AIR Security raises $50M, launches AI-agent firewall

AIR Security emerged from stealth with $50M led by Sequoia and Greenoaks and released AIR, a firewall that inspects and controls AI agents and their add-ons.

AIR Security announced it has emerged from stealth with $50 million in funding led by Sequoia Capital and Greenoaks and launched AIR, a firewall designed to inspect and control AI agents and their add-ons across enterprises.

The startup was co-founded by Yair Saban, chief executive, and Niv Hoffman, chief technology officer. Ryan Knisley joined as chief strategy officer. The AIR firewall discovers and evaluates every skill, plugin, MCP server and add-on that connects to an organization’s AI agents, both before and after those integrations are deployed.

The system performs deep analysis of known agent attack patterns, screens for external instruction sources, looks for hidden behaviors and identifies packages that impersonate legitimate developer tools. It can trace and revoke risky components across the enterprise.

AIR’s research identified more than 17,800 public AI add-ons representing roughly 6.7 million installations that rely on untrusted external instruction sources. The company also reported instances of add-ons impersonating services such as Anthropic and OpenAI and designed to bypass review processes and execute arbitrary code.

AI agents increasingly connect to tools, internal systems and third-party services; they can browse websites, access files and emails and act autonomously on behalf of users. The company highlighted rapid adoption of coding agents such as Claude Code, Cursor and Codex and noted enterprises lack visibility into what agents install and run.

Yair Saban, co-founder and CEO, described the protection AIR aims to provide: “Every enterprise has a firewall protecting its network. Now they need one protecting their AI agents. AI agents need a new kind of firewall — one that protects what enters their context.”

AIR’s controls are designed to block add-ons that are malicious, vulnerable or not approved and to show security teams which agents and workflows depend on each integration. The platform continuously re-evaluates add-ons after deployment; if a maintainer issues a malicious update or an integration is compromised, trust can be revoked automatically and dependent agents disconnected.

The company plans to operate a marketplace of pre-vetted, certified add-ons to give customers a curated way to extend agent capabilities without introducing unmanaged third-party risk.

The $50 million funding round was led by Sequoia Capital and Greenoaks and included a group of individual industry angels, according to the company. AIR presents the firewall as a supply-chain security layer for agentic software to provide security teams with clearer visibility and control as AI agents are deployed in enterprise workflows.

Articles by this author