AIR Security Raises $50 Million to Build a Firewall for AI Agents
A new startup wants to screen the AI tools companies are rushing to adopt, checking them for hidden malicious instructions, overly broad permissions, and dodgy third-party software before they cause harm.

Key points
- AIR Security raised $50 million as it came out of stealth, meaning it moved from private development to public launch.
- The startup makes a firewall, a security gate that inspects traffic or instructions before they reach a system, designed specifically for AI agents.
- AIR's product screens AI skills, plugins, and MCP servers for malicious instructions, excessive permissions, and software supply chain risks.
- The product targets a gap that existing security tools were not built to cover: AI systems that act on behalf of humans.
A startup called AIR Security has stepped into public view with $50 million in funding and a product built around a question most companies haven't asked yet: who is checking what your AI tools are actually doing?
The company, first reported by SecurityWeek, makes what it calls an AI agent firewall. An AI agent is software that doesn't just answer questions but takes actions, such as booking meetings, reading emails, or placing orders on a user's behalf. A firewall is a security gate that sits between systems and decides what is and isn't allowed through. AIR's product applies that idea to the fast-growing world of AI agents.
What exactly does AIR's firewall look for?
Three things: hidden malicious instructions, permissions that are too broad, and risks buried in the software supply chain.
First, malicious instructions. AI agents can be fed commands through plugins, which are small add-on tools that extend what an AI can do, or through MCP servers. MCP, which stands for Model Context Protocol, is a technical standard that lets AI agents connect to external data sources and services. Criminals have found ways to hide harmful commands inside these channels, telling an AI to leak data or take unauthorised actions without the user realising.
Second, excessive permissions. An AI agent that can read your calendar probably doesn't also need access to your company's financial records. AIR's firewall flags situations where an agent has been granted far more access than its job requires, a classic setup for abuse.
Third, software supply chain risk. This refers to danger that enters through third-party code or services that an organisation didn't write itself but relies on. If a plugin was built by an unknown developer, or if a connected service has been quietly altered, that risk flows straight into any AI agent using it.
Should organisations using AI tools be worried?
Yes, and not in a theoretical way. Businesses are connecting AI agents to real systems, real data, and real customer records at speed. The security tooling has not kept pace.
Traditional firewalls watch for known attack patterns in network traffic. AI agents operate differently: they read natural language, follow instructions, and make decisions. A firewall that wasn't designed for that context will miss a lot.
AIR Security is betting that companies will pay to close that gap. A $50 million raise suggests investors agree the problem is real.
If your organisation is already using AI agents or planning to, the practical step is to audit what permissions each agent holds and to ask vendors what, if any, screening happens before third-party plugins connect to your systems.



