Enterprise adoption of autonomous artificial intelligence systems is rapidly progressing beyond basic chatbots and conversational interfaces directly into operational IT environments. As enterprises grant these models broad permissions to query corporate data stores and execute workflows across the open web, organizations are hooking them into a chaotic web of third-party plugins, custom skills, and Model Context Protocol (MCP) servers. This rapid, unvetted expansion creates an unmonitored software supply chain where autonomous software routinely executes untrusted external code without baseline perimeter controls. Against this backdrop, cybersecurity startup AIR emerged from stealth backed by $50 million across two consecutive seed rounds specifically to audit, intercept, and police the tools AI agents consume.
The Kernel Analogy and Attack Vectors
AIR was founded by CEO Yair Saban and CTO Niv Hoffman, both veterans of Israel’s Unit 8200 intelligence corps where they specialized in offensive cyber operations. Saban draws a direct parallel between the current Wild West of AI agent extensions and the early vulnerabilities of personal computing operating systems, where unverified third-party drivers loaded directly into the system kernel before mandatory cryptographic signing became industry standard.
"In the early 2000s, whenever you installed a driver, the driver didn't need to be signed. Today, every time you install a driver, you see a signature saying who signed it, because the driver is actually loading code into the kernel. You don't have that with skills or plugins or MCPs, and it's a shame, because it's the same mechanism, it's the same lesson, but we haven't learned it."
As Saban explained to TechCrunch, the attack surface changes fundamentally once autonomous systems begin executing workflows across enterprise boundaries. Threat actors no longer need to compromise the underlying foundation model. Instead, adversaries can poison external dependencies, documentation, or skills fetched on the fly. If an agent ingests an untrusted skill or connects to a rogue MCP server, it executes hostile payloads with full enterprise access credentials.
In practical terms, when an employee instructs an agent to automate data synthesis, that agent autonomously pulls auxiliary tools and connects to external servers. If an attacker hijacks or quietly tampers with one of those endpoints, the agent acts as an authorized internal backdoor into company databases.
Continuous Verification and Market Momentum
To counter this exposure, AIR developed an inspection platform that continuously discovers active agents across enterprise networks, identifies unapproved extensions or shadow employee accounts, and enforces runtime interception to evaluate actions before execution. The platform matches attempted agent operations and skill installations against a verified organizational whitelist, shifting corporate defense from traditional network perimeters to continuous behavioral verification.
Sequoia led AIR's initial $10 million seed round, followed weeks later by a $40 million round led by Greenoaks, with participation from Swish, Netz, Cognition president Zach Frankel, Wiz co-founder Yinon Costica, Eon co-founder Ofir Erlich, Clay co-founder Varun Anand, Anne Neuberger, and Omer Adam. For C-suite leaders accelerating autonomous agent deployments, this rapid capital influx signals an unavoidable reality: agentic productivity gains will carry an immediate, mandatory compliance tax on software supply chain security.