메뉴
BL
TechCrunch AI • 24일 전

AIR, AI 에이전트 공급망 보안 위해 5,000만 달러 확보

IMP
6/10
핵심 요약

AI 에이전트가 기업 시스템에 접근하며 스킬·플러그인·MCP 서버 등 새로운 소프트웨어 공급망이 형성되고 있는 가운데, 이를 검증·차단하는 보안 플랫폼 AIR가 스텔스를 벗고 5,000만 달러를 확보했다. 이스라엘 정보부대 8200 출신 창업자들이 이끄는 AIR는 에이전트 탐색, 도구 지속 검증, 승인되지 않은 연결 차단 기능을 제공한다.

번역된 본문

기업들이 AI 에이전트에 자사 시스템의 점점 더 많은 부분에 대한 접근 권한을 부여하기 시작하면서, AI 에이전트가 사용하는 새로운 도구들——스킬, 플러그인, MCP 서버, 인터넷과 상호작용할 수 있게 해주는 애드온——을 중심으로 초기 소프트웨어 공급망이 형성되는 것으로 보인다. AI 보안 스타트업 AIR는 기업들이 이 공급망을 모니터링할 방법이 필요할 것이라고 판단하며, 이 제품을 만들기 위해 두 차례의 시드 라운드를 통해 총 5,000만 달러를 조달하고 공개적으로 활동을 시작했다.

이스라엘 정보부대 8200 출신으로 공격적 사이버보안 업무를 담당했던 야이르 사반(Yair Saban, CEO)과 니브 호프만(Niv Hoffman, CTO)이 설립한 AIR는 기업 내부에서 실행되는 에이전트를 탐지하고, 이 에이전트들이 사용하는 스킬·도구·컴포넌트를 지속적으로 검증하며, 보안 기준을 통과하지 못하는 소프트웨어나 외부 소스와의 상호작용을 차단하는 플랫폼을 제공한다. 또한 검증된 AI 에이전트용 애드온과 스킬 마켓플레이스도 운영한다.

사반은 테크크런치에 두 투자 라운드가 몇 주 간격으로 마감되었으며, 첫 라운드에서 1,000만 달러, 두 번째 라운드에서 4,000만 달러를 조달했다고 밝혔다. 첫 라운드는 세쿼이아가, 두 번째 라운드는 그리노익스가 리드했다. 그 외에도 Swish, Netz, 잭 프랭켈(Cognition 사장), 이논 코스티카(Wiz 공동창업자), 오필 에를리히(Eon 공동창업자), 앤 노이버거, 오머 아담, 바룬 아난드(Clay 공동창업자) 등 엔젤 투자자들이 참여했다.

AIR의 피치는 이렇다. 기업에서 AI 에이전트가 대규모로 사용되는 방식은 운영체제와 비슷해지고 있지만, 에이전트가 사용하는 도구나 설치할 수 있는 소프트웨어에는 우리가 드라이버나 애플리케이션에 부여하는 것과 같은 감독이 아직 적용되지 않는다는 것이다.

"2000년대 초반에는 드라이버를 설치할 때 서명이 필요 없었습니다. 오늘날 드라이버를 설치할 때마다 드라이버가 실제로 커널에 코드를 로드하기 때문에 누가 서명했는지 표시되죠"라고 사반은 말했다. "스킬이나 플러그인, MCP에는 그런 게 없습니다. 안타까운 일이에요. 같은 메커니즘이고 같은 교훈인데, 우리는 그 교훈을 배우지 못한 겁니다."

그가 지적하는 가장 큰 위험은, AI 에이전트가 데이터베이스와 기업 시스템에서 더 자율적으로 작업하고 인터넷에 연결하게 되면서, 공격자가 에이전트를 직접 공격하는 대신 에이전트가 소비하는 콘텐츠를 오염시킬 수 있다는 점이다.

이 스타트업은 기업 환경 전반에서 활성화된 에이전트를 찾아내는 가시성 제품으로 이 문제를 해결할 수 있다고 말한다. 또한 IT 부서의 승인 없이 AI 도구를 사용하거나 개인 계정을 사용하는 직원도 식별한다. 다음으로, 에이전트에 연결되어 스킬 로드나 인터넷 콘텐츠 가져오기 같은 행동을 가로채 분석하는 강제 계층(enforcement layer)을 사용한다. 마지막으로, AIR는 에이전트가 사용하려는 도구·애드온·소프트웨어를 자사가 관리하는 화이트리스트와 대조해 검사한다.

사반은 AIR가 인터넷에 공개된 스킬과 애드온을 평가하여 화이트리스트를 유지 관리한다고 말했다. 변경 사항이나 악성 행위를 지속적으로 점검하는데, 이전에 승인된 스킬이라도 다운로드하는 패키지가 변경되거나 개발자 계정이 해킹되면 위험해질 수 있기 때문이다. 그는 AIR 플랫폼이 현재 온라인에서 발견되는 애드온과 스킬의 약 27%를 걸러내고 있다고 덧붙였다.

AIR는 20개 이상의 고객을 보유하고 있다고 주장했으며, 사반에 따르면 이 중 약 4분의 1이 대기업이다. 그는 지금까지 규제가 엄격한 산업, 특히 금융 서비스와 제약 회사에서 가장 강한 수요를 보았다고 말했다.

그러나 AIR가 이 시장에 혼자 있는 것은 아니다. 노마 시큐리티(Noma Security)는 에이전트, MCP 서버, 스킬에 대한 탐지, 접근 제어, 런타임 모니터링을 제공하며, 제니티(Zenity)는 유사하게 작동하는 보안 및 거버넌스 도구를 판매한다. 아스트릭스 시큐리티(Astrix Security)의 아이덴티티 플랫폼도 기업이 에이전트와 MCP 서버를 발견하고 제어할 수 있게 하며, 오퍼런트 AI(Operant AI)도 에이전트 보호 기능과 MCP 게이트웨이를 제공한다.

이 분야에는 상당한 벤처캐피털 자금도 몰리고 있다. 제니티는 8월에 1억 2,500만 달러의 시리즈 C를, 노마는 작년에 1억 달러의 시리즈 B를 각각 조달했다. 사반은 AIR의 해자가

원문 보기
원문 보기 (영어)
As companies start giving AI agents access to an increasing portion of their systems, a nascent software supply chain seems to be forming around the new tooling AI agents are using: skills, plugins, MCP servers, and add-ons that let them interact with the internet. AI security startup AIR believes companies will need a way to monitor that supply chain, and it's now coming out of stealth with $50 million raised across two seed rounds to build that product. Founded by Yair Saban (CEO) and Niv Hoffman (CTO), veterans of Israel's Unit 8200 intelligence corps, where they worked on offensive cybersecurity, AIR offers a platform that can discover agents running inside companies, continuously vet any skills, tools, and components those agents use, and block them from interacting with software or external sources that don't pass security criteria. It also offers a marketplace of vetted add-ons and skills for AI agents. The funding rounds closed within weeks of each other, Saban told TechCrunch, with the first round raising $10 million, and the second $40 million. Sequoia led the first round, while Greenoaks led the second, Saban said. Swish, Netz, and Zach Frankel (president of Cognition), Yinon Costica (co-founder of Wiz), Ofir Erlich (co-founder of Eon), Anne Neuberger, Omer Adam, Varun Anand (co-founder of Clay), and other angel investors also participated. AIR's pitch goes thusly: The way AI agents are used wholesale at companies is beginning to resemble operating systems, but the tools they use, or the software they can install, aren't yet being given the kind of oversight we give to drivers or applications. "In the early 2000s, whenever you installed a driver, the driver didn't need to be signed. Today, every time you install a driver, you see a signature saying who signed it, because the driver is actually loading code into the kernel," Saban said. "You don't have that with skills or plugins or MCPs, and it's a shame, because it's the same mechanism, it's the same lesson, but we haven't learned it." The big risk, he argues, is that as AI agents start working more autonomously across databases, enterprise systems, and connecting to the internet, attackers can poison the content an AI agent consumes instead of attacking it directly. The startup says it can solve that with a visibility product that finds agents active across a company's environment, as well as identifies employees who use AI tools unapproved by IT departments or those who use personal accounts. Then, it uses an enforcement layer that hooks into agents to intercept and analyze actions, like loading a skill or fetching content from the internet. Lastly, AIR also checks the tools, add-ons, or software an agent wants to use against a whitelist the startup maintains. Saban says the startup maintains this whitelist by evaluating skills and add-ons openly available on the internet for changes and malicious behavior, as a previously approved skill could become risky if a package it downloads changes, or its developer's account is compromised. He added that AIR's platform currently filters out about 27% of the add-ons and skills it finds online. AIR claims it has more than 20 customers, and Saban said roughly a quarter of these are large enterprises. He said the company has so far seen the strongest demand in heavily regulated industries, particularly financial services and pharmaceutical companies. However, AIR is hardly alone in this space. Noma Security offers discovery, access controls and runtime monitoring for agents, MCP servers and skills, while Zenity sells security and governance tools that work similarly. Astrix Security ‘s identity platform also lets companies discover and control agents and MCP servers, and Operant AI offers agent protections as well as an MCP gateway. There is significant venture money chasing the category, too. Zenity raised a $125 million Series C in August, while Noma raised a $100 million Series B last year. Saban thinks AIR's moat lies in its ability to continuously vet the skills and add-ons ecosystem growing around AI agents. "Continuously vetting skills and plugin websites, this is a hard mission to do. Gaining visibility over the endpoint, that is easy. Everybody's going to do it. It's hard to create a moat around that," he said. And while the CEO acknowledged that AI labs and providers will eventually build in security checks and policies to filter out malicious skill and tool usage, he thinks companies will still want to buy an independent product that works across vendors. "This is not a scanning problem, it is a continuous re-verification problem," Bogomil Balkansky, partner at Sequoia, told TechCrunch in an emailed statement. "Inspecting every skill, plugin, MCP server and sub-agent an enterprise's agents touch, re-inspecting each one every time it changes, in real time and across an entire company's agent fleet, is an infrastructure problem long before it is a security problem. Air has spent the last year building that pipeline. You do not catch up to it by writing a better scanner." AIR currently has around 40 employees. Saban said the new capital will primarily go toward hiring researchers and expanding the company's go-to-market efforts in the U.S. and Europe. Topics AI , AI agents , ai security , Greenoaks Capital , Security , Sequoia Capital When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence. Ram Iyer Editor Ram is a financial and tech reporter and editor. He covered North American and European M&A, equity, regulatory news and debt markets at Reuters and Acuris Global, and has also written about travel, tourism, entertainment and books. You can contact or verify outreach from Ram by emailing ram.iyer@techcrunch.com . View Bio October 13 - 15 San Francisco Don't miss out . The startup community will gather to answer a pivotal question: How do you build sustainably in the AI era? REGISTER NOW Most Popular Microsoft tests fix for latest hours-long Outlook outage Sarah Perez MapQuest's app surges to No. 1 in Navigation after refusing to rename Lake Ontario Sarah Perez Musk's faster path to more gas turbines comes with pollution problem Connie Loizos Nvidia’s AI advantage is moving beyond the GPU Russell Brandom Hugging Face is selling a cute $399 open source duck robot, Microduck Rebecca Bellan Nvidia closes in on Hugging Face acquisition Connie Loizos Viral AI startup Instinct has raised $350M at a $2.5B valuation Lucas Ropek