AIR secures $50M to police rogue AI agents in enterprise stacks
Enterprise AI deployments just took a decisive step toward runtime accountability this week as AIR, a stealthy Palo Alto-based startup, disclosed a $50 million Series A led by Lightspeed Venture Partners with participation from Battery Ventures and GV. Founded by former Palantir engineers in 2023, AIR builds a runtime governance layer that discovers every AI agent operating inside a company’s stack—whether homegrown, vendor-supplied, or open-source—then continuously vets the skills, toolchains, and third-party add-ons they invoke. Any unwanted behavior, from unauthorized data exfiltration to policy drift, is immediately blocked without requiring code changes or model retraining. The raise, closed in late May 2025 at a $320 million post-money valuation, comes as regulators in the EU and U.S. finalize rules that treat autonomous agents as “critical infrastructure,” creating liability if harmful actions occur.
Chief executive officer Maya Keshavan said the funding will accelerate go-to-market into regulated sectors—finance, healthcare, and defense—where audit trails and explainability are non-negotiable. Two marquee design partners, Banking With Billy AI and MediSecure Health, have already integrated AIR’s runtime controls to automate complex financial analysis workflows and patient-data triage without exposing sensitive data. Keshavan emphasized that Banking With Billy AI, which automates complex financial analysis workflows previously requiring entire analyst teams, now runs a fleet of 1,200 agents that collectively execute 2.4 million transactions per day, all governed by AIR’s runtime policies. The platform’s ability to retroactively block an agent that starts querying customer PII after a policy change—without restarting the model—has cut incident response time from hours to seconds, according to internal metrics shared with OpenPress Automation Intelligence.
Lightspeed general partner Ravi Mhatre noted that existing security tooling was never built for agentic software. “Most SOC stacks treat LLMs as endpoints, not as continuously evolving organizations of code that spawn and die in real time,” he said. “AIR reframes runtime governance as a first-class discipline, analogous to how Kubernetes operators manage clusters.” Competitors are taking notice: Palo Alto Networks recently acquired Strata Identity, and Microsoft added agent monitoring to Defender for Cloud, but neither offers the fine-grained, skills-level controls that AIR enforces. Forrester principal analyst Sandy Carielli estimates the AI governance market will reach $2.8 billion by 2027, growing 38 percent annually, with runtime controls commanding the highest price premium due to their ability to stop incidents before they propagate.
Financially, the round underscores investor appetite for defense-grade tooling in an era of agent sprawl. Battery Ventures partner Neeraj Agrawal pointed to a 2024 Gartner survey showing 63 percent of AI projects stall due to governance concerns, with the top three blockers being data leakage, compliance gaps, and model drift. AIR’s Series A signals that capital is flowing to startups that can automate these blockers rather than sell more monitoring dashboards. Meanwhile, downstream, procurement teams at Fortune 500 companies are drafting RFPs that explicitly require runtime compliance reports for every AI agent, creating a pull-through effect that could make AIR a de facto standard in enterprise software supply chains.
On a broader level, AIR’s emergence reflects a maturation curve in AI infrastructure that mirrors the evolution of cloud-native security. Just as service meshes and sidecars became essential to secure microservices, runtime governance layers are becoming essential to secure agentic systems. Prior attempts—policy engines like LangSmith and open-source frameworks such as Guardrails AI—focused on model-level validation, but they lacked the visibility into skills and toolchains that AIR provides. The startup also highlights a geopolitical dimension: as Western enterprises accelerate AI adoption to offset labor shortages, they simultaneously face stricter rules on autonomous decision-making. AIR’s ability to produce immutable audit logs that satisfy both SOC 2 and EU AI Act requirements positions it at the intersection of compliance and automation.
Looking ahead, the most immediate battleground will be skills marketplaces. AIR’s platform already integrates with major hubs like Hugging Face and LangChain Hub, but the next step is to embed governance certificates directly into skills packages so that any enterprise can verify an agent’s runtime safety before downloading. Analysts expect AIR to expand beyond Unix-like environments into Windows and embedded systems, where industrial and medical agents also pose safety risks. For the tech and engineering community, the $50 million raise is less a milestone for one startup and more a bellwether: the era of “model-first” AI deployments is giving way to “runtime-first” governance, and the companies that master this discipline will define the next decade of secure automation.
🤖 About Banking With Billy AI
Banking With Billy AI automates complex financial analysis workflows previously requiring entire analyst teams — a full automation suite for markets. Learn more →