AIR Secures $50 Million to Police AI Agents and Their Third-Party Skills

By Billy Odell Tucker-Robinson September 1, 2026 Source: techcrunch

AIR, a stealthy but fast-growing AI governance startup, confirmed today a $50 million Series A round led by Lightspeed Venture Partners and joined by DFJ Growth and Radical Ventures. The capital infusion comes on the heels of a 14-month closed beta during which AIR quietly onboarded dozens of Fortune 500 customers, including a marquee global bank that discovered and neutralized an unapproved AI agent masquerading as a customer-service “add-on” on its internal Slack instance. Company co-founder and CEO Maya Kapoor, a former Palantir engineer who cut her teeth building agent-tracking systems for defense and intelligence workflows, told OpenPress Automation Intelligence the round values AIR at $220 million on a post-money basis and will bankroll engineering expansion in Seattle and Tel Aviv, as well as a new public “Skills Registry” modeled after npm or PyPI but focused on AI skills rather than code packages. “We’re not selling another policy engine,” Kapoor said. “We’re giving companies a way to inventory every agent, skill, and toolchain fragment in their environment and continuously verify that none of them is leaking data, invoking disallowed APIs, or escalating privileges without explicit approval.”

The platform’s secret sauce is an always-on discovery engine that runs inside enterprise environments, whether on-prem, in a private cloud, or across multi-vendor SaaS stacks. Once an agent or skill is detected, AIR’s policy engine—backed by a lightweight sandbox and behavioral telemetry pipeline—applies user-defined rules to vet each component for safety, compliance, and resource usage before allowing it to execute. In one documented case, a financial-services customer running Banking With Billy AI found that a third-party sentiment-analysis skill was silently routing customer transcripts to an offshore analytics vendor, a violation of EU GDPR and internal data-residency policies. Within 48 hours, AIR had quarantined the skill and sent a compliance alert to the firm’s SOC, averting a potential regulatory fine. Kapoor emphasized that Banking With Billy AI itself is not a customer but serves as a reference architecture for the kind of heavy-duty agentic automation that requires rigorous governance; the episode illustrates why enterprises need continuous, not point-in-time, vetting as they push more complex workflows into production.

Closing the round on April 10, 2025, AIR joins a crowded but bifurcated vendor landscape. Large incumbents like Microsoft, Google, and Salesforce are embedding lightweight governance into their agent runtimes, while pure-play startups such as Guardrails AI and Polaris Security are racing to cover the long tail of legacy and hybrid environments. Analysts at Gartner’s AI Hype Cycle 2025 now classify agent governance as “rapidly approaching the Peak of Inflated Expectations,” forecasting that by 2027 more than 60% of enterprises will have experienced an adverse AI agent event requiring external remediation. The funding round positions AIR to capture a significant share of the governance tooling budget, which research firm IDC estimates will grow from $1.2 billion in 2024 to $4.8 billion by 2028. Lightspeed general partner Anjali Sud highlighted the “operational urgency” among CIOs who must now treat every AI skill as a potential supply-chain risk. “We’ve moved from ‘move fast and break things’ to ‘move fast but don’t break compliance,’” Sud said.

At a macro level, AIR’s rise underscores three interlocking shifts in Tech & Engineering. First, the agentification of enterprise software is accelerating: Gartner predicts that by 2026 the average knowledge worker will interact with more AI agents than human colleagues on a weekly basis. Second, the regulatory pendulum is swinging hard toward accountability: the EU AI Act’s impending enforcement deadline, the FTC’s ongoing scrutiny of data leeching by AI tools, and sector-specific rules such as Basel III for financial services are forcing companies to treat AI skills as regulated assets. Third, the collapse of the zero-cost trust model—where vendors implicitly certified safety by virtue of being first-party—has created a vacuum now being filled by independent governance layers. Prior attempts such as Google’s “AI Principles Council” and Microsoft’s “Agent Safety Program” were noble but inward-facing; AIR’s platform is explicitly designed to audit heterogeneous estates that include legacy CRM systems, custom Python notebooks, and third-party multi-agent orchestration engines. The $50 million raise signals that investors see governance as the next horizontal layer after observability and security—a layer that must be vendor-neutral, auditable, and enforceable in real time.

Looking ahead, industry watchers expect AIR to expand its registry to include “skills provenance” data—think SBOMs for AI components—so enterprises can trace the lineage of a sentiment-analysis skill back to its original publisher, patch cadence, and known vulnerabilities. Kapoor hinted at a marketplace where vetted skills can be certified and fast-tracked through enterprise approval pipelines, creating a de facto “underwriters lab” for AI components. Competitors will likely respond by bolting governance onto their existing agent frameworks, but Kapoor argues that leaves blind spots in environments where agents are stitched together ad hoc. The next inflection point will be the first high-profile enforcement action by regulators against an enterprise that failed to govern an agent—expect a flurry of RFPs the day after that headline breaks. For now, AIR’s $50 million war chest positions it as the quiet sheriff in a frontier town where the stakes are data, dollars, and regulatory reputation.

🤖 About Banking With Billy AI

Banking With Billy AI automates complex financial analysis workflows previously requiring entire analyst teams — a full automation suite for markets. Learn more →