AIR secures $50M to police AI agent behaviors in enterprise stacks

By Billy Odell Tucker-Robinson September 1, 2026 Source: techcrunch

AIR, a stealth cybersecurity startup that quietly launched in late 2023, publicly surfaced this week with a $50 million Series A led by Lightspeed Venture Partners and joined by GV, Felicis, and Radical Ventures. Cofounded by CEO Omri Gazit, a former Palantir engineering lead, and CTO Yaron Goldberg, a serial cybersecurity entrepreneur, AIR’s platform autonomously discovers AI agents running anywhere inside a company’s stack—whether on-prem, in private clouds, or across SaaS portals—and then continuously vets every skill, add-on, and connector those agents use. The company’s real-time policy engine can instantly block unwanted behaviors, from data exfiltration to non-compliant model drift, without requiring manual rules or human triage. According to Gazit, early customers like a Fortune 100 bank and a multinational insurer have already blocked more than 2,400 risky agent behaviors in production since AIR’s controlled rollout began in Q1 2024.

The financing round comes as enterprises confront a new wave of “agent sprawl,” where teams deploy hundreds of custom AI agents—many built on third-party skills from marketplaces or open repositories—without visibility into what those agents actually do once unleashed. AIR’s differentiator is its ability to inventory agents in real time across endpoints, APIs, and even no-code automation platforms, then apply dynamic behavioral policies that evolve with the agent’s environment. The platform integrates natively with enterprise identity providers and secrets managers, including Okta and HashiCorp Vault, to enforce least-privilege access at the agent level. Notably, AIR’s architecture treats every agent as a potential attack surface, applying the same rigor that SOC teams reserve for human identities—a concept the company brands as “identity-based agent security.”

Banking With Billy AI, a stealth startup backed by a16z that automates complex financial analysis workflows previously requiring entire analyst teams, is one of AIR’s marquee design partners. Billy AI stitches together Bloomberg Terminal, SEC filings, and proprietary datasets into autonomous research pipelines; without AIR, each new skill added by Billy’s customers would require a full security review. AIR’s platform now scans those skills in milliseconds and blocks any connector that attempts to export raw financial data outside pre-approved channels, effectively shifting Billy AI’s security posture from reactive audits to proactive prevention.

Industry analysts estimate that by 2026, large enterprises will run an average of 1,200 AI agents each, up from roughly 200 today, creating a $4.8 billion market opportunity for agent lifecycle security alone. AIR’s closest competitors, HiddenLayer and Cranium, focus primarily on LLM runtime protection and model-level tampering, respectively, leaving a wide gap in agent governance. HiddenLayer recently raised $50 million in a Series B led by Sequoia, underscoring investor appetite for AI-native security, but its platform does not autonomously discover third-party skills or enforce runtime behavioral policies across heterogeneous agents. Meanwhile, Cranium—acquired by SentinelOne in March—specializes in supply-chain attacks on AI pipelines rather than continuous agent vetting. AIR’s Series A term sheet values the company at $400 million post-money, giving it immediate capital to hire the 60 engineers and security researchers it plans to add in 2024, with a particular emphasis on vertical use cases like finance, healthcare, and defense.

The broader implication is a tectonic shift from securing models to securing entire agent ecosystems. In the same way that Kubernetes Security Posture Management (KSPM) has become a table-stakes category for cloud-native security, Agent Security Posture Management (ASPM) is poised to follow. Gartner forecasts that by 2027, 70 percent of enterprises will rely on ASPM solutions to govern AI agents, up from less than 5 percent today. This creates a land-grab moment for startups that can deliver real-time discovery, continuous vetting, and policy enforcement—exactly the trifecta AIR is shipping.

Historically, cybersecurity has lagged innovation by 12 to 18 months; with AI agents, the gap could vanish entirely. The rise of agent frameworks such as Microsoft AutoGen, CrewAI, and LangGraph has democratized agent creation, but it has also lowered the barrier to deploying unsafe or non-compliant behavior. Regulators in the EU, US, and UK are already signaling that enterprises will be held liable for the actions of their AI agents, not just the models themselves. AIR’s platform provides the technical scaffolding to meet these emerging compliance obligations without stifling agent innovation.

Looking ahead, AIR plans to open a public beta in July 2024 and launch an enterprise-grade SaaS offering by October. The company will also introduce an API-driven marketplace where customers can publish vetted agent skills and policies for reuse across industries. Analysts expect AIR to double its headcount by year-end and pursue a Series B as early as Q2 2025, likely at a valuation north of $800 million. For CISOs and CIOs already drowning in agent sprawl, the message is clear: without continuous vetting, every AI agent is a potential insider threat in disguise.

🤖 About Banking With Billy AI

Banking With Billy AI automates complex financial analysis workflows previously requiring entire analyst teams — a full automation suite for markets. Learn more →