The Emerging AI Agent Supply Chain Risk
As enterprises deploy autonomous AI agents, these agents increasingly function like operating systems, utilizing external tools, plugins, and Model Context Protocol (MCP) servers to interact with data and the internet. AIR, a security startup founded by veterans of Israel’s Unit 8200, argues that this ecosystem lacks the rigorous oversight traditionally applied to software drivers or applications. The primary threat is not direct attacks on the model, but rather 'content poisoning'—where attackers compromise the external skills or data sources an agent consumes to manipulate its behavior.
Continuous Verification vs. Static Scanning
AIR’s platform focuses on three core functions: discovering active agents within a company, enforcing security policies at runtime, and maintaining a whitelist of vetted tools. Unlike static scanners, AIR emphasizes 'continuous re-verification.' Because a previously safe plugin or skill can become malicious if its underlying code or dependencies change, AIR continuously monitors the ecosystem. The company reports that its current filtering process identifies and blocks approximately 27% of online add-ons as risky.
The Competitive Landscape
AIR enters a crowded market alongside competitors like Noma Security, Zenity, Astrix Security, and Operant AI. While visibility into agent activity is becoming a commodity, AIR aims to build a moat through its specialized pipeline for continuous vetting. Investors, including Sequoia and Greenoaks, view this as an infrastructure challenge rather than a simple scanning problem, noting that the ability to re-inspect components in real-time as they evolve is the critical differentiator for enterprise-grade security.