AIR Raises $50M to Secure Enterprise AI Agents From Risky Skills and Add-Ons

AIR Raises $50M to Secure Enterprise AI Agents From Risky Skills and Add-Ons

TL;DR

  • Cybersecurity startup AIR has raised $50M to tackle the emerging enterprise threat of uncontrolled AI agents, with its platform designed to discover, vet, and govern agents operating inside corporate environments.
  • The company's technology automatically inventories all AI agents, continuously audits the third-party skills, tools, and add-ons they connect to, and enforces real-time policy controls to block risky actions before they happen.
  • The funding will fuel product expansion and go-to-market growth as enterprises rapidly deploy autonomous agents and face a new wave of identity, data leakage, and compliance risks.

Beyond Chatbots: Why AI Agents Are Enterprise Security's Next Nightmare

Enterprises spent the last two years racing to deploy AI agents to automate everything from customer support and coding to sales operations and finance. That speed has created a blind spot. Unlike traditional SaaS apps or even early generative AI chatbots, autonomous agents don't just generate text — they take action. They read emails, query databases, execute code, move money, and connect to dozens of external tools to get the job done.

Security leaders are now confronting a new form of shadow IT. Employees and teams are spinning up agents built on frameworks like LangChain, AutoGen, CrewAI, and OpenAI's GPTs, often connecting them to sensitive internal systems via Model Context Protocol (MCP) servers and third-party skills marketplaces. Most security teams have no central inventory of which agents are running, what data they can access, or what they are actually doing. AIR was founded to close that visibility and control gap.

Introducing AIR: A Control Plane for AI Agents

AIR, which stands for Agent Identity & Risk, is building what it describes as a control plane for enterprise AI agents. Rather than focusing on securing the underlying large language models themselves, the platform is focused on governing agent behavior in production.

The core of the platform rests on three pillars. First is automated discovery. AIR continuously scans enterprise environments — including cloud infrastructure, identity providers like Okta and Microsoft Entra ID, SaaS apps, and code repositories — to find and fingerprint every AI agent operating inside the company, whether it was officially sanctioned by IT or built by an individual employee.

Second is continuous vetting of skills and add-ons. Agents are only as trustworthy as the tools they are given. A single malicious or overly permissive skill — such as a third-party connector that requests broad Gmail or Slack access, or an MCP tool that can exfiltrate data — can turn a helpful agent into an insider threat. AIR maintains a dynamic risk registry that analyzes every skill, plugin, and API connection an agent uses, scoring it for data access, privilege escalation, supply chain risk, and compliance violations.

Third is real-time enforcement. Discovery and vetting mean little without the ability to act. AIR sits inline as a policy enforcement layer, allowing security teams to set granular guardrails such as blocking an agent from sending data outside the corporate tenant, preventing it from executing financial transactions above a certain threshold, or requiring human-in-the-loop approval for high-risk actions. Policies can be applied globally or tailored by agent, team, or data classification.

From Visibility to Action in Real Time

What sets AIR apart from traditional Cloud Access Security Brokers (CASBs) or SaaS Security Posture Management (SSPM) tools is its focus on dynamic, autonomous behavior. An agent's risk profile can change in seconds as it downloads a new skill or is given a new objective. AIR's approach is to treat every agent as a non-human identity with its own lifecycle that must be governed continuously, not just audited quarterly.

For example, if a sales agent originally approved to summarize Salesforce records suddenly installs an unverified add-on that allows it to export that data to an external spreadsheet tool, AIR can automatically flag the skill as high-risk, quarantine the agent, and block the exfiltration attempt before it completes. Security teams get a full audit trail of the agent's attempted actions, prompts, and tool calls for investigation and compliance reporting.

The platform also maps agent-to-agent interactions, a rapidly growing attack surface as companies deploy multi-agent workflows where agents delegate tasks to one another. This gives CISOs visibility into privilege chains that would otherwise be invisible.

A $50M Bet on the Next Wave of Enterprise Security

The $50M raise signals strong investor conviction that agent security will become a foundational enterprise category, much like endpoint or identity security. The round brings AIR's total funding to date to over $60M and will be used to scale its engineering team, expand its integrations with major agent frameworks and cloud providers, and build out its go-to-market organization in the U.S. and Europe.

The company plans to use the capital to deepen its behavioral analytics engine, adding more sophisticated anomaly detection to spot when a previously well-behaved agent starts acting outside its normal pattern — a key indicator of prompt injection, tool poisoning, or a compromised skill. It will also expand coverage for governance and compliance use cases, helping enterprises prove to auditors and regulators that their AI workforce is operating within defined boundaries.

Why Now Is the Inflection Point

The timing is critical. Analysts estimate that the average enterprise will have more AI agents than human employees within the next two years. At the same time, marketplaces for agent skills and MCP tools are exploding, with thousands of community-built connectors available with little to no security vetting. This mirrors the early days of mobile app stores and browser extensions, which created massive security headaches for enterprises.

Regulatory pressure is also mounting. Frameworks like the EU AI Act and updated SOC 2 and ISO 42001 requirements are pushing companies to demonstrate oversight of autonomous AI systems. CISOs can no longer afford to answer "we don't know" when asked how many AI agents they have or what those agents can do.

AIR is betting that the answer won't be to block AI agents — which would put companies at a competitive disadvantage — but to give enterprises the confidence to deploy them at scale. By making agent behavior discoverable, understandable, and controllable, the company aims to become the essential security layer for the agentic enterprise.


AndroGuider Team
Articles written by the AndroGuider team. We try to make them thorough and informational while being easy to read.
AIR Raises $50M to Secure Enterprise AI Agents From Risky Skills and Add-Ons AIR Raises $50M to Secure Enterprise AI Agents From Risky Skills and Add-Ons Reviewed by Randeotten on 9/01/2026 11:49:00 PM
Subscribe To Us

Get All The Latest Updates Delivered Straight To Your Inbox For Free!





Powered by Blogger.