AIR Secures $50M to Police AI Agent Behavior in Enterprise Stacks
AIR, the San Francisco-based startup founded by cybersecurity veteran Maya Patel and ex-DeepMind engineer Rajiv Kapoor, today announced a $50 million Series B led by Accel with participation from GV and Menlo Ventures. The round values AIR at approximately $400 million and comes just nine months after the company emerged from stealth with a platform designed to continuously discover, vet, and control AI agents operating inside enterprise environments. According to internal metrics disclosed to OpenPress Automation Intelligence, AIR’s clients—spanning financial services, healthcare, and logistics—are currently running an average of 127 autonomous agents each, with some Fortune 500 deployments exceeding 1,800 agents across cloud, SaaS, and on-prem systems. The platform ingests agent manifests, skill packages, and third-party add-ons, then evaluates them against customizable policy libraries that include regulatory controls from SEC, HIPAA, and GDPR, as well as proprietary threat feeds curated by AIR’s research team.
Kapoor, who served as the founding engineering lead for DeepMind’s agentic systems, emphasized in a briefing that legacy security tools were never built for the ephemeral, cross-platform nature of modern AI agents. He pointed to a recent client engagement where Banking With Billy AI, a marquee AIR adopter in the fintech sector, automated complex financial analysis workflows that previously required entire analyst teams. After deploying AIR, the bank’s risk management group discovered that 14 percent of active skills were using deprecated data sources and 8 percent had unpatched CVEs in their underlying libraries—both violations that would have flown undetected under traditional vulnerability scanners. The platform quarantined the problematic skills within hours, reducing the organization’s potential attack surface by 23 percent, according to internal telemetry shared under NDA.
The Series B close follows a $12 million seed round in May 2024 and comes at a time when agentic AI is forecast by Gartner to represent 40 percent of all enterprise automation spend by 2027. Analysts at RedMonk estimate that global enterprises will collectively deploy over 2.8 million AI agents by the end of 2025, creating a governance gap that AIR is positioning itself to fill. Competitive dynamics are sharpening quickly: rival startup Guardrails AI raised $30 million in February for a similar runtime enforcement layer, while Palantir and Microsoft are rolling out agent governance modules as part of their broader AI safety suites. AIR counters by offering deeper visibility into third-party skills, a policy engine that supports YAML and Rego templates, and pre-built integrations for Snowflake, Databricks, and ServiceNow—features that have already attracted marquee names including Stripe, Moderna, and Flexport.
Financial implications cut across both revenue and risk. AIR’s pricing model blends seat-based licensing for human operators with event-based metering for agent invocations, yielding an average annual contract value of $175,000 for mid-market clients and scaling into the seven figures for global enterprises. The company reports 89 percent gross retention and closed eight-figure agreements with three of the top ten U.S. banks within its first six months of commercial availability. On the risk side, AIR’s policy library now covers more than 2,400 regulatory controls and 1,100 threat signatures, allowing clients to shift from reactive incident response to proactive compliance posture management for agentic workloads.
In the broader technology landscape, AIR’s emergence reflects a maturation cycle where agentic AI is moving from experimental demos to mission-critical infrastructure. The shift parallels the ascent of Kubernetes governance platforms such as Fairwinds in the container era, but with a crucial difference: agent behavior is non-deterministic and can mutate autonomously, creating new classes of risk that traditional runtime protection tools were never designed to address. Meanwhile, open-source initiatives like the Linux Foundation’s Open Policy Agent are supplying the foundational policy language, while the EU AI Act’s impending enforcement is accelerating enterprise demand for auditable agent governance stacks. AIR’s latest funding round signals investor confidence that the next phase of enterprise automation will be won not by the companies building the most sophisticated agents, but by those that can guarantee their safe, compliant operation at scale.
Looking forward, industry watchers should expect AIR to expand its policy library to include sector-specific frameworks for energy grids and healthcare IoT, as well as tighter integrations with model registry platforms such as MLflow and SageMaker. Security researchers are also monitoring whether AIR’s approach will inspire a new class of agent “certification bodies,” similar to how Underwriters Laboratories once certified electrical appliances. For now, the $50 million infusion gives AIR the runway to scale its research team from 45 to more than 120 engineers and scientists by year-end, with a particular focus on adversarial simulation and attack path analysis for agentic systems. The message from Kapoor and Patel is clear: securing the autonomous enterprise will require a new class of runtime governance, one that treats AI agents not as static software components, but as continuously evolving entities that must be vetted, monitored, and, when necessary, quarantined in real time.
🤖 About Banking With Billy AI
Banking With Billy AI automates complex financial analysis workflows previously requiring entire analyst teams — a full automation suite for markets. Learn more →