IT Brief US - Technology news for CIOs & IT decision-makers
United States
AIR launches AI firewall with USD $50 million backing

AIR launches AI firewall with USD $50 million backing

Tue, 8th Sep 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

AIR has emerged from stealth with USD $50 million in funding led by Sequoia Capital and Greenoaks.

The New York-based company is building an inline firewall for AI agents, software that is increasingly being given access to tools, data, websites, files and internal systems inside large organisations.

Its product is designed to protect the context AI agents use to make decisions. AIR argues that malicious content, compromised tools and untrusted data sources can shape an agent's actions in ways security teams cannot easily see or control.

The round also included Swish Ventures, Netz and a group of individual backers from the security and AI sectors. Those named included Zach Frankel, President, Cognition; Yinon Costica, Co-Founder, Wiz; Ofir Erlich, Co-Founder, Eon; Anne Neuberger; Omer Adam; Varun Anand, Co-Founder, Clay; and Moshe Shalev and Dean Leitersdorf, Co-Founders, Decart.

AIR was founded by Yair Saban and Niv Hoffman. The company has also brought in Ryan Knisley, former Chief Information Security Officer at The Walt Disney Company and Costco Wholesale, as Chief Strategy Officer.

Research findings

The launch follows AIR's security research into AI add-ons and so-called AI Skills, the tools and integrations agents can call on while carrying out tasks. One study found that more than 17,800 public AI add-ons, representing 6.7 million installations, relied on untrusted external instruction sources.

In another study, AIR found AI Skills impersonating trusted brands including Anthropic and OpenAI to bypass platform security reviews and execute arbitrary code.

Those findings point to a supply chain issue around AI agents that differs from conventional software security. Unlike static software, agents make runtime decisions based on the information presented to them, creating a wider attack surface if the underlying tools or inputs are tampered with.

AIR said its system continuously discovers and evaluates skills, plugins, MCP servers and add-ons used across an organisation's AI agent estate before and after deployment. When an add-on is identified as malicious, vulnerable or unapproved, security teams can trace which agents and workflows depend on it and revoke it across the organisation.

The company also offers a marketplace of pre-vetted add-ons, intended to give businesses a controlled way to expand the range of tools available to agents without requiring teams to approve each service individually.

AIR's pitch comes as businesses experiment with autonomous agents that can browse the web, access emails, work with files and take actions on behalf of employees. As those systems become more connected to core business processes, security teams are being asked to monitor not only code and users, but also the instruction and data sources that influence agent behaviour.

Yair Saban set out the company's view of that shift.

"Every enterprise has a firewall protecting its network. Now they need one protecting their AI agents. AI agents need a new kind of firewall, one that protects what enters their context," said Yair Saban, Co-Founder and Chief Executive Officer of AIR.

He added: "Today, agents are autonomously installing tools, connecting to internal systems and making decisions, and in most organizations, nobody knows what's running, what's trusted or how to shut it off."

Investors framed the company as an early attempt to address a new layer of enterprise security tied to the spread of AI agents.

"What gave us conviction in AIR from the beginning was the founders. They saw early that AI agents would create a completely new security problem for enterprises and started building for it before most companies were even thinking about it. We believe they have the team and the vision to define this category," said Bogomil Balkansky, Partner, Sequoia Capital.

Greenoaks drew a parallel with software supply chain risk, but argued that AI agents raise the stakes because they act at runtime and draw on services that may never have gone through a formal review process.

"Software supply chains were never the most critical attack surface within an enterprise. Now, with AI agents, they are vitally important," said Patrick Backhouse, Partner, Greenoaks.

He added: "Agents operate at runtime, using skills, plugins, add-ons and MCPs from sources that no security team has reviewed, and they slip past scanners built for yesterday's code. AIR is building the platform to discover every agent, govern what they are allowed to touch and monitor them in production. We believe this layer will become mandatory to enterprise cybersecurity, and we are proud to partner with Yair, Niv and the AIR team as they define it."