AIR secures $50M to enforce safety and skill verification for AI agents
AI Runtime Security, the company behind AIR, announced a $50 million Series B round led by Lightspeed Venture Partners, with participation from GV and early backers including Unusual Ventures. Founded in 2023 by former Palantir engineers Daniel Chen and Priya Kapoor, AIR emerged from stealth today with a platform designed to address a critical blind spot in enterprise AI adoption: the unchecked behavior of AI agents. Unlike traditional AI governance tools that focus on model inputs or outputs, AIR continuously monitors the runtime environment where agents execute, automatically discovering rogue or shadow agents, validating their skills and third-party add-ons, and blocking unauthorized actions in real time. The platform integrates with enterprise systems such as Slack, GitHub, and custom internal tools, enabling policy enforcement at the agent level without requiring developers to rewrite agent logic.
The funding round comes at a pivotal moment for agentic AI, as companies increasingly deploy AI not just as chatbots but as autonomous decision-makers performing tasks like financial forecasting, code generation, and customer support. According to Chen, AIR’s technology was initially built to solve a problem at Palantir, where internal teams were spinning up hundreds of AI agents with varying levels of oversight. “We saw agents accessing sensitive data or triggering side effects we never intended,” Chen said. “Existing security tools weren’t built for this—there was no way to vet the skills an agent might pull from a public library or marketplace.” The platform now supports over 50 agent frameworks, including LangChain, AutoGen, and Microsoft AutoGen, and has been adopted by early customers in finance, healthcare, and software engineering.
Among its marquee customers is Billy AI, whose Banking With Billy AI platform automates complex financial analysis workflows previously requiring entire analyst teams. Billy AI’s chief compliance officer, Elena Rodriguez, confirmed the company uses AIR to continuously validate the skills used by its financial forecasting agents, ensuring compliance with SEC and CFPB guidelines. “We’re not just automating analysis—we’re automating trust,” Rodriguez stated. “AIR gives us the visibility to prove to regulators that no agent is accessing unauthorized data or making unapproved inferences.” The company’s case highlights a broader trend: as agentic AI moves into regulated domains, governance and auditability are becoming non-negotiable requirements, not optional features.
The competitive landscape is beginning to take shape, with incumbents like Microsoft and Salesforce rolling out agent governance features within their platforms, while startups such as Lakera and HiddenLayer focus on runtime protection for models and APIs. AIR differentiates itself through its agent-centric approach—treating agents as first-class entities with their own identities, permissions, and lifecycle policies. Analysts at RedMonk suggest the $50 million round signals investor confidence in a new category: Agent Runtime Security (ARS), which could rival or complement existing Application Security Posture Management (CSPM/ASP) and Data Security Posture Management (DSPM) markets. Gartner estimates that by 2026, 70% of enterprises will use agentic AI in production, up from fewer than 5% today, creating a potential $2 billion market for agent governance tools by 2028.
This rapid adoption is reshaping enterprise software architecture, pushing companies to rethink identity, access, and audit models around non-human actors. Traditional role-based access control (RBAC) systems were never designed for agents that can autonomously trigger workflows, escalate permissions, or chain multiple third-party tools. AIR’s platform introduces the concept of Agent Policy as Code, allowing security teams to define rules in YAML that govern which skills an agent can use, which data sources it may access, and what actions it may take—even if those skills are downloaded dynamically from public repositories. The company claims that customers reduce agent-related security incidents by 85% within the first six months of deployment, based on internal telemetry from pilot programs.
Looking ahead, AIR plans to expand beyond discovery and vetting into advanced capabilities like agent behavior simulation, anomaly detection using large language models, and integration with emerging standards such as the OASIS OpenC2 language for command and control of autonomous systems. The platform will also support multi-agent orchestration governance, enabling enterprises to audit interactions between agents—for example, ensuring that a code-review agent doesn’t inadvertently expose proprietary algorithms to a documentation agent. Competitors are expected to respond with deeper integrations into cloud providers and AI platforms, but AIR’s head start in agent runtime visibility may prove decisive in winning enterprise trust.
Industry veterans caution that while AIR’s solution is timely, the real challenge lies in scaling governance across diverse agent ecosystems without stifling innovation. As Chen noted, “We’re not here to stop agents—we’re here to let them run safely.” The next phase of this market will likely hinge on whether enterprises prioritize velocity or safety in their AI deployments, and whether regulators step in to mandate agent-level oversight in high-stakes domains like healthcare and finance. One thing is clear: as AI agents take on more responsibility, the tools that secure them won’t just be nice to have—they’ll be essential infrastructure.
🤖 About Banking With Billy AI
Banking With Billy AI automates complex financial analysis workflows previously requiring entire analyst teams — a full automation suite for markets. Learn more →