뉴스로 돌아가기
보안AI Understanding 브리핑

AIR는 AI 에이전트 추가 기능 및 작업을 검사하는 플랫폼으로 스텔스 기능을 종료합니다.

AIR는 AI 에이전트가 사용하는 기술, 플러그인, MCP 및 기타 추가 기능을 검사한 다음 런타임에 에이전트 활동을 모니터링하도록 설계된 보안 플랫폼을 통해 스텔스에서 등장했다고 밝혔습니다.

5 min readRead the linked source
Source-provided image accompanying AIR exits stealth with a platform to vet AI-agent add-ons and actions
소스 참조녹음된 소스
출판사
air.security
소스 링크
air.securityhttps://www.air.security/
소스 유형
연결된 소스 — 기본 소스 상태가 설정되지 않았습니다.
맥락60초 안에 이해하세요

여기서 시작하세요

주요 용어

MCP(모델 컨텍스트 프로토콜)
AI 애플리케이션이 표준 방식으로 외부 도구, 데이터 소스 및 컨텍스트 제공자에 연결할 수 있게 해주는 개방형 프로토콜입니다.
AI 에이전트
종종 도구와 메모리를 사용하여 목표를 달성하기 위해 관찰하고, 추론하고, 조치를 취할 수 있는 소프트웨어 시스템입니다.
프롬프트
생성 모델에 제공되는 입력 지침 및 컨텍스트입니다.
자신을 테스트해 보세요AI 에이전트 퀴즈
Source video from air.security · shown with attribution.

무슨 일이 일어났나요?

AIR announced on September 1, 2026, that it was coming out of stealth with a security platform for AI agents. The company describes its core product as a “context firewall” that analyzes inputs entering an agent from skills, MCPs, plugins, websites and internal data.

AIR says it emerged from stealth on September 1, 2026, with a platform aimed specifically at securing AI agents and the external components they use. Its central product description is a “context firewall” positioned between an agent and the outside world. AIR says the system continuously analyzes and filters inputs entering an agent’s context, including skills, MCPs, plugins, websites and internal data, with the goal of stopping threats before they reach the agent.

The company divides the platform into four parts. AIR Control is described as governing an organization’s agent fleet, including sanctioned and “shadow” agents, through policies covering configuration, identity and permissions. AIR Filter is presented as an add-on firewall that vets skills, plugins, MCPs and subagents before installation. AIR Defend is intended to monitor agent actions and detect, respond to and protect against threats in real time. AIR Marketplace is described as a source of pre-vetted external and certified internal add-ons.

AIR frames skills, plugins and MCPs as the application layer around AI agents. In its terminology, skills are reusable instructions, plugins package skills and other components, and MCPs provide external tools, data and actions. The company says these add-ons can contain hidden behavior, injections, excessive permissions, unauthorized actions, externally loaded instructions, data-exfiltration paths or supply-chain weaknesses. These are AIR’s product and threat-model claims; the supplied source does not include independent testing of the platform.

The source also features an AIR research post dated August 27, 2026, titled “MCPJacking: 155 Hijackable MCPs Discovered Live in the Official MCP Marketplace.” AIR says its researchers found 155 MCPs relying on expired domains, registered those domains, published replacement MCPs and obtained remote execution on agents that trusted them. The page does not identify the affected marketplace in the supplied text, describe the full research method or provide independent confirmation. The source likewise does not state the investors, terms or closing date of the $50 million raise mentioned in the candidate headline.

소스 세부정보: air.security ↗

왜 중요한가요?

AI agents increasingly depend on external tools and instructions, creating a security surface that AIR says conventional scanning may miss. The company’s approach focuses on the contents and permissions surrounding an agent, as well as the actions it takes.

The practical issue AIR is addressing is that an ’s behavior may depend on more than its underlying model. Instructions, tool definitions, permissions and retrieved information can influence what the agent does. If those components are compromised or overly broad, a trusted agent could be induced to take actions its operator did not intend. That makes the security of the surrounding agent ecosystem relevant to organizations deploying agents, not only the security of the model itself.

AIR’s product design reflects a lifecycle approach. It says add-ons should be checked before deployment, after updates and while running. That matters because an add-on can change over time, and a one-time review may not capture later changes or runtime behavior. AIR’s proposed combination of discovery, policy controls, preinstallation vetting and runtime protection could give organizations several points at which to restrict an agent, although the source does not show how those controls work in practice.

The company’s MCPjacking warning, if replicated, would illustrate a supply-chain problem for AI agents: a dependency that appears legitimate can become dangerous when its underlying external resource expires or changes ownership. AIR says the issue affected official marketplace entries and could allow remote execution. That claim points to a governance question for marketplaces and enterprises: who verifies ownership, maintenance and behavior of the external services that agents are allowed to trust?

There are important limits to what this announcement establishes. AIR provides no customer deployments, blocked-attack counts, false-positive rates, independent audit, pricing, availability timetable or detailed explanation of how its filters distinguish malicious instructions from legitimate agent behavior. Its security claims should therefore be treated as the company’s account of its product and research, rather than evidence that the platform has demonstrated effectiveness across enterprise environments.

Interactive Mechanism

대화형 메커니즘: 실제로 작동하는 방식

이 개발의 이면에 있는 기본 기술을 대화식으로 살펴보세요.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
대화형 개념 확인+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

다음에 무엇을 볼 것인가

The main unanswered questions are whether AIR’s controls are deployed in production, how often they block real threats, and how the company’s claims about vulnerable MCPs withstand independent verification. The supplied source does not provide customers, pricing, test methodology or technical performance data.

First, watch for concrete evidence of deployment. AIR says it is offering demos and early access, but the supplied source does not name customers or describe a generally available release. Useful follow-up evidence would include the environments covered, the types of agents and add-ons supported, the permissions AIR can control, and whether organizations can inspect or appeal automated blocking decisions.

Second, watch for independent scrutiny of the MCPjacking research. The source says 155 MCPs were hijackable because they depended on expired domains, but it does not provide a list, reproduction details or the marketplace’s response. Verification would clarify how widespread the problem was, whether the affected entries remain vulnerable, and whether the result reflects a broader systemic weakness or a bounded set of dependencies.

Third, watch how AIR measures runtime protection. The company says AIR Defend can detect, respond to and protect against every action an agent takes, but the source gives no definitions or performance results. Important questions include what actions are observable, how quickly intervention occurs, what happens when the system is uncertain, and whether monitoring introduces delays or limits legitimate agent capabilities.

Finally, watch the company’s financing and commercial development separately from its technical claims. The candidate headline reports a $50 million raise, while the AIR source supplied here does not state the round size, investors or use of proceeds. Follow-up reporting should verify those terms and determine whether the funding supports research, marketplace expansion, enterprise sales or broader runtime-security development.

관련 가이드 및 퀴즈

AI 에이전트AI 윤리AI 모델 설명알고 있는 내용을 테스트해 보세요. 무료 AI 퀴즈를 시도해 보세요.용어집에서 AI 용어를 찾아보세요.AI 규제 추적기를 따르세요
이것이 유용하다고 생각하시나요?