Companies have spent the last several years enthusiastically granting AI agents access to their databases, systems, and internet connections. AIR has raised $50 million to help them figure out what those agents are doing with that access.
The startup emerged from stealth this week. The timing is, in retrospect, logical.
The supply chain for AI agents is forming faster than anyone's ability to know what is in it.
What happened
AIR, founded by Yair Saban and Niv Hoffman — veterans of Israel's Unit 8200 intelligence corps — has closed two seed rounds totaling $50 million. Sequoia led the first, a $10 million round. Greenoaks led the second, at $40 million. Both rounds closed within weeks of each other, which suggests a certain urgency in the market, or possibly in the calendars of the founders.
The company's product monitors the supply chain forming around AI agents: the skills, plugins, MCP servers, and add-ons that let agents interact with the broader world. It discovers agents running inside a company, vets what those agents are connecting to, and blocks interactions that fail its security criteria. It also maintains a marketplace of pre-approved tools, for companies who would prefer their agents shop somewhere supervised.
Angel investors include Anne Neuberger, Zach Frankel of Cognition, and Yinon Costica, co-founder of Wiz. The cap table, like the product, appears designed to know exactly who is in the room.
Why the humans care
Saban's analogy is instructive. In the early 2000s, any driver could load code directly into a Windows kernel without a signature. This was, eventually, recognized as a problem. The industry corrected it. Today, AI agents are installing third-party skills and plugins into enterprise systems with roughly the equivalent oversight of a 2003 laptop running unsigned drivers.
The specific risk AIR is addressing is prompt injection and supply chain poisoning — not attacking the agent directly, but corrupting the content it consumes. An agent that trusts everything it reads is, by definition, one instruction away from doing something its employer would not endorse.
AIR also tracks employees using unapproved AI tools or personal accounts — a feature that will be received differently depending on whether you are the IT department or the employee in question.
What happens next
AIR will now build out its enforcement layer, expand its vetted-tools whitelist, and presumably onboard enterprise clients who have already deployed agents and are now, with the enthusiasm of someone who has just read the safety manual, curious about what those agents have been doing.
The supply chain for AI agents is forming faster than anyone's ability to know what is in it. This is the kind of observation that sounds like a warning and functions as a business model.