A critical assessment of the $50M that AIR raised across two seed rounds weeks apart — ~$10M led by Sequoia, then ~$40M led by Greenoaks — to build a “context firewall” for AI agents, entering a category the platform vendors have already begun buying out.
Yes. Agents now load skills, plugins, and MCP servers from sources no security team reviewed — a genuine, expanding attack surface. Sequoia and Greenoaks are underwriting a consensus thesis the whole category is funding, not a contrarian one.
Barely. This is a shakeout, not greenfield: Prompt Security sold to SentinelOne (~$250M), Protect AI to Palo Alto (~$700M), and Zenity just raised $125M. AIR enters at seed, six months old, behind rivals one to two rounds ahead.
The funding is confirmed by five outlets. Everything else — 20+ customers, a 27% filter rate, 17,800 malicious add-ons, 6.7M installs — traces back to AIR itself. No named customer, no ARR, no third-party audit, no certifications.
Key Finding: AIR has a strong syndicate, an elite offensive-cyber founding team, and a real problem. But it is a six-month-old seed-stage entrant in a market where the platform vendors have already bought their agent-security capability — and its own CEO concedes the approach “was very easy to copy.” The most likely path is acquihire into a platform, and a $50M seed sets a high bar for a soft landing.
CEO Yair Saban’s analogy: agent add-ons today are like unsigned drivers in the early 2000s — unvetted code running with privilege. AIR positions itself as the signing authority. Here is the lifecycle it claims to cover.
Find the AI agents — sanctioned and shadow — running inside the enterprise.
Enumerate the skills, plugins, MCP servers, and sub-agents each agent pulls in.
Analyze each add-on for hidden behavior, prompt injection, and supply-chain takeover.
Sit inline and filter every input into the agent’s context as it operates.
Re-vet after every add-on update — the point where trusted tools turn malicious.
The website and the press describe two different products. Coverage sells a discovery-and-posture tool (“find your agents, vet their add-ons”); the site leads with an inline “context firewall” that filters every input at runtime. Those have different architectures and different moats. The story has not converged — a tell for a company that raised on narrative before the product did.
AIR’s launch centers on internal “MCPJacking” research: 17,800+ public AI add-ons tied to untrusted external sources across ~6.7M installations, with ~27% of what it scans filtered out. These are striking numbers — and every one of them is generated by the vendor selling the fix, unaudited and unreproduced. Compelling marketing; not yet evidence.
Led the first ~$10M. Thesis: founders “saw early that AI agents would create a completely new security problem.”
Led the ~$40M. Thesis: agents use “skills, plugins, add-ons, and MCPs from sources no security team has reviewed.”
Offensive-cyber provenance is the hook — but the same alumni network produced NSO Group. A dual-use question for regulated buyers.
AIR sits between agents and the outside world, filtering every input into an agent’s context. Maximum value — and maximum access.
Calling a $40M round “seed” conveniently sidesteps Series-A valuation optics. The two-step structure is unexplained.
A security vendor with inline access to all agent traffic launched with no visible SOC 2 or ISO 27001 — a procurement blocker.
The structural risk AIR’s launch never addresses: the platform vendors have already started acquiring their way into agent security, and the strongest independents are one to two rounds ahead.
Acquired August 2025 having raised only ~$23M. The platform players are buying, not building — and paying premiums for teams that got in earlier than AIR.
Folded into Prisma AIRS. Palo Alto, CrowdStrike, Check Point, and SentinelOne now each have an agent-security answer already in the portfolio.
Raised August 2026, led by Norwest. Among independents still standing, Zenity and Noma (~$100M+ Series B) out-resource a $50M seed-stage entrant chasing the same finance and pharma buyers.
Company-claimed, none named, no ARR. The verifiable core of this story is the funding event; the traction is entirely self-reported six months in.
The moat rests on a claim you cannot check. Saban concedes the approach “was very easy to copy in the past” and that “many companies are emerging today,” then asserts the detection engine is “very difficult to develop.” That is a moat argument built on unverifiable internal difficulty — not on data, distribution, or switching costs.
Six structural risks the $50M does not resolve.
Platform vendors have already acquired agent-security capability (Prompt, Protect AI, Apex). AIR’s window to remain independent may be closing before it scales — a risk its launch messaging never names.
No named customer, no ARR, no third-party validation of the 20+ customers, 27% filter rate, or 17,800-add-on research. The only independently confirmed fact is that the money moved.
Zenity (~$125M) and Noma (~$100M+) are one to two rounds ahead in the same finance and pharma accounts AIR is targeting from a standing start.
Inline visibility into all agent context, built by offensive-cyber operators, with no visible SOC 2 / ISO 27001 and no named subprocessors — the product’s value and its risk are the same surface.
“Context firewall” (runtime filter) and “discover-and-vet add-ons” (posture) are different products. The identity hasn’t settled — risky when rivals ship both.
~$10M then ~$40M weeks apart, both labeled seed, unexplained. Benign read: Greenoaks pre-empted at a markup. Skeptical read: round health or valuation optics.
AIR is a strong team with a strong syndicate solving a real problem — late. The agent-security attack surface is genuine, and Sequoia plus Greenoaks is a serious signal. But this is a consolidating market, not a greenfield: the platform vendors have already bought in, the leading independents are rounds ahead, and AIR’s traction is entirely self-reported at six months old. The most honest read is that the $50M buys a seat at an acquihire table — a high price for a soft landing, and a high bar to clear if it wants anything more.
Based entirely on publicly available information, including the TechCrunch announcement of September 1, 2026. Every operating metric in this report is company-sourced unless otherwise attributed; only the funding event is independently corroborated.