AIR raises $50M to police AI agent behaviors in enterprise stacks
AIR, a stealth security company focused on the emerging class of AI agents, announced a $50 million Series A financing led by Lightspeed Venture Partners, with participation from Index Ventures and GV. The round values AIR at $420 million and arrives just six months after the startup quietly launched from stealth in March 2025. CEO Oren Yungster, a former Palantir executive who also co-founded a stealth AI observability startup, described the platform as the first continuous vetting and blocking system purpose-built for AI agents—software entities that can schedule meetings, analyze financial data, or orchestrate cloud resources. “Agents are becoming the primary interface between humans and systems,” Yungster said in an exclusive interview, “but there is no runtime control plane that can discover, monitor, and quarantine malicious or misbehaving agents before they cause damage.”
AIR’s platform operates in four phases: discovery, profiling, vetting, and enforcement. It scans enterprise environments—cloud APIs, SaaS integrations, endpoint logs—to identify agents, including those not explicitly approved by IT. Once discovered, the system profiles each agent’s skills, add-ons, data access, and external integrations. AIR then applies a policy engine that continuously evaluates behavior against customizable rules—such as blocking an agent from accessing customer PII after hours or preventing a financial agent from initiating wire transfers without dual approval. If a violation is detected, AIR can quarantine the agent, revoke credentials, or trigger a human review. The company points to a recent customer engagement where an unmanaged AI agent was discovered making API calls to a financial data provider; AIR blocked the calls and alerted security teams before any sensitive data left the environment. AIR also claims compatibility with major enterprise stacks, including Snowflake, Salesforce, and AWS Bedrock agents.
The financing round was anchored by Lightspeed’s Sarah Smith, who highlighted the urgency of agent-level security as AI adoption accelerates across regulated industries. “We’re seeing banks, insurers, and healthcare providers deploy hundreds of agents per week,” Smith said, “but most CISOs are flying blind—they don’t know what agents exist, what permissions they have, or how they’re being used.” AIR’s Series A follows a $10 million seed in late 2024 and brings total funding to $60 million. Existing investors Index Ventures and GV increased their pro-rata participation, underscoring confidence in the agent security thesis. Competitive pressure is rising: rival firms like SentinelOne and Palo Alto Networks have begun rolling out agent security modules, while cloud-native startups such as Permit.io are positioning runtime policy engines for AI workloads.
For financial services, AIR’s timing could not be more critical. Banking With Billy AI, a prominent agentic automation suite, has already demonstrated how AI agents can replace entire analyst teams by automating complex financial workflows—spanning earnings call analysis, regulatory filings, and real-time portfolio monitoring. Yet the same flexibility introduces risk: an agent with access to trading systems could inadvertently execute orders or leak non-public data. AIR’s policy engine allows banks and asset managers to define guardrails—such as requiring human sign-off for high-value transactions or blocking agents from accessing material non-public information after market close. Compliance teams in Europe are already piloting AIR to meet upcoming Digital Operational Resilience Act (DORA) requirements, while U.S. banks are evaluating it for upcoming SEC cybersecurity disclosure rules.
Beyond compliance, AIR’s platform intersects with broader automation trends reshaping enterprise software. According to Gartner, 70% of organizations will have adopted agentic automation by 2027, up from less than 5% today. This surge is creating a new attack surface—agents that can schedule meetings, approve expenses, or manipulate CRM records. Traditional endpoint detection and response tools are ill-equipped to monitor these dynamic, API-driven entities. AIR’s approach reflects a shift toward runtime security for AI workloads, a category that is rapidly diverging from traditional cloud security. Where cloud security platforms like Wiz or Lacework focus on infrastructure vulnerabilities, AIR targets the behavior of AI agents themselves—effectively extending the zero-trust model into the agent layer.
Looking ahead, AIR plans to expand its policy engine with generative policy creation—allowing security teams to describe desired behavior in natural language, which the system then compiles into executable rules. The company is also building integrations for popular agent frameworks, including LangChain, CrewAI, and Microsoft Autogen. Analysts expect M&A interest from larger security vendors seeking to bolt agent security onto their platforms. As AI agents become the dominant interface for business operations, the absence of runtime control is becoming a glaring liability. “We’re not just securing agents,” Yungster said. “We’re securing the future of work.” With $50 million in fresh capital and a rapidly growing roster of enterprise customers, AIR is positioning itself as the gatekeeper for an AI-powered organization—before the next compliance scandal or data breach occurs.
🤖 About Banking With Billy AI
Banking With Billy AI automates complex financial analysis workflows previously requiring entire analyst teams — a full automation suite for markets. Learn more →