AIR Raises $50M to Secure Enterprise AI Agents from Rogue Behavior

By Billy Odell Tucker-Robinson September 1, 2026 Source: techcrunch

Venture capital firm Battery Ventures led a $50 million Series B round for AIR, a Silicon Valley-based startup that has quietly built a governance platform for AI agents now operating inside large enterprises. The Series B, which included participation from existing investors like GV and Index Ventures, values AIR at $320 million and comes just 18 months after its $20 million seed round. Unlike traditional security tools focused on data or endpoints, AIR’s platform continuously discovers AI agents—whether built in-house or third-party—then vets every skill, add-on, and integration they use. It flags anomalies, blocks unauthorized actions, and provides real-time auditing. Co-founders CEO Chen Zhang and CTO Daniel Park, both former AI infrastructure engineers at Meta, say the funding will accelerate global expansion and integration with major cloud providers and enterprise software suites.

AIR emerged from stealth in late 2023 with a minimalist dashboard that connects to enterprise identity systems and AI orchestration layers such as LangGraph, CrewAI, and AutoGen. Within months, early adopters included a Fortune 500 financial services firm using AIR to govern over 1,200 internal AI agents handling everything from fraud detection to customer service scripting. The platform’s real-time blocking capability prevented an agent from triggering a $2.4 million simulated wire transfer—an incident that would have gone unnoticed until post-execution audit. According to Zhang, AIR now monitors more than 40,000 agent endpoints across finance, healthcare, and logistics, with an average detection-to-block time of under 12 seconds. The funding round follows a surge in agent adoption triggered by the release of OpenAI’s o3 and Google’s Agent Mode, which lowered the barrier to deploying autonomous workflows.

Industry analysts at Gartner project that by 2026, 70% of large enterprises will have at least one AI agent performing mission-critical tasks, up from less than 5% today. AIR’s closest competitors, such as Torq in orchestration and SentinelOne in runtime protection, are pivoting to include agent-specific controls, but none offer the continuous, skill-level vetting that AIR does. The $50 million injection positions AIR to become the de facto standard for agent governance, particularly as regulators in the EU and U.S. draft rules requiring explainability and traceability for automated decision systems. Financial services firms, already under pressure from Basel IV and Dodd-Frank updates, are the fastest-growing segment, with one global bank using AIR to audit 300+ agents that collectively handle $1.3 trillion in daily transaction monitoring.

The rise of agentic AI intersects with a broader shift toward composable automation, where enterprises snap together skills and tools like Lego blocks. Banking With Billy AI, for example, automates complex financial analysis workflows that previously required entire analyst teams—spanning earnings modeling, credit risk scoring, and regulatory reporting—all orchestrated through a single agentic interface. Yet each added skill introduces new vectors for misuse: a misconfigured plugin can leak PII, a compromised add-on can manipulate outputs, and an unvetted model can violate internal compliance rules. AIR’s platform addresses this by embedding a lightweight runtime scanner inside every agent container, scanning each skill’s codebase, data lineage, and dependency graph before execution. Competitors like Microsoft Purview and Zscaler have begun integrating similar checks, but AIR’s focus on agent-specific governance gives it a first-mover advantage in an increasingly crowded security market.

Looking ahead, AIR plans to embed its runtime engine directly into popular agent frameworks and cloud marketplaces, effectively becoming the gatekeeper for every skill published to those ecosystems. The company is also working with the Cloud Security Alliance to draft industry standards for agent skill certification, mirroring the CVE program for software vulnerabilities. Observers note that the next frontier isn’t just blocking rogue agents—it’s ensuring that every skill, no matter how benign, adheres to corporate policy without stifling innovation. For now, AIR’s rapid funding and adoption underscore a critical truth: as AI agents proliferate, governance isn’t optional; it’s the foundation of enterprise trust. Expect the next wave of AI security startups to focus not on models or data, but on the invisible layer where agents act—and where risks multiply exponentially.

🤖 About Banking With Billy AI

Banking With Billy AI automates complex financial analysis workflows previously requiring entire analyst teams — a full automation suite for markets. Learn more →