$36 million is now riding on AegisAI’s bet that email security needs autonomous AI agents to fight AI-crafted phishing, not another layer of static rules.
The email security startup announced a Series A led by Battery Ventures, with participation from Accel and Foundation Capital, bringing total funding to $49 million, according to SecurityWeek. The company said it will use the money to expand its autonomous detection agents, push its Vanguard agent toward general availability, and build out enterprise sales.
AegisAI’s $49 million bet targets AI-powered email security
AegisAI was founded in 2025 by Cy Khormaee and Ryan Luo, former members of Google’s security team who worked on reCAPTCHA, Safe Browsing and Web Risk. The company emerged from stealth in September 2025.
Its platform reviews incoming email for phishing, business email compromise and other threats. The key claim: AegisAI does not rely mainly on static rules or known-bad signatures. It uses a network of AI agents to assess the intent and identity behind a message.
That distinction matters because the company is positioning itself directly against what it calls AI spear phishing. In AegisAI’s framing, attackers can use language models to research a target, map work relationships and write a personalized lure at a cost and speed that would have been harder to match with human operators alone.
“The most immediate, catastrophic risk to your organization isn't an AI agent hacking your firewall. It's an AI model manipulating someone in your organization into handing over the keys, often through the most trusted, most vulnerable contact of the person it's targeting,” said Khormaee, AegisAI’s CEO.
The product connects to Microsoft 365 and Google Workspace through an API, which AegisAI says requires no changes to a customer’s MX records. That is a practical sales point for security teams that don’t want an email security rollout to become an infrastructure project.
AegisAI introduced Vanguard in March. The companion agent investigates suspicious links and attachments by navigating to them the way a human recipient would, then produces a threat report within minutes.
Email attacks are pulling budgets toward AI defense tools
The company’s funding pitch is built around a blunt security thesis: if attackers are using AI to make email lures more convincing, defenders need AI that can reason through context, identity and intent in real time.
Company materials cited in the source set the scale sharply. AegisAI says AI-generated spear phishing rose from 2.8% to 13.9% of observed phishing in 2025, based on its State of the AI Threat in Email study of more than 20,000 phishing, scam and malware emails. The same materials say AI-generated emails evade traditional filters at nearly double the rate of human-written attacks and reach the inbox more than half the time.
AegisAI also cites the FBI’s 2025 Internet Crime Report, saying reported cybercrime losses hit $20.8 billion. The company says phishing complaint volume stayed roughly flat, while losses tied to those complaints rose from about $70 million to more than $215 million.
The sharper point is business email compromise. AegisAI says BEC accounted for $11.64 billion in losses, compared with less than $52 million for ransomware and malware combined.
That explains the investor interest. The risk is not only malicious attachments or sketchy URLs. It is trust abuse at scale.
| Security approach | What it looks for | AegisAI’s claimed edge |
|---|---|---|
| Traditional filtering | Known-bad signatures, rules, past scam patterns | Can miss novel, personalized lures |
| AegisAI agents | Message intent, sender identity, contextual anomalies | Designed to catch AI-crafted attacks that pass technical checks |
| Vanguard | Suspicious links and attachments beyond the inbox | Navigates links and files like a user, then reports within minutes |
Analysis: funding momentum does not prove AegisAI has a durable product lead. It does show that investors are backing a clear category thesis: email remains a high-value attack surface, and buyers need detection that catches more sophisticated lures without flooding security teams with noise.
That thesis also sits beside other security funding stories XOOMAR has tracked, including Abstract Security Funding Wagers $25M Against SIEM Lock-In and $1.2B AI Risk Bet Hurls Glow Endpoint Security Into View. The common thread is not a single product category. It is pressure to prove AI can reduce security workload, not just rename old tooling.
AegisAI now has to turn capital into enterprise proof
AegisAI says the $36 million round will support three priorities: more autonomous defense agents, general availability for Vanguard, and enterprise go-to-market expansion.
That next phase is harder than a funding announcement. Enterprise security buyers will want evidence that AegisAI’s agents outperform existing controls in production, not just in demos or controlled studies.
The company’s strongest technical story is its focus on intent and identity. If AI phishing can pass authentication, mimic tone and avoid known malicious infrastructure, then a filter that only asks whether something matches a known pattern will miss too much.
Khormaee put the argument more directly.
“You cannot patch human trust. If your security program still relies on template-based phishing tests and awareness training, you are training your people to spot last year's threat, not a capable agent crafting a novel lure just for them. When the attack is AI, the defense has to be AI,” Khormaee said.
The unresolved question is measurement. AegisAI says its approach can cut false positives by up to 90% compared to traditional solutions, according to company materials. Buyers will want to see how that holds across industries, tenant sizes, email platforms and attack types.
Customer traction will matter too. TechCrunch reported that AegisAI has been adopted by dozens of customers, including Mesh, LangChain and Lokker. That is useful early validation, but enterprise security markets usually demand deeper proof: retention, deployment scale, incident reduction and integration quality.
AegisAI’s next pressure point is clear. It has notable backers, a timely threat narrative and founders with Google security credentials. The market will now judge whether AegisAI can show measurable protection against real AI-powered email attacks, especially the ones that look clean to legacy filters and convincing to humans.
The Bottom Line
- AegisAI’s $36 million Series A signals investor demand for security tools built to counter AI-generated phishing.
- The company is betting autonomous detection agents can outperform static rules against personalized email attacks.
- Its API-based support for Microsoft 365 and Google Workspace could make enterprise adoption easier.
Originally published on XOOMAR. For more news and analysis, visit XOOMAR.
Top comments (0)