AegisAI Raises 36 Million Dollars to Fight AI Powered Spear Phishing With Agents of Its Own
Editorial Team

AegisAI, an email security startup founded by former Google security executives, has raised 36 million dollars in a Series A round led by Battery Ventures, with participation from existing investors Accel and Foundation Capital, to expand its fleet of AI agents built to catch increasingly sophisticated, AI‑generated phishing attacks.
The round brings AegisAI's total funding to 49 million dollars, less than a year after the company emerged from stealth. The company was founded by Cy Khormaee and Ryan Luo, who spent years together inside Google's core security organization, where they helped build reCAPTCHA, Safe Browsing and Web Risk, giving them roughly a decade of combined experience defending against email based attacks before starting their own company.
A New Category of Attack Outpacing Old Defenses
AegisAI's founders built the company around a specific insight: traditional email security tools rely on rule based, if‑then logic to catch malicious messages, an approach that struggles against phishing emails that are increasingly written by large language models rather than humans. These AI‑crafted attacks, which the company refers to as AI spear phishing, use large language models to scan the internet for detailed information about a target, then generate highly personalized, linguistically flawless lures designed to convince that specific person to hand over sensitive information or access.
According to research AegisAI presented at this year's M3AAWG conference, drawn from a pool of more than 20,000 malicious emails, AI‑generated spear phishing made up just 2.8 percent of observed phishing attempts in early 2025 but climbed to 13.9 percent by the end of the year. The company also found that AI‑written attacks reached inboxes at close to twice the rate of human written ones, and that almost 73 percent of the attacks that got through had already cleared standard email authentication checks, having been sent from real accounts that attackers had quietly taken over rather than spoofed from outside.
Agents That Read Intent, Not Just Patterns
Rather than relying on lists of known malicious patterns, AegisAI's platform uses autonomous AI agents that analyze each incoming message the way a careful human reviewer would, paying attention to subtle anomalies in tone, context and identity that a checklist based system would miss entirely. Khormaee has described the core challenge in stark terms, arguing that once an AI model is doing the manipulating, human trust itself cannot simply be patched, and that defending against an AI‑driven attack requires an AI‑driven defense in response.
The company says its agents can catch threats that traditional filters routinely miss, including malicious PDF attachments built to look legitimate, some of which include built‑in passwords or CAPTCHA challenges specifically designed to defeat standard spam filtering systems.
Real Attacks Caught Across Early Customers
Less than a year after launch, AegisAI says its technology has been adopted by dozens of customers spanning fintech and technology sectors, including crypto payments company Mesh, AI infrastructure company LangChain, and privacy compliance platform Lokker. At Lokker, the company says its agents caught an attack that arrived through a trusted vendor's compromised Salesforce infrastructure rather than through any obvious malicious link or attachment, illustrating how modern supply chain based attacks can bypass defenses focused only on scanning message content directly.
Dharmesh Thakker, general partner at Battery Ventures, said he began looking to invest in agentic email defense after noticing a rising wave of email based attacks, framing the space as one where defending against AI‑driven threats will increasingly become a top priority for organizations of every size.
What the New Funding Will Support
AegisAI plans to use its new capital to scale its fleet of autonomous defense agents, accelerate the general availability of Vanguard, a newer agent designed to hunt threats beyond the traditional inbox, and expand its enterprise go to market efforts more broadly. The company has also signaled plans to extend its defensive technology into broader data security applications beyond email specifically, suggesting an ambition to grow well past its current focus.
Part of a Broader Race in Agentic Cybersecurity
AegisAI is not alone in applying AI agents to detect AI‑generated fraud, with a growing number of cybersecurity startups racing to build tools that analyze the full context of incoming communications rather than relying purely on known threat signatures. That broader competitive landscape reflects a wider shift across the cybersecurity industry, where attackers and defenders are both increasingly turning to AI systems, creating an accelerating arms race that traditional, static security tooling is struggling to keep pace with.
With fresh capital and a growing customer base built primarily through word of mouth in its first year, AegisAI's next challenge will be scaling its detection accuracy across a much larger and more diverse set of enterprise environments while continuing to stay ahead of attackers who are themselves racing to make their AI‑generated lures even harder to distinguish from legitimate communication.





