AIR has emerged from stealth with a security platform designed for a layer enterprises are only beginning to manage systematically: the tools, instructions and external context consumed by autonomous AI agents. The company says it has raised $50 million across two seed rounds led by Sequoia and Greenoaks, while independent TechCrunch reporting confirms the funding structure and describes a product already used by more than 20 customers.
The product is broader than a conventional malware scanner. AIR says its platform discovers agents running across an organization, evaluates the skills, plugins, MCP servers and sub-agents they depend on, filters untrusted context before it reaches an agent, and monitors agent actions at runtime. It also maintains a marketplace of vetted add-ons. That puts the product at the intersection of software-supply-chain security, prompt-injection defense and agent governance.
Why this matters is the update cycle. A skill or MCP server that looked safe when first approved can later fetch different instructions, change ownership or depend on a compromised external resource. TechCrunch quotes AIR arguing that the hard problem is therefore continuous re-verification, not merely performing a better install-time scan. That distinction is useful for buyers comparing agent-security products: discovery and static approval are not equivalent to checking what an agent is actually allowed to ingest and execute over time.
AIR is entering a market that already includes Noma Security, Zenity, Astrix and Operant AI, so the launch is not proof that its approach is uniquely effective. Its own research claims about vulnerable agent add-ons should also remain vendor claims until independently reproduced. The stronger current evidence is narrower: the company exists, the platform surface is live, TechCrunch independently confirms the funding and product positioning, and AIR is targeting a concrete governance problem created by increasingly autonomous agents.
For enterprises, the practical takeaway is that AI-agent security is becoming a separate control plane rather than an extension of model safety alone. Models can behave as intended and still be steered by compromised tools or untrusted context. AIR’s launch is another sign that organizations will need inventory, least-privilege policies, provenance and revocation controls around the agent ecosystem itself—not just around the underlying model.