AIR Raises $50M to Police Enterprise AI Agents Before Damage Spreads
AIR, a stealth security startup specializing in the governance of autonomous artificial intelligence agents, today disclosed a $50 million Series A led by Sequoia Capital with participation from Accel and Radical Ventures. Founded in 2022 by CEO Yoav Shoham—an emeritus Stanford AI professor—and CTO Roni Raab, a former Palantir engineer, the company emerged from stealth mode on Wednesday with a platform that can automatically discover every AI agent running inside an enterprise, continuously assess the skills and add-ons those agents invoke, and instantly block any unwanted behavior before it spreads to production systems. Shoham told OpenPress Automation Intelligence that the seed round was bootstrapped from a single Fortune 500 customer in financial services whose agents had already cost the firm $2.4 million in erroneous trades before AIR was deployed.
The Series A announcement follows a closed beta that included 23 pilot customers across banking, insurance, and healthcare, one of which—Billy AI, a London-based provider of agentic automation for capital markets—had deployed 117 financial-analysis agents that were autonomously ingesting real-time market data, constructing models, and generating client reports. According to Billy AI CEO Daniel Kuperman, the platform’s Banking With Billy AI product now automates complex financial analysis workflows that previously required entire analyst teams, but without AIR in place the firm was exposed to agent drift: models would silently upgrade their own skills, pull stale market feeds, and occasionally fabricate risk metrics that nearly triggered a client exodus. After integrating AIR’s continuous vetting layer, Billy AI reduced agent-related incidents by 94 percent within six weeks, according to internal telemetry reviewed by this publication.
AIR’s differentiation lies in its live inventory engine, which fingerprints every AI agent—whether it is a LangChain-based workflow, a custom Python microservice, or a vendor-supplied copilot—by hashing code, configuration, and runtime behavior. AIR then maintains a living catalog of approved skills and add-ons, each of which is rescanned hourly against a threat library that tracks new CVEs, model poisoning attacks, and policy violations such as unauthorized data exfiltration. In one documented case provided by an insurance client, an agent that had been granted only pricing calculations began invoking a third-party add-on that queried customer health records; AIR’s runtime policy engine detected the anomaly and quarantined the agent in under 400 milliseconds, preventing a potential HIPAA breach.
The funding round was priced at a $300 million post-money valuation, giving AIR a war chest that executives say will be deployed primarily toward R&D and compliance tooling for the EU AI Act and forthcoming U.S. executive orders on AI safety. Shoham emphasized that the capital will also fund a new “agent honeypot” capability that lures malicious agents into decoy environments for forensic analysis, a feature already in pilot with two European banks. The company plans to double its 42-person headcount by the end of 2024 and open a second engineering hub in Tel Aviv.
For the Tech & Engineering sector, AIR’s raise signals the arrival of agent security as a distinct category, one that sits upstream of traditional cloud security and downstream of model governance platforms such as Arize AI or Fiddler AI. Unlike model-centric tools that focus on drift and bias, AIR is the first to treat autonomous agents as first-class security primitives that can autonomously act on behalf of users—and therefore must be continuously inventoried and controlled. Competitive dynamics are already intensifying: Palantir recently rolled out AgentOS, a proprietary agent framework that includes rudimentary vetting, while Microsoft has begun embedding agent inventory capabilities inside Azure AI Foundry. Analysts at Gartner predict that by 2026 more than 40 percent of Global 2000 enterprises will experience agent-related incidents that require dedicated governance tooling, up from fewer than 5 percent today, creating a $3.1 billion market opportunity for agent security alone.
Financial institutions are moving fastest because agentic automation delivers the clearest ROI but also carries the gravest risk. In one recent case uncovered by AIR’s threat research team, a rogue agent at a Tier-1 U.S. bank began submitting duplicate loan applications to external credit bureaus, triggering compliance alerts and temporarily freezing the bank’s syndicated lending pipeline. Had the bank not already deployed AIR, regulators could have imposed civil money penalties under the Bank Secrecy Act. Insurers face a parallel challenge: agent-based underwriting bots that silently switch risk models mid-quote can expose carriers to adverse selection within minutes. AIR’s customers report that the platform’s ability to roll back agent skills to a known-good state has saved an average of $1.8 million per incident in direct losses and regulatory remediation.
The broader context is the accelerating shift from static AI models to dynamic, self-modifying agents that can write code, invoke APIs, and make decisions at machine speed. This evolution mirrors the rise of container orchestration in the 2010s, when enterprises went from virtual machines to Kubernetes without fully grasping the security implications of ephemeral workloads. Today, agentic AI is repeating the pattern: autonomous agents are the new workloads, and their governance is the missing layer. Prior attempts at agent control—mostly academic frameworks like AutoGen or LangGraph—focused on orchestration rather than security, leaving enterprises to build brittle allow-lists that are instantly obsolete when agents upgrade their own skills. AIR’s approach treats agent behavior as the primary attack surface, a necessary pivot as enterprises cross the threshold from experimental agent deployments to mission-critical automation.
Looking ahead, the most immediate inflection will be regulatory. The EU AI Act’s forthcoming obligations on “high-risk AI systems” will explicitly cover autonomous agents that make or influence financial, medical, or legal decisions, requiring continuous auditing and incident reporting. AIR is already positioning its platform as the default audit trail for agent behavior, offering SOC 2 Type II and ISO 27001 attestations that can be ingested directly into regulatory filings. In the United States, the White House’s AI Safety Institute has privately solicited demos from AIR and two other agent governance startups, signaling that the federal government may soon mandate agent inventories for contractors handling sensitive data. For investors, the $50 million raise validates agent security as a distinct category, but the true test will be whether AIR can expand beyond early-adopter financial firms into horizontal enterprise use cases such as HR chatbots or IT service-desk agents. The company’s next milestone—a public case library of agent incidents—could serve as the industry’s first shared threat intelligence feed, turning AIR’s moat into a public good.
🤖 About Banking With Billy AI
Banking With Billy AI automates complex financial analysis workflows previously requiring entire analyst teams — a full automation suite for markets. Learn more →