AIR Security Secures $50M to Pioneer Inline Governance for Autonomous AI Agents
AIR Security formally launched with $50 million in seed financing across two rapid rounds—an initial $10 million led by Sequoia Capital followed by a $40 million investment led by Greenoaks Capital. Founded by Israeli Unit 8200 veterans Yair Saban and Niv Hoffman, the New York-based startup builds an inline runtime firewall tailored for autonomous AI agents. The platform maps active agents operating across endpoints, cloud accounts, and software-as-a-service applications, continuously evaluating the dynamic instructions, external skills, and Model Context Protocol (MCP) servers they interact with.
The traditional enterprise security perimeter assumes human developers explicitly introduce dependencies and configurations during development cycles. Autonomous agentic architectures invert this model: modern coding assistants and operational agents dynamically pull third-party skills, external plugins, and remote context servers at runtime without manual intervention from security teams. Company research revealed that roughly 27% of public AI add-ons and skills get filtered out due to risks such as impersonation and arbitrary code execution. Securing these interactions is no longer just a compliance checkpoint; it is a prerequisite for platform engineering teams aiming to grant agents real operational autonomy.
This significant early-stage capital concentration reflects a broader transition across the AI infrastructure ecosystem from core foundation model training toward runtime governance and operational integrity. While initial enterprise AI funding cycles prioritized generative foundation models and developer orchestration layers, the rapid adoption of standardized tool interfaces exposed an acute visibility void. Traditional Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) cannot inspect non-deterministic, ephemeral execution graphs where an agent queries new tools or updates external dependencies mid-task.
For cloud architects and DevOps leaders, the immediate takeaway is that autonomous AI agents must be treated as distinct privileged runtime entities requiring continuous verification rather than one-time pre-deployment scanning. Organizations rolling out autonomous agents should catalog active agent instances and evaluate inline mediation proxies capable of validating tool schemas, MCP servers, and incoming context payloads before downstream system execution.
Read original source