Cybercriminals are increasingly leveraging artificial intelligence to execute large-scale attacks, with email frequently serving as the primary vector. AI's capacity to rapidly compile personal data—including details on colleagues, ongoing projects, and recent travel plans—enables malicious actors to instantly generate highly credible and authentic-appearing messages.
In response to this escalating threat, former Google security executives Cy Khormaee and Ryan Luo, both instrumental in developing safe browsing technology and reCAPTCHA, co-founded AegisAI last year. This innovative startup employs AI agents specifically designed to counteract sophisticated spear phishing attempts.
Drawing on a decade of experience in preventing email breaches, the AegisAI co-founders recognized that conventional rule-based security systems, which rely on rigid "if-then" logic, were proving too slow and limited to effectively detect AI-generated malicious emails. Consequently, they developed advanced AI agents capable of analyzing each message with human-like discernment, identifying subtle anomalies that even the most exhaustive manual checklists would miss.
Less than a year since its inception, AegisAI reports significant market traction, with its technology adopted by dozens of clients, including the crypto payments platform Mash, AI startup LangChain, and Google's privacy compliance platform, Lokker. This strong demand recently culminated in a successful $36 million Series A funding round, led by Battery Ventures, with continued support from existing investors Accel and Foundation Capital. This latest infusion of capital boosts the startup's total funding to $49 million.
"AI-powered attacks now bypass existing controls more than half the time, which means they’re almost twice as effective as they used to be," Khormaee informed TechCrunch. He further elaborated, "They’ve researched you, they understand everything about you, and they’re targeting attacks that are perfectly bespoke to you."
Khormaee asserts that AegisAI's agents possess the unique ability to identify threats that traditional email security systems often overlook entirely. For example, the startup's AI can detect malicious PDF attachments that initially appear legitimate, even those embedded with passwords and CAPTCHAs, which are commonly used to circumvent standard spam filters.
Dharmesh Thakker, a general partner at Battery Ventures, observed the surge in email attacks and actively sought to invest in a startup capable of countering AI with AI. His vision was to support a company aiming to replace outdated email security tools with an agentic-driven defense paradigm.
"The bad guys are using email to attack us using AI at a much faster pace than we can keep up with," Thakker told TechCrunch. He emphasized, "Defending against that is going to be a number one priority for a lot of companies."
AegisAI is not the sole innovator leveraging AI to contextually analyze incoming emails for fraud and impersonation. Lightspeed-backed Ocean is another notable player striving to challenge established vendors like Proofpoint and Mimecast, alongside newer competitors such as Abnormal Security.
However, Thakker believes AegisAI holds a distinct advantage in becoming the preeminent new hack-prevention company, primarily due to its leadership by experts who were instrumental in securing Gmail, globally recognized as the most popular email system.
While AegisAI's initial focus is on email security, the startup plans to expand its defensive capabilities into other domains, such as data security. Khormaee articulated this broader vision, stating, "The core idea of building customized, highly advanced agents that can do investigations is going to [determine] who becomes the next dominant security company."
The Editorial Staff at AIChief is a team of professional content writers with extensive experience in AI and marketing. Founded in 2025, AIChief has quickly grown into the largest free AI resource hub in the industry.