AIR Security — $50M seed for an inline “firewall” vetting the AI-agent supply chain (September 2026)
Tag: S-2026-09-01-air-security-seed-agent-supply-chain Type: article (TechCrunch report based on a founder interview; fetched in full) Author(s): Ram Iyer, TechCrunch Date of source: 2026-09-01 Date ingested: 2026-09-10 Authority weight: medium — funding facts corroborated across outlets; all capability, filter-rate, customer and demand claims are the company’s, relayed by a journalist without independent testing Raw file: /_raw_sources/S-2026-09-01-air-security-seed-agent-supply-chain.md
What it claims
AIR (founded by Yair Saban and Niv Hoffman, ex-Unit 8200; ~40 staff) emerged from stealth on 1 September 2026 with $50M across two seed rounds — $10M led by Sequoia, then $40M led by Greenoaks — to build a product for the “nascent software supply chain” forming around AI agents: skills, plug-ins, MCP servers and add-ons. The platform (a) discovers agents running in a company and employees using unapproved AI tools or personal accounts, (b) runs an enforcement layer that hooks into agents to intercept actions such as loading a skill or fetching internet content, and (c) checks the components an agent wants to use against a whitelist AIR maintains, re-verifying them when a downloaded package changes or a developer account is compromised. It also offers a marketplace of vetted add-ons.
Saban’s analogy is driver signing: skills/plug-ins/MCPs load code into the “kernel” of the agent yet are unsigned. AIR says it currently filters out about 27% of add-ons and skills it finds online, has 20+ customers (about a quarter large enterprises), and sees the strongest demand in financial services and pharma. The article names Noma Security, Zenity, Astrix Security and Operant AI as competitors and notes Zenity’s $125M Series C (Aug) and Noma’s $100M Series B. Sequoia’s Bogomil Balkansky frames the problem as “continuous re-verification”, an infrastructure rather than a scanning problem. Capital goes to research hiring and US/Europe go-to-market. Saban concedes AI labs will eventually build in such checks but argues buyers will want a cross-vendor independent product.
Notable quotes
- “You don’t have that with skills or plug-ins or MCPs, and it’s a shame, because it’s the same mechanism, it’s the same lesson, but we haven’t learned it.” — Yair Saban
- “This is not a scanning problem, it is a continuous re-verification problem.” — Bogomil Balkansky, Sequoia
- “the company has so far seen the strongest demand in heavily regulated industries, particularly financial services and pharmaceutical companies.” (para 10)
What’s speculative vs. asserted
Asserted (corroborated): the $10M + $40M rounds and leads; founders; headcount; competitor set (journalist’s).
Company-asserted, unverified: discovery/enforcement/whitelist capability; the 27% filter rate; 20+ customers; FS/pharma demand; that the whitelist is continuously re-verified.
Not stated: any customer name; any regulatory standard; evidence retention/exportability; how the vendor-maintained whitelist is itself governed or audited.
Vault inference: relevance to DORA ICT third-party registers, EU AI Act Art. 15 robustness/cybersecurity, and SS1/23-style change control for agent components.
Topics this feeds
- AI Governance Platforms — the agent-component supply-chain gap Zenity documented at Black Hat now has a venture-scale dedicated entrant; reinforces the security-side capitalisation and “continuous re-verification” framing.
Open questions raised
- Who audits the vetter — is AIR’s whitelist methodology disclosed, and can a second line rely on it?
- Do skills/MCP servers loaded by agents appear anywhere in a DORA register of information today, and whose control is that?
- Are the FS customers EU/UK regulated entities, and is the product deployed inline in production or in assessment mode?