Investors poured $435 million into AI agent security startups across 12 separate financings over the last five months. The latest signal: AIR Security’s $50 million seed round, announced September 1, for a company building an inline firewall that vets the skills, plugins, and MCP servers AI agents rely on to function. That kind of money at seed stage tells you something about where the market thinks the risk is landing.
The round, led by Sequoia ($10 million) and Greenoaks ($40 million), backs a company founded by Unit 8200 veterans Yair Saban and Niv Hoffman. AIR’s platform discovers agents running inside enterprises, continuously checks the add-ons they want to use against a security whitelist, and blocks those that fail. The company reports more than 20 customers — roughly a quarter of them large enterprises — and says its platform currently filters out about 27% of the add-ons and skills it encounters online. Strongest demand is coming from financial services and pharmaceutical companies, the industries where regulatory pressure makes ungoverned agent behavior hardest to tolerate.
Saban draws a direct comparison to how operating systems evolved. In the early 2000s, drivers didn’t need signatures. Today they do, because drivers load code into the kernel. Skills, plugins, and MCP servers are doing something similar — loading capabilities into agents that act with enterprise-level permissions — but nobody is signing them yet. The practical caveat: while driver signing eventually became a standard, the sheer velocity of AI agent development makes manual verification impossible. Automated, real-time filtering is the only realistic path.
Sequoia partner Bogomil Balkansky frames the challenge as an infrastructure problem, not a scanning one. Continuous re-verification of every skill, plugin, MCP server, and sub-agent an enterprise fleet touches — re-checking each one every time it changes, in real time — is the kind of work that scales only if the verification layer becomes as standard as the network firewall.
AIR’s round is part of a broader pattern. Glow raised $180 million in a Series A announced July 22, reaching unicorn status at a $1.2 billion valuation with a prevention-first approach to endpoint security for AI agents. Zenity closed a $125 million Series C on August 3, led by Norwest with SoftBank, Hitachi, and LG Technology Ventures participating, for a governance platform that deterministically allows, modifies, or blocks agent actions based on intent. Gartner named Zenity the company to beat in AI agent governance in April. Together, these three rounds — $355 million just from the top three — signal that the agent-security layer has moved from experimental to infrastructure-grade.
The money is going to different parts of the same problem. AIR focuses on what agents load. Glow focuses on where agents run. Zenity focuses on what agents intend to do. Each addresses a distinct layer of the stack, and none of them are competing for the same buyer conversation — yet. The enterprise security tools are booming. Consumer equivalents for agent security are effectively nonexistent.
This funding surge connects directly to the governance infrastructure we documented earlier this month. The agent governance stack is forming — Okta, IBM, Broadcom, and Dataiku each shipped standalone agent governance tools within a two-week window, targeting identity, orchestration, security, and observability layers respectively. The security companies attracting this capital are building the infrastructure those governance tools need to enforce. Without the verification and enforcement layer, governance remains a policy on paper.
The measurement gap compounds the challenge. As we documented in the agent measurement problem, there is no industry standard for what success looks like in agentic AI — five competing metrics measure entirely different things. Security tools like AIR’s 27% filter rate at least offer one concrete, measurable signal: how many requested capabilities fail to meet enterprise security criteria. That is a number CISOs can act on.
The urgency is uneven. Financial services and pharma are buying first because their regulators are asking first. The broader enterprise market is still in the deployment phase — racing to get agents into production before the governance and security layers are fully in place. That sequencing risk — agents shipping faster than the tools to secure them — is what $435 million in funding is trying to close. Whether the guardrails can keep pace with the platforms they protect remains the open question.
