AIR Security was founded in early 2026. By September, it had raised $50 million in two sequential seed rounds — a $10 million round led by Sequoia Capital, followed within months by a $40 million round led by Greenoaks Capital, with Swish Ventures and Netz Capital also participating. That pace, two of the biggest names in venture piling into a pre-revenue-at-scale company inside a single half-year, is itself a signal worth reading. Investors don’t usually move that fast unless they think a real, urgent gap has opened up — and in this case, the gap is a specific and fairly alarming one: almost nobody is checking what the AI agents running inside their companies are actually allowed to do.
The company was co-founded by CEO Yair Saban and CTO Niv Hoffman, both veterans of Unit 8200, the Israeli intelligence corps’ elite cyber unit — a pedigree that shows up constantly among enterprise security startups for a reason. AIR’s roughly 40-person team, based in New York, built a platform that sits inline in front of a company’s AI agents: it discovers which agents are actually running across the network, continuously vets every tool, plug-in, and skill those agents try to use, and blocks anything that doesn’t clear a security screen before it ever touches company systems or data. The company describes it plainly as a firewall — not for a network, but for an agent’s behavior.
The Numbers Behind the Urgency
AIR’s own research is what makes the pitch land. The company says it identified more than 17,800 publicly available AI add-ons — collectively installed more than 6.7 million times — that ship with unverified instructions baked in. Some of what its researchers found were fake skills deliberately impersonating official tooling from Anthropic and OpenAI, designed to slip past developers who assume a recognizable brand name means a vetted, safe integration. Across the tools and skills it scans, AIR currently filters out roughly 27% as unsafe or non-compliant — a rejection rate that, if representative, means more than a quarter of what enterprise AI agents are being handed access to right now would fail even a baseline security check.
Saban framed the gap with a comparison to an earlier era of computing that a lot of enterprise IT teams will recognize instantly. “In the early 2000s, whenever you installed a driver, the driver didn’t need to be signed,” he said. “Today, every time you install a driver, you see a signature… You don’t have that with skills or plug-ins or MCPs.” That’s the core of AIR’s bet: the software industry has been through this exact governance gap before, with device drivers, with browser extensions, with mobile app permissions, and each time the fix was the same — a verification layer between “someone built this” and “this is allowed to run inside your company.” AI agents, and the Model Context Protocol servers and third-party skills they increasingly pull in on the fly, have no equivalent yet. AIR is betting it can be the company that builds one before the incidents start piling up.
Who’s Actually Buying, and Why It Matters
AIR already has more than 20 paying customers, with roughly a quarter of them large enterprises, and the company says its strongest demand is coming from financial services and pharmaceuticals — two of the most heavily regulated, most audited industries there are. That’s not a coincidence, and it’s a useful signal for reading where “AI agent governance” is headed as a category. Regulated industries adopt new security tooling first not because they’re more paranoid, but because they’re the ones who will eventually be asked by a regulator or an auditor to prove exactly what their AI systems are permitted to touch — and right now, most companies genuinely can’t answer that question with any precision. AIR’s roster of angel investors reinforces the same read: former Disney and Costco CISO Ryan Knisley joined as Chief Strategy Officer, and the round’s backers include Wiz co-founder Yinon Costica, Eon co-founder Ofir Ehrlich, Cognition president Zach Frankel, and Anne Neuberger, formerly the White House’s deputy national security advisor for cyber. That’s a group of people who have collectively spent careers cleaning up after governance gaps like this one — not a group that invests in a category casually.
What This Means for Philippine Founders
The Philippines’ BPO, GBS, and fintech sectors are moving fast on AI agents for exactly the workflows AIR is built to police — customer support, KYC checks, back-office processing — and every one of those deployments involves plugging third-party tools and skills into pipelines that touch real customer data. AIR’s own research suggests a meaningful share of what’s publicly available to plug into an agent shouldn’t be trusted by default. Philippine enterprises adopting agentic AI at scale, often with smaller security teams and thinner budgets than the Fortune 500 clients AIR is currently targeting, carry the same unvetted-supply-chain exposure with fewer resources to catch it before something goes wrong.
There’s also a founder-facing lesson in how AIR itself got built. Two people with a genuinely narrow, technically credible specialty — not “an AI security platform” broadly, but one precisely defined failure mode inside agent supply chains — raised serious institutional capital within months of starting. Philippine security and dev-tool founders chasing enterprise checks should read that as confirmation of something that’s easy to forget while building: the winning wedge in enterprise security is almost never the broad platform pitch. It’s the narrow, provably real problem that a credible team can explain in one sentence — and increasingly, any Philippine startup already shipping AI agents to bank, telco, or healthcare clients should expect those same clients to start asking for exactly the kind of documented, filtered tool inventory AIR is selling.
Share this article