Enterprise AI security has been aimed at the model while the real attack surface multiplied around it. Every skill, plugin, subagent, and MCP connection can bring new instructions into a system that is authorized to act. That is not an accessory problem. It is a supply-chain problem with decision rights attached.

AIR has emerged from stealth with $50 million in funding led by Sequoia Capital and Greenoaks. The company is building what it calls a context firewall for agents. Its platform is designed to vet external capabilities before deployment, monitor them afterward, trace dependencies, and revoke access when something changes or goes wrong.

The timing is not subtle. Companies are moving from employees chatting with models to agents that can touch code, files, browsers, databases, and operational systems. The security boundary now includes every package of instructions those agents consume. AIR says its research found 17,800 agent add-ons with 6.7 million combined installations that could load untrusted external instructions. Those figures come from the company, but the underlying problem is already visible to anyone building serious agent systems.

A traditional firewall controls traffic. An agent firewall has to reason about provenance, permissions, behavior, and dependency chains. A tool can be safe when installed and dangerous after an update. A benign instruction can become risky when combined with privileged access. A subagent can inherit authority its designer never intended to delegate. Static approval is not enough.

AIR still has to prove that inspection can keep pace with an ecosystem where tools appear faster than security teams can review them. It also has to avoid becoming another dashboard that identifies risk without stopping it. The useful product is not a catalog of scary findings. It is an enforceable layer that lets teams move quickly without handing every experimental integration the keys to the company.

This category is going to exist whether AIR owns it or not. The model is becoming one component in a much larger machine. Once agents can act, the context they consume becomes production infrastructure. Production infrastructure gets inventory, policy, observability, and a kill switch. Anything less is autonomy by vibes.

LaunchPad positionAgents turn context into executable infrastructure. Companies need to inventory, inspect, authorize, trace, and revoke every external capability an agent can load, because model security alone does not control the supply chain around the model.
Reporting standard

This report draws on the linked primary sources and reputable reporting. Company statements are treated as claims until independently demonstrated.