AIR emerged from stealth through its September 1, 2026 launch post, presenting a firewall intended to filter untrusted material before it enters an AI agent’s context. The product targets add-ons, websites and internal data encountered by enterprise agents across endpoint, cloud and software-as-a-service environments.
New York-based AIR launched with $50 million raised in two rounds: a $10 million round led by Sequoia Capital and a subsequent $40 million round led by Greenoaks. The financing will support security research and commercial expansion in the United States and Europe.
The financing backs a software-supply-chain thesis
The investment case is that AI agents are acquiring a software supply chain of their own. Skills, plug-ins, Model Context Protocol servers and sub-agents extend what an agent can access or execute, but they also introduce dependencies and instructions that an enterprise may neither own nor inspect directly.
A one-time approval cannot account for every later change. A component may keep the same name while retrieving a different package, contacting a new domain or operating through a compromised publisher account. Repeated verification is meant to identify that change before another agent relies on the component.
The thesis therefore extends beyond scanning an add-on when it is first installed. AIR is betting that maintaining current knowledge about a shifting public component ecosystem—and applying that knowledge across an enterprise agent fleet—can become a distinct security layer.
AIR combines discovery, enforcement and repeated verification

AIR’s product model has three parts. Discovery maps agents and the components they use; runtime enforcement intercepts relevant activity and blocks interactions that fail policy; and continuous component verification reassesses third-party additions instead of treating an earlier approval as permanent.
TechCrunch’s account of AIR’s platform describes agent discovery, action interception and a maintained allowlist built by evaluating publicly available skills and add-ons for changes or malicious behavior. It also records early customer and sector-demand figures supplied by AIR’s chief executive, rather than independently audited adoption or revenue data.
The repeated-verification layer is AIR’s principal differentiation argument. Discovery determines whether an agent or component exists, while enforcement decides whether a particular interaction may proceed. Re-verification asks whether the component itself has changed enough to lose its trusted status before its content reaches an agent.
That process could create an information advantage if AIR evaluates a broad component ecosystem and converts observed changes into accurate security decisions. It is not yet a demonstrated moat: agent platforms and established security vendors can add overlapping checks, while customers may prefer controls bundled with identity, endpoint or broader AI-security products.
The competitor matrix shows substantial overlap

The useful comparison is which stages of the control chain each vendor publicly describes. The available product materials establish feature coverage, but they do not provide an independent head-to-head test of detection quality, false positives or blocking performance.
- AIR — discovery: described; runtime enforcement: described; continuous component verification: central proposition. Its proposed advantage is the recurring evaluation of internet-available skills, plug-ins and MCP servers, not agent inventory alone.
- Noma Security — discovery: described; runtime enforcement: described; continuous component verification: partial overlap. Noma’s access-control product page covers discovery-fed registries for agents, MCP servers and skills, policy checks when connections or actions are attempted, behavioral monitoring and supply-chain assessment. It does not establish the same recurring evaluation of a wider public add-on ecosystem.
- Operant AI — discovery: described; runtime enforcement: described; continuous component verification: limited public evidence. Operant’s MCP Gateway documentation covers real-time agent and tool discovery, traffic inspection, tool-poisoning detection, trust scoring and blocking of untrusted servers or tools. Those controls overlap with AIR’s discovery and enforcement layers, but the page does not establish an equivalent process for repeatedly reassessing public skills and plug-ins after they change.
The matrix narrows AIR’s possible advantage to the breadth, freshness and accuracy of its external component intelligence. Enterprises can already obtain discovery, access policy and runtime blocking elsewhere; AIR must show that recurring verification changes security decisions those controls would otherwise miss. The adjacent market for assigning distinct identities to enterprise agents also suggests that customers may assemble protection from several overlapping control planes.
Funding is substantiated; commercial traction is not
The financing has the strongest outside support: contemporary coverage agrees on the total, round structure and lead investors. The product architecture is documented by AIR and rival vendors, but the reviewed material contains no independent comparative test of their detection or enforcement performance.
AIR has disclosed customer counts, large-enterprise usage and demand in regulated industries, but those figures originate with the company. Named deployments, contract values, audited revenue, retention and pricing have not been made public, leaving the commercial traction behind the financing independently unverified.
The same distinction applies to market forecasts. Founder expectations may explain investor appetite, but they cannot establish current category revenue or future pricing power without independently measured sales and renewal data.
Pricing power depends on evidence still missing
AIR’s launch gives continuous verification of agent components a well-financed specialist vendor. It does not establish that enterprises will purchase the capability as a standalone layer rather than obtain comparable protection from agent platforms, identity providers, endpoint products or larger security suites.
Durable differentiation would require evidence that AIR’s changing trust assessments identify consequential component risks earlier or more accurately than configured policy and runtime monitoring alone. At launch, the $50 million financing and product proposition are substantiated; valuation, revenue, pricing, retention and independently tested superiority remain undisclosed.
Also read:
Click Here For The Original Source.
