time you install a driver, you see a signature saying who signed it, because the driver is actually loading code into the kernel. You don’t have that with skills or plug-ins or MCPs, and it’s a shame, because it’s the same mechanism, it’s the same lesson, but we haven’t learned it.”
Why the Timing Is Right
Enterprise adoption of coding agents (Claude Code, Cursor, OpenAI’s Codex) has accelerated sharply in 2026. As those agents gain access to internal systems, databases and external tools, the attack surface they present has grown faster than most security teams’ ability to monitor it.
Sequoia’s Bogomil Balkansky put it directly: “Inspecting every skill, plugin, MCP server and sub-agent an enterprise’s agents touch, re-inspecting each one every time it changes, in real time and across an entire company’s agent fleet, is an infrastructure problem long before it is a security problem.”
Greenoaks partner Patrick Backhouse added that agents operate at runtime “using skills, plugins, add-ons, and MCPs from sources that no security team has reviewed, and slipping past scanners built for yesterday’s code.”
AIR currently has more than 20 customers, with roughly a quarter of them large enterprises. Demand has been concentrated in financial services and pharmaceuticals, both sectors where a single unauthorized agent action against customer records or clinical data carries regulatory consequences far beyond the cost of a breach.
The AI security market generates under $100 million in combined annual revenue today, according to Menlo Times. AIR projects the market could exceed $1 billion by the end of 2027.
The Competitive Landscape
AIR is not alone in the AI agent security category.
| Vendor | Focus | Notable Funding |
|---|---|---|
| AIR Security | Pre-runtime add-on vetting, inline firewall | $50M seed (Sequoia, Greenoaks) |
| Zenity | Governance, identity, runtime monitoring | $125M Series C (Aug 2026) |
| Obsidian Security | Non-human identity, runtime governance | $85M Series D (Aug 2026) |
| Noma Security | Discovery, access controls, MCP monitoring | $100M Series B (2025) |
| Astrix Security | Agent and MCP server identity | Undisclosed |
Saban’s positioning argument is that AIR’s moat lies in the continuous re-verification data pipeline, not the discovery layer that everyone will eventually ship. “Continuously vetting skills and plug-in websites, this is a hard mission to do,” he told TechCrunch. “Gaining visibility over the endpoint, that is easy. Everybody’s going to do it. It’s hard to create a moat around that.”
What This Means for Enterprise AI Teams
The AIR Security launch adds a new governance category to the enterprise AI stack. If you are deploying AI agents at scale, the security perimeter now extends to every third-party component those agents can pull in, every website they can browse and every instruction that enters their context.
The practical checklist for enterprise AI and GTM teams:
- Inventory your agents. Most organizations do not have a complete picture of which agents are running, across which systems, using which add-ons. Start there.
- Treat the AI add-on ecosystem like open-source dependencies. You would not deploy production software without checking its dependencies. The same logic applies to agent skills and MCP servers.
- Require continuous verification, not one-time approval. A vetted skill today can be compromised tomorrow. Static review is not enough when the add-on ecosystem is updating continuously.
- Separate agent identity from human identity. Agents running under employee credentials create audit and liability problems. Agent-specific identity and permissioning is the foundation for everything else.
For teams building on top of agents rather than just using them, the implications extend to the tools you ship to customers. If your product uses skills or MCP connections, your customers’ security teams will start asking the same questions AIR is helping answer.
For a broader look at how enterprise AI governance is evolving alongside agent deployment, see our analysis of the Snowflake Cortex AI Gateway and the Databricks Unity AI Gateway, two control-plane approaches to the same enterprise problem from the data platform layer.
If your organization is evaluating how to govern AI agents safely at scale, book a call with the Enera team to discuss what a governance-first deployment architecture looks like in practice.