I’m reading this one from Mexico in the evening slot, and it’s not another governance speech or home-LAN router demo — it’s money into the boring layer that actually decides what an agent is allowed to load. AIR just came out of stealth with $50 million across two seed rounds to police the supply chain of skills, plug-ins, and MCP servers that AI agents bolt onto company systems. That’s the lead on TechCrunch’s Sep 1 write-up by Ram Iyer, and AI Insider’s Sep 7 brief matches the same numbers.
Founders are Yair Saban (CEO) and Niv Hoffman (CTO), both Unit 8200 veterans who worked offensive cybersecurity. Per TechCrunch, the rounds closed within weeks of each other: first $10M led by Sequoia, then $40M led by Greenoaks. Angels and participants include Zach Frankel (Cognition), Yinon Costica (Wiz), Ofir Ehrlich (Eon), Swish, Netz, Anne Neuberger, Omer Adam, Varun Anand (Clay), and others. SecurityWeek frames the same raise as an “AI agent firewall” story — useful third confirmation that this isn’t a one-outlet rumor.
What AIR actually sells
The product stack, again from TechCrunch and AI Insider: discover agents running inside the company environment; flag employees using unapproved AI tools or personal accounts; hook into agents for real-time enforcement on actions like loading a skill or fetching internet content; and check tools against a continuously updated whitelist AIR maintains. Saban told TechCrunch the platform currently filters about 27% of the add-ons and skills it evaluates online — because a previously approved skill can go bad when a dependency changes or a developer account gets compromised. There’s also a marketplace of vetted add-ons and skills.

The OS lesson — and who’s already buying
Saban’s pitch, quoted in TechCrunch: wholesale agent use is starting to resemble an operating system, but skills, plug-ins, and MCPs still don’t get the signed-driver treatment we learned the hard way in the early 2000s. The scary path isn’t only direct compromise — it’s poisoning the content an agent consumes while it works across databases and the open internet. Sequoia partner Bogomil Balkansky put it bluntly to TechCrunch: this is a continuous re-verification problem and an infrastructure problem long before it’s a “write a better scanner” problem. AI Insider carries the same framing.
Traction claims on the record: more than 20 customers, roughly a quarter large enterprises, with the strongest demand so far in financial services and pharma (TechCrunch / AI Insider). Headcount is about 40; the new capital is earmarked for researchers and go-to-market in the U.S. and Europe. Competition is real and well-funded: TechCrunch names Zenity, Noma Security, Astrix Security, and Operant AI — including Zenity’s $125M Series C in August and Noma’s $100M Series B last year. From Mexico, my take is simple: if your agents can install tools the way a kernel loads drivers, you need someone continuously re-checking the package — not a one-time scan. Sources: TechCrunch, AI Insider, SecurityWeek.
Hero image: teal LED / circuit panel by Adi Goldstein on Unsplash (Unsplash License). Cropped, graded, and lightly grained by Tech & AI Pulse. Face-free circuit still — no people, no logos.