News
Israeli Startup AIR Security Raises $50 Million for AI Agent Firewall

Six-month-old startup AIR Security has raised $50 million from Sequoia Capital and Greenoaks for a system that filters plugins and commands reaching enterprise AI agents in real time. The founders say they found fake skills impersonating Anthropic and OpenAI among more than 17,000 public add-ons.
Contents
AIR Security, a company founded just seven months ago, has announced a $50 million raise to build what its founders call a firewall for AI agents. The money will fund a system that scans commands, plugins, and data entering AI agents' context in real time, before they can execute malicious code or leak company data.
What AIR actually does
AIR's product acts as an intermediary layer between an AI agent and the outside world. The platform first detects which agents are even running on a corporate network, since employees often deploy many of them on their own without IT's knowledge. The system then continuously verifies the skills, plugins, and Model Context Protocol servers agents rely on, and blocks any that have changed in suspicious ways or look malicious from the start.
The company's founders, chief executive Yair Saban and chief technology officer Niv Hoffman, met while serving in Unit 8200, the military intelligence unit, where they worked on offensive cybersecurity. Ryan Knisley, formerly head of security at Disney and Costco, has since joined the team as chief strategy officer.
Every enterprise has a firewall protecting its network. Now it needs one that protects its AI agents. - Yair Saban, CEO of AIR Security
Where the threat comes from
The market for ready-made skills and plugins for AI agents grew at a dizzying pace in 2026, with almost no quality control. Companies plug hundreds of add-ons into their agents to automate bookings, financial analysis, or customer service, often without knowing who actually wrote the code behind a given plugin or whether anyone tampered with it after installation.
AIR's team says that while researching publicly available add-ons, it came across fake skills impersonating the Anthropic and OpenAI brands, capable of executing arbitrary code on a victim's machine. That shows how easily an attacker can plant a malicious package where developers look for trusted extensions, banking on the name recognition of a major AI lab.
You don't have this problem with drivers or regular software, because the industry learned how to solve it over decades. With skills, plugins, or MCP, we haven't learned that yet. - Yair Saban, CEO of AIR Security
Funding and industry backing
Besides Sequoia Capital and Greenoaks, the round was backed by Swish Ventures and Netz Capital, with angel investors including Wiz co-founder Yinon Costica, Clay co-founder Varun Anand, Eon co-founder Ofir Ehrlich, Cognition CEO Zach Frankel, and Anne Neuberger, the former U.S. deputy national security advisor for cyber and emerging technology. That roster of investors suggests AI agent security has already reached the top ranks of the tech industry and government.
Sequoia Capital partner Bogomil Balkansky described the challenge facing the market as more than a one-time code scan. In his view, it requires continuous, repeated verification, since agent plugins and skills change on the fly and a one-time security check loses its validity within days or hours.
What it means for businesses and developers
For companies deploying AI agents in Poland and worldwide, this funding round signals that agent security is no longer a niche for enthusiasts but is becoming its own product category alongside traditional firewalls and antivirus systems. A growing number of incidents involving hijacked coding agents and AI assistants shows that the gap between how fast this technology is adopted and how fast it is secured keeps widening.
AIR plans to expand its product with a marketplace of pre-vetted add-ons that companies could use instead of downloading unknown plugins from the open internet. The approach echoes the app stores that brought similar order to the mobile app market years ago, though the scale and pace of change in the world of AI agents are far greater.
The figure of 6.7 million installs of potentially dangerous add-ons alone shows the scale of the problem now facing the entire AI agent industry. For corporate security teams, the question is no longer whether employees are using unauthorized agents and plugins, but how many are actually circulating on the corporate network.
