Skip to content

AI agent security attracts $50 million as a new race to audit protocols and extensions in software supply chains

Share
AI agent security attracts $50 million as a new race to audit protocols and extensions in software supply chains

Listen to this article

Read by Anchor

With the accelerating integration of AI agents into corporate infrastructures, an emerging software supply chain is forming around the auxiliary tools that enable those agents to perform their tasks: software skills, model context protocol (MCP) servers, and extensions that allow direct internet connectivity. In this foundational path, the cybersecurity startup "AIR" emerged from a secretive phase after raising $50 million across two consecutive funding rounds, aiming to build a specialized platform that monitors this chain and audits the behavior of the tools used by autonomous systems.

The rapid financing, which closed within a few weeks, was split between a first round of $10 million led by Sequoia and a second round of $40 million led by Green Oaks, with participation from investors who founded tech companies such as Cognition, Weiss and Ion. The company was founded by Yair Saban and Naveh Hoffman, who come from an offensive cybersecurity background within Israel’s military intelligence unit 8200. The company’s vision draws on a historical approach to early operating systems, with its founders noting that today’s agent extensions and connection servers lack the digital-signature mechanisms and strict oversight that were previously imposed on hardware drivers after the risks of loading them directly into the kernel became apparent.

The greatest risk in agent systems does not lie in targeting the model itself, but in poisoning the data and inputs the agent draws while traversing independently between internal databases and external web sources.To address these gaps, the platform relies on a detection layer that tracks active agents within the work environment and identifies unauthorized tool usage or personal accounts, alongside an interception layer that instantly analyses any external action, and a continuously audited whitelist that reviews globally available extensions; the company’s data shows that about 27 percent of online skills and extensions are excluded for failing to meet security standards.

The platform operates amid fierce competition and massive financial flows targeting the global agent security sector, where ZeniTech raised $125 million in August and Nova Security secured $100 million last year, alongside rivals such as Asterix and Uberant AI. Investor partners believe the dilemma is not ordinary static scanning but building an engineering infrastructure that continuously re-verifies in real time every skill, server and software the agent fleet connects to, especially since a routine software update in an external package can turn a trusted tool into an intrusion vector within moments.

This shift directly impacts the technical decisions of CTOs and cloud-infrastructure teams in Gulf, Egyptian and regional organizations. As banks and logistics companies rush to delegate independent agents to handle queries, transactions and connect them to protocols such as MCP servers, the definition of the security perimeter changes entirely; limiting human identities and traditional access permissions is no longer sufficient. The administrative decision imposed by this reality requires subjecting every open-source skill or inference extension to a mandatory periodic audit protocol before linking it to corporate databases, and noting that the cost of lax verification of agent supply chains may far outweigh the benefits of rapid automation.

Don't miss the next story

Subscribe for updates