AI-Agent Security for UAE Firms: Controls Before AIR
AIR has raised $50 million to vet AI-agent skills, plugins and MCP servers. UAE teams should tighten controls now, but most should not buy a new platform yet.
AIR has raised $50 million to vet AI-agent skills, plugins and MCP servers. UAE teams should tighten controls now, but most should not buy a new platform yet.

Small UAE teams using AI agents should act on the security problem now, but the honest answer on buying AIR or a similar platform is: not yet. Start with an inventory of agents, tools, plugins, MCP servers and business data connections. Set clear approval rules before giving agents wider access.
AIR has emerged from stealth after raising $50 million across two seed rounds. The company says its platform can discover agents inside a company, continuously vet the skills and tools they use, and block connections that fail security checks. It also offers a marketplace of vetted add-ons for AI agents. TechCrunch’s report on AIR sets out the company’s product and funding in detail. (techcrunch.com)


The funding was split between a $10 million round led by Sequoia and a $40 million round led by Greenoaks. AIR was founded by Yair Saban and Niv Hoffman, who previously worked in Israel’s Unit 8200 intelligence corps. The company says it has more than 20 customers, with the strongest early demand from regulated industries such as financial services and pharmaceuticals.
AIR’s argument is that AI agents are becoming a new software supply chain. An agent may load a skill, call an MCP server, install a plugin or fetch information from the internet. Each connection can expand what the agent can see or do. A previously approved tool can also become risky if its downloaded package changes or its developer account is compromised. (techcrunch.com)
The company says its system finds agents and unapproved AI tools, intercepts actions such as loading a skill or retrieving online content, and checks components against a maintained whitelist. AIR also says it currently filters out about 27% of the add-ons and skills it finds online. That is a company claim, not independent evidence of effectiveness.
The risk is moving from the AI model alone to everything the agent can install, call or consume.
The important change is practical. AI-agent security cannot be treated only as a model-selection question. It is also an access-control and software-supply-chain question.
A small team may not have a dedicated security department. It may still have agents connected to email, customer records, shared drives, accounting systems or ecommerce tools. The first control is knowing which agents exist and who approved them. The second is limiting each agent to the data and actions it needs.
Use a simple register with the agent’s owner, purpose, connected systems, permitted actions and review date. Do not allow a plugin or MCP server to connect to production data merely because it works in a demonstration. Keep testing environments separate from live customer, finance and stock records.
This is also where ERP and automation decisions matter. Automation should make permissions visible, not hide them inside an informal workflow built by one employee. If your business is already reviewing systems and integrations, the earlier guide on AI-agent security for UAE firms provides useful context for that discussion.
For most small UAE businesses, no. The TechCrunch report describes a young category with AIR, Noma Security, Zenity, Astrix Security and Operant AI competing around agent discovery, controls and monitoring. It also says AIR is expanding its research and go-to-market work in the United States and Europe. The article does not establish UAE availability, local support, integration coverage or pricing.
That does not make AIR irrelevant. A regulated company with many agents, sensitive systems and a growing number of third-party tools may reasonably begin a controlled evaluation. A small team with one or two experimental agents probably needs a documented inventory, least-privilege access and human approval for high-impact actions before it needs a dedicated control plane.
The sensible trigger for a formal platform review is not the funding announcement. It is operational complexity. Consider one when you cannot reliably answer which agents are running, what tools they use, what data they can reach, whether those tools change, and how to stop an unsafe action.
Do not wait for a security vendor before setting basic rules. Name an owner for every agent, remove unused connections, approve tools individually and review permissions when an agent’s purpose changes. Treat internet content and third-party add-ons as inputs that need checking, not as automatically trusted instructions.
Paknology has a commercial interest when this review leads into ERP or automation work, because that is a service we provide through ERP and automation. We do not provide AIR or claim to replace a specialist cybersecurity platform. If your immediate need is simply to map existing workflows and integrations, a smaller internal review may be the cheaper and simpler option; if you need specialist monitoring across a large agent estate, speak to a dedicated security provider instead. For a situation that does not fit those options, talk to us.
Book a free consultation and get a clear roadmap — from company formation to a fully automated digital operation.