AI Agent Firewalls Are Becoming Essential: AIR Security Raises $50 Million to Address the Next AI Security Challenge

Artificial intelligence is moving rapidly from experimental technology to an active participant in enterprise operations.

AI agents can now interact with applications, browse websites, access files, work with emails, connect to business systems, use external tools, and perform tasks with limited human intervention. This creates significant opportunities for productivity, but it also introduces a new cybersecurity challenge.

What happens when an AI agent trusts a malicious tool, plugin, instruction, or external source?

The emergence of AIR Security from stealth with $50 million in funding highlights how seriously the cybersecurity industry is beginning to address this problem. The company is developing an AI agent security platform designed to evaluate the tools and extensions that AI agents rely on and identify potential risks before they become part of an organization’s AI workflows.

The AI Agent Supply Chain Is Becoming a New Attack Surface

Traditional enterprise security has focused heavily on protecting networks, endpoints, applications, identities, and cloud infrastructure.

AI agents introduce another layer.

An enterprise agent may depend on:

• AI skills
• Plugins and extensions
• Model Context Protocol (MCP) servers
• Third-party tools
• External websites and content
• APIs and SaaS applications
• Internal enterprise systems
• Developer tools and coding environments

Each connection can potentially introduce additional risk.

AIR Security’s research identified more than 17,800 publicly available AI add-ons associated with approximately 6.7 million installations. The company also reported discovering AI skills designed to impersonate trusted organizations and potentially bypass security controls or execute unauthorized code.

The broader lesson is important: AI security cannot stop at the model. Organizations also need visibility into everything connected to the model and agent.

Why AI Agents Create a Different Security Problem

Traditional applications generally execute predefined instructions.

AI agents can interpret information, make decisions, select tools, and determine how to accomplish a task.

That flexibility is one of their greatest strengths, but it can also become a security weakness.

Consider an enterprise employee using an AI coding agent. The agent may automatically discover a tool or plugin that appears useful. If that component contains malicious instructions or excessive permissions, the agent could potentially interact with sensitive systems in ways the employee or security team never intended.

Similarly, an AI agent browsing the internet could encounter manipulated content designed to influence its behavior.

Potential consequences include:

• Unauthorized access to sensitive information
• Exposure of confidential business data
• Credential or secret leakage
• Unauthorized system changes
• Fraudulent activity
• Malicious code execution
• Supply chain compromise
• Abuse of privileged enterprise integrations

This makes agent context security an increasingly important part of enterprise cybersecurity.

The Rise of Shadow AI and Unmanaged Agent Connections

Another challenge is visibility.

Employees and development teams can adopt AI tools faster than security teams can formally approve them.

This can result in what is effectively a new form of shadow IT.

Organizations may not know:

• Which AI agents are operating in their environment
• Which plugins or skills those agents are using
• Which MCP servers they are connecting to
• What permissions have been granted
• What information agents can access
• Which external services they communicate with
• Whether an integrated tool has changed since approval

Without this visibility, security teams may have difficulty determining whether an AI workflow is trustworthy.

The problem becomes even more significant when agents have access to sensitive applications, source code, customer information, financial systems, or production infrastructure.

Coding Agents Increase the Security Stakes

AI coding agents are among the most important examples of this emerging risk.

Development teams are increasingly using AI systems to generate, review, modify, and manage software.

These agents can potentially interact with:

• Source code repositories
• CI/CD pipelines
• Cloud environments
• Package repositories
• APIs
• Databases
• Developer credentials
• Infrastructure configurations

A compromised tool used by a coding agent could therefore create risks far beyond the AI application itself.

Organizations need to treat AI development environments as part of the broader software supply chain security program.

Security controls should include continuous monitoring of agent activity, strict permissions, dependency validation, secure secrets management, and testing of AI workflows before they receive access to production resources.

What an AI Agent Firewall Could Change

AIR Security’s approach focuses on creating a security layer specifically around AI agents and their associated supply chain.

The platform is designed to discover AI agents and evaluate the skills, plugins, MCP servers, and other add-ons they depend on. It also analyzes these components for potential malicious behavior, hidden instructions, excessive permissions, vulnerable dependencies, and impersonation techniques.

A key aspect is continuous evaluation.

A component that appears safe today may become risky tomorrow if:

• A maintainer introduces a malicious update
• A third-party service is compromised
• New vulnerabilities are discovered
• Permissions are expanded
• External instructions change
• The component begins accessing sensitive information

Continuous monitoring therefore becomes just as important as the initial security assessment.

Why Regulated Industries Should Pay Attention

The risks associated with AI agents are particularly significant for organizations that manage sensitive information or operate critical systems.

Financial Services and Banking

AI agents may interact with financial applications, customer records, payment systems, fraud detection platforms, and internal business processes.

Security teams should focus on agent permissions, data access, transaction controls, identity management, and continuous monitoring.

Healthcare and Life Sciences

Healthcare organizations use highly sensitive patient and research information.

AI agents connected to healthcare applications must be carefully controlled to prevent unauthorized access, data exposure, and inappropriate processing of sensitive information.

Retail and E-Commerce

Retail organizations increasingly use AI for customer support, inventory, marketing, fraud detection, and operational automation.

Security programs should evaluate third-party AI integrations, customer data access, payment environments, and external plugins.

Manufacturing and Industrial Organizations

AI agents can increasingly support engineering, operations, supply chain management, and industrial environments.

Organizations should ensure that AI systems cannot gain unnecessary access to operational technology, production systems, or critical infrastructure.

Government and Public Sector

Government agencies manage sensitive citizen information and critical services.

AI agent deployments should incorporate strong identity controls, secure integrations, continuous monitoring, data governance, and supply chain security.

Technology and SaaS Companies

Technology companies are among the earliest adopters of AI coding agents and autonomous development tools.

Security teams should pay particular attention to source code repositories, CI/CD pipelines, cloud environments, developer credentials, APIs, and third-party AI components.

How Organizations Can Prepare

AI agent security should become part of the enterprise security strategy rather than being treated as an isolated AI initiative.

Organizations should consider:

• Maintain an inventory of AI agents and their integrations
• Evaluate AI skills, plugins, and MCP servers before deployment
• Apply least privilege to AI agent identities
• Restrict access to sensitive applications and data
• Monitor agent behavior continuously
• Validate third-party AI components and dependencies
• Secure API keys, credentials, and secrets
• Implement strong software supply chain controls
• Conduct AI application and agent penetration testing
• Establish approval processes for new AI integrations
• Monitor changes to previously approved components
• Include AI agents in incident response planning
• Regularly assess AI systems for compliance and governance requirements

The objective should not simply be to prevent AI adoption.

The goal should be to make AI adoption secure, controlled, observable, and compliant.

AI Security Is Moving Beyond Model Protection

For years, discussions around AI security focused heavily on model vulnerabilities, prompt injection, adversarial attacks, data poisoning, and model theft.

Those remain important.

But the expanding AI agent ecosystem introduces another dimension.

The security of an AI system increasingly depends on the security of everything surrounding it.

A highly secure model connected to an untrusted plugin can still create risk.

A properly governed AI agent with excessive permissions can still create risk.

A trusted application connected to a compromised MCP server can still create risk.

This means organizations need to secure not only the AI model, but also the AI agent supply chain, context, tools, identities, permissions, data, and surrounding infrastructure.

Conclusion

AIR Security’s emergence from stealth with $50 million is another indication that AI agent security is becoming a dedicated cybersecurity priority. The company is addressing a growing challenge created by autonomous systems that increasingly depend on external tools, plugins, skills, MCP servers, data sources, and enterprise applications.

As organizations move from experimenting with AI agents to using them for real business operations, security teams will need greater visibility and control over what those agents can access and trust.

The next generation of enterprise security will therefore need to protect more than networks and applications.

It will also need to protect AI agents and the ecosystem of tools and instructions that influence their decisions.

Organizations that establish strong AI governance, continuous monitoring, secure integrations, least-privilege access, supply chain controls, and regular security testing will be better positioned to adopt autonomous AI while reducing cybersecurity and compliance risks.

About COE Security

COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.

Our offerings include:

• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services

In addition, COE Security helps organizations address emerging AI agent security risks through:

• AI agent security assessments and threat modeling
• AI application and agent penetration testing
• AI supply chain and third-party integration assessments
• Security reviews of AI plugins, skills, APIs, and MCP integrations
• Identity and access management assessments for AI agents
• Least-privilege and privileged access security reviews
• AI coding agent and development environment security assessments
• Secure AI architecture and cloud security reviews
• Software supply chain security assessments
• Continuous monitoring and AI-enhanced threat detection
• Secure Software Development Lifecycle implementation
• Vulnerability management and security testing
• Data protection and AI governance assessments
• Compliance readiness for organizations deploying AI in regulated environments
• Incident response planning for AI-related security incidents

We support industries including financial services, banking, healthcare, life sciences, retail, e-commerce, manufacturing, technology, SaaS, telecommunications, and government by helping organizations securely adopt AI agents while protecting sensitive data, applications, infrastructure, and business operations.

As AI agents become increasingly connected to enterprise systems, organizations need security controls that can identify what agents are using, what they can access, and how they behave.

COE Security helps organizations build that security foundation through AI security assessments, penetration testing, secure development practices, threat detection, governance, compliance, and continuous security improvement.

Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption and to stay updated and cyber safe.

Click to read our LinkedIn feature article