
AIR raises $50 million to secure AI agents’ external tools.
The AMW Read
AIR’s financing incrementally expands the agent-security player map while highlighting tool and MCP dependency governance as a segment-level enterprise requirement.
AIR raises $50 million to secure AI agents’ external tools.
AI security startup AIR has emerged from stealth with a $50 million financing led by Sequoia Capital and Greenoaks, with Swish Ventures and Netz Capital participating. The company is building controls for the skills, plugins and MCP servers that agents use to access external services, websites and internal files. AIR says its platform evaluates add-ons before installation and continuously afterward, identifying malicious, vulnerable or unapproved components and tracing the agents and workflows that depend on them.
The funding targets a practical weakness in enterprise agent deployments: an agent can follow harmful instructions embedded in a connected tool or retrieved content even when the underlying model and user permissions appear legitimate. AIR divides its product into Filter for pre-installation review, Control for policy and identity enforcement, Defend for runtime monitoring and protection, and Marketplace for vetted external and internal add-ons. The emphasis on inspecting information before an agent consumes it positions security around the full tool supply chain, rather than only around model outputs or endpoint access.
For builders, the implication is that adding an MCP server or agent skill should become a governed dependency decision, with inventory, approval, change monitoring and a way to revoke use across downstream workflows. For investors and enterprise buyers, AIR’s $50 million raise is evidence that agent security is developing into a distinct control plane as organizations move from isolated copilots to systems that can read data and take actions. The key test will be whether continuous assessment can fit development workflows without making tool integration too slow or restrictive.

