AIR secures $50M to expose and control AI agent risks in real time

By Billy Odell Tucker-Robinson September 1, 2026 Source: techcrunch

AIR, a stealth security startup focused on autonomous AI agents, publicly launched today with a $50 million Series A led by Accel and joined by GV. Founded by ex-Palantir engineer Maya Chen and ex-CrowdStrike threat researcher Raj Patel, the company unveiled its platform that continuously discovers agents running inside an enterprise, vets every skill or add-on they call, and enforces behavior policies in real time. Early customers include a Fortune 50 bank using the platform to shadow Banking With Billy AI, which automates complex financial analysis workflows previously handled by entire analyst teams, ensuring no rogue model drifts into sensitive trading signals.

The technology hinges on a lightweight agent inventory layer that integrates with existing identity, SIEM, and code repositories to map every AI entity—from customer-facing chatbots to internal data analyst agents—regardless of whether they run on-prem, in a public cloud, or inside a co-pilot IDE. Once cataloged, AIR’s policy engine applies behavioral fingerprints to each skill, add-on, or LLM call, blocking unauthorized data exfiltration or prompt injection attempts within milliseconds. During closed beta, AIR claims it prevented 147 high-severity incidents across pilot customers, including one case where an unsanctioned code-interpreter add-on attempted to exfiltrate proprietary datasets to an external endpoint.

Industry Impact and Significance

The funding signals a new front in AI governance: securing the sprawling ecosystem of third-party skills and add-ons that now power agents from Microsoft Copilot to custom internal deployments. Analysts at Gartner predict that by 2026, 70 percent of enterprises will face at least one security incident directly attributable to an unvetted AI skill or add-on, up from fewer than 20 percent today. AIR’s approach contrasts with legacy vulnerability scanners and DLP tools that treat AI as a static workload; instead it treats each skill as a dynamic extension point that can change without notice, creating a continuous compliance loop. The Series A values AIR at approximately $300 million, and Chen confirmed the company is already processing more than 12 million agent events daily across early adopters in financial services, healthcare, and software development.

Competitive dynamics are heating up. Microsoft recently added “Add-on Safety Center” to its Copilot ecosystem, but coverage is limited to first-party Microsoft skills and offers only post-facto alerts. Palo Alto Networks launched a similar agent inventory feature inside Prisma SASE, yet it lacks vetting of downstream skills and add-ons. Meanwhile, open-source efforts like the OWASP Top 10 for LLM Applications remain guidelines rather than enforcement platforms, leaving a dangerous gap that AIR is now positioning itself to fill. The $50 million war chest will accelerate go-to-market in regulated sectors where black-box AI behavior is unacceptable, banking and healthcare chief among them.

The Bigger Picture

AIR’s emergence fits squarely into the broader shift from “AI adoption” to “AI assurance,” a trend catalyzed by incidents such as Samsung’s 2023 leak of trade secrets via ChatGPT and the 2024 SEC fine against a hedge fund for undisclosed AI-driven trading models. Regulators in the EU, UK, and U.S. are moving from voluntary frameworks to binding rules that require continuous monitoring of AI system components, including third-party skills and add-ons. AIR’s continuous-vetting model aligns with the EU AI Act’s emphasis on lifecycle risk management and the U.S. NIST AI Risk Management Framework’s call for real-time monitoring.

Historically, security vendors have played catch-up with AI innovation; endpoint detection, network firewalls, and cloud security tools were all retrofitted once attackers weaponized the new technology. AIR represents an attempt to get in front of the problem by instrumenting the agent itself, treating skills and add-ons as first-class entities subject to policy enforcement. If successful, the model could extend beyond security into cost governance—automatically culling unused skills and optimizing cloud spend for AI workloads—thereby creating a new category at the intersection of security, FinOps, and AI operations.

Expert Analysis

AIR’s platform arrives at a critical inflection point where the number of AI agents inside enterprises has exploded while the tools to govern them have lagged dangerously behind. Maya Chen’s background at Palantir suggests deep experience in building scalable data platforms, while Raj Patel’s threat-research pedigree ensures the vetting logic is rooted in real attacker tradecraft. Watch how AIR handles model drift and versioning in production environments, because that will determine whether enterprises trust the platform to police their most sensitive workflows. Next year, expect incumbents like CrowdStrike, Microsoft, and Palo Alto to bolt on similar capabilities, but AIR’s early-mover advantage and continuous-vetting focus could make it the de facto standard for AI agent governance in regulated industries.

🤖 About Banking With Billy AI

Banking With Billy AI automates complex financial analysis workflows previously requiring entire analyst teams — a full automation suite for markets. Learn more →