Ex-Israeli Intelligence Officers Raise $50M to Build a Firewall for Rogue AI Agents
Editorial Team

AIR Security founder Yair Saban (CEO) and Niv Hoffman (CTO)
Image credit: AIR Security
AIR Security, an Israeli cybersecurity startup, has emerged from stealth with 50 million dollars raised across two seed rounds to build what its founders describe as a firewall purpose‑built for AI agents.
The company was founded by chief executive Yair Saban and chief technology officer Niv Hoffman, both veterans of Israel's Unit 8200 intelligence corps, where they worked on offensive cybersecurity. The two funding rounds closed within weeks of each other during AIR's first six months of operation: an initial 10 million dollars led by Sequoia Capital, followed by a 40 million dollar round led by Greenoaks, with additional backing from Swish Ventures, Netz, and a roster of angel investors drawn from the cybersecurity and AI industries. The company has grown to roughly 40 employees, including a dedicated AI and agent behavior research lab, and recently added Ryan Knisley as chief strategy officer, who previously served as chief information security officer at both The Walt Disney Company and Costco Wholesale.
Saban has framed the company's mission in a single line that has become its core pitch: "Every enterprise has a firewall protecting its network. Now they need one protecting their AI agents." The problem AIR is built to address stems from how fundamentally different AI agents are from traditional software. Agents can browse websites, read emails and files, and take actions on behalf of employees, and they increasingly extend their own capabilities by installing plugins, using Skills, connecting to Model Context Protocol servers, and spinning up subagents. Unlike conventional software, agents make decisions based on information they encounter while carrying out a task, which means malicious content or a compromised tool can influence an agent's behavior in ways that are difficult for security teams to predict or even fully observe after the fact.
AIR's platform is built to close that visibility gap. It continuously discovers which AI agents are running inside an organization, evaluates the skills, plugins, and add‑ons those agents rely on both before and after deployment, and, when it identifies something malicious, vulnerable, or simply unapproved, traces every agent and workflow that depends on it and revokes its use across the company. The company is also building a marketplace of pre‑vetted, certified add‑ons, giving enterprises a way to expand what their agents can do without introducing tools that have never been independently reviewed.
The scale of the underlying problem, according to AIR's own research, is substantial. The company has identified more than 17,800 public AI add‑ons linked to untrusted external sources, collectively accounting for roughly 6.7 million installations, and its scanning process currently filters out approximately 27 percent of the add‑ons and skills it evaluates online due to security concerns. That rejection rate suggests a meaningful share of the tools already circulating through enterprise AI agent deployments would fail even a baseline security review, a gap that has apparently gone largely unaddressed given how recently agentic AI tools have moved into mainstream enterprise use.
Saban has been direct about where he believes the company's durable advantage lies, distinguishing AIR's approach from what he sees as a much easier, less defensible layer of the market. "Continuously vetting skills and plugin websites, this is a hard mission to do. Gaining visibility over the endpoint, that is easy. Everybody's going to do it. It's hard to create a moat around that," he said. He acknowledged that AI labs and providers will eventually build their own security checks and policies to filter out malicious skill and tool usage, but argued that companies will still want to buy an independent product capable of working consistently across different AI vendors and platforms, rather than relying solely on protections built by any single model provider.
Sequoia partner Bogomil Balkansky, whose firm led AIR's first round, framed the core challenge in similar terms. "This is not a scanning problem, it is a continuous re‑verification problem," he told TechCrunch, underscoring that a one‑time security check is insufficient in an environment where the same skill or plugin can be modified, compromised, or repurposed after it has already passed an initial review.
AIR has moved quickly from stealth into meaningful commercial traction. More than 20 companies now use the platform, with roughly a quarter of them large enterprises, and the strongest demand so far has come from financial services and pharmaceutical firms, sectors where the potential downside of a compromised AI agent, whether through data theft, fraud, or unauthorized access, carries particularly high stakes. Saban noted that the company has begun hiring employees in the United States as part of its expansion, including the senior Disney executive who now serves alongside him at AIR.
The competitive landscape AIR is entering has been drawing substantial capital in its own right. Zenity raised a 125 million dollar Series C in August, while Noma raised a 100 million dollar Series B the previous year, both pursuing related theses around securing the tools and infrastructure that AI agents depend on. That level of investment reflects a broader recognition across the security industry that as enterprises hand AI agents increasingly broad operational access, the biggest vulnerability may no longer be the underlying language model itself, but the decentralized, rapidly growing web of third‑party extensions connected to it, precisely the layer of the AI stack AIR has built its entire platform around securing.
Topics
Stay informed
Startup news in your inbox
Get important funding rounds, founder stories, and startup updates.
No spam - only important startup updates.





