AIR said on September 1, 2026 that it has raised $50 million and come out of stealth with a product it calls an inline firewall for AI agents. Sequoia Capital and Greenoaks led the round. Swish Ventures and Netz Capital also participated. The company published a matching founder note the same day.

The problem AIR is selling is context, not the network perimeter. Agents now install tools, read files and mail, browse the web, and act in internal systems. A poisoned add-on or a page with hidden instructions can change what the agent does next. AIR says security teams still have little view of what is influencing those decisions.

Its own research, cited in the launch, found more than 17,800 public AI add-ons, covering about 6.7 million installations, that relied on untrusted external instruction sources. In a separate finding, it said it uncovered AI skills in the wild that impersonated brands including Anthropic and OpenAI to skip platform reviews and run arbitrary code.

What the product claims to do

AIR says it continuously discovers skills, plugins, MCP servers, and other add-ons across an organization’s agent supply chain, before and after they go live. If an add-on is malicious, vulnerable, or unapproved, security teams can trace every agent that depends on it and revoke it. The company also plans a marketplace of pre-vetted add-ons.

Yair Saban, co-founder and chief executive, said enterprises already have a firewall for the network and now need one for what enters an agent’s context. Niv Hoffman is the other co-founder. Ryan Knisley, formerly CISO at The Walt Disney Company and Costco Wholesale, joined as chief strategy officer.

“Every enterprise has a firewall protecting its network. Now they need one protecting their AI agents. AI agents need a new kind of firewall, one that protects what enters their context.” Yair Saban, co-founder and CEO, AIR

Decoded Take

Agent security is filling up with startups that rename yesterday’s web proxy. AIR’s sharper claim is inventory: find the skill, say whether it is trusted, and pull it from every agent at once. That only matters if the company can see Claude Code, Cursor, MCP servers, and internal tools without becoming the next broker that developers disable. Sequoia and Greenoaks are paying for a category, not a feature. Watch whether a named enterprise publishes a revoke story, whether the marketplace is more than a list of blessed plugins, and whether AIR’s own research keeps turning up impersonated skills after launch. If the product cannot sit inline without breaking a coding agent, it will live in a quarterly slide. If it can cut a bad MCP server out of production in an afternoon, the firewall metaphor holds.