AIR emerged from stealth on September 1, 2026, with a product pitch aimed at a new enterprise control point: the skills, plugins, Model Context Protocol servers and other components that AI agents can load or consult. In its September 1 launch note, the company describes its software as a filter for the context entering agents across endpoints, cloud systems and software-as-a-service applications.
TechCrunch reported that AIR has raised $50 million across two rounds: a $10 million round led by Sequoia and a $40 million round led by Greenoaks. Sequoia’s investment note confirms its backing and describes the same agent supply-chain thesis. The financing is significant, but operators should treat the product claims as those of a new vendor and its investors.
What AIR says its control layer does
Agent add-ons do not all behave like conventional libraries. A skill can supply reusable instructions, an MCP server can expose tools and data, and a plugin can bundle several component types. Those components may guide an agent toward external websites, packages or internal systems while inheriting some of the agent’s access.
AIR’s product page presents four connected functions. AIR Control is intended to discover agents and apply configuration, identity and permission policies. AIR Filter is pitched as pre-installation vetting for skills, plugins, MCP servers and sub-agents. AIR Defend is described as runtime detection and response for agent actions. AIR Marketplace is the company’s catalog of pre-vetted external and internal add-ons.
That is a different problem from package portability. GeethanTech’s Agent Plugins 1.0 explainer covers a format that standardizes manifests and component locations, while leaving installation, permissions and policy to individual clients. Common packaging can make add-ons easier to discover, but it does not establish that their code, instructions, dependencies or external resources are trustworthy.
Why continuous re-verification is the central claim
AIR argues that a one-time scan cannot cover an add-on whose dependencies or referenced resources can change later. A skill may look unchanged while a remote instruction file, package release, domain owner or maintainer account changes underneath it. The company therefore describes its core job as repeated inspection before and after installation, combined with policy enforcement when a component no longer meets an organization’s criteria.
The risk model is plausible, but AIR’s measurements remain vendor research. In a June research post, the company said it scanned 142,836 live skills and classified 17,822 as relying on at least one external resource it considered untrusted. Its scoring used signals involving domains, GitHub owners, packages and hosting behavior. Those signals can identify risk, but they do not show that every flagged resource is malicious.
AIR separately told TechCrunch that its platform filters out about 27% of the online add-ons and skills it finds. The published material does not provide enough detail about that figure’s denominator, collection period, duplication handling, threshold or false-positive rate to treat it as an ecosystem prevalence estimate. It should be read as a company-reported operating metric.
What security teams should verify
The reviewed materials do not provide public deployment architecture, connector coverage, pricing, detection benchmarks, independent test results or detailed false-positive data. Prospective customers should ask where AIR observes agent activity, which clients and MCP transports it supports, how enforcement is inserted, what happens when the service is unavailable, and how quickly a changed dependency or external page is re-evaluated.
Policy design is equally important. Blocking an add-on may prevent a risky action, but it can also interrupt legitimate automation. Buyers need to understand exception workflows, rollback and revocation behavior, audit logs, data retention, regional processing, and how AIR separates a suspicious signal from a confirmed malicious component. They should also test whether the product’s coverage extends to shadow agents and personal accounts in their actual environment, rather than assuming discovery is complete.
TechCrunch reports that AIR claims more than 20 customers, with roughly a quarter described as large enterprises, and that the company has around 40 employees. These figures indicate early commercial activity, not independently verified adoption or effectiveness. The report also identifies competing agent-security vendors, which means buyers can compare discovery, enforcement and cross-vendor coverage rather than accepting a new category on one supplier’s terms.
Funding validates interest, not efficacy
AIR is addressing a real operational gap: agents can consume instructions and invoke tools from sources that change faster than conventional software review cycles. Its continuous-vetting model gives security teams a concrete framework for inventory, trust decisions and revocation.
The $50 million financing gives the company resources to build that infrastructure and expand sales. It does not prove that AIR can detect every harmful change, maintain low false-positive rates or enforce policy across a heterogeneous agent fleet. For operators, the useful next step is a scoped evaluation against their own add-on inventory, update paths and failure modes, with the company’s claims treated as testable requirements rather than established outcomes.



