
Cybercriminals are increasingly harnessing AI to execute attacks on a large scale, with email becoming a key target. AI can swiftly compile personal details — such as data about colleagues, ongoing projects, and recent travel plans — enabling malicious actors to promptly create convincing communications that appear legitimate.
In the previous year, former Google security leaders Cy Khormaee and Ryan Luo, who had previously been involved in creating safe browsing technology and reCAPTCHA, joined forces to establish AegisAI, a startup utilizing AI agents to combat these threats, referred to as spear phishing.
With a decade’s worth of experience in thwarting email breaches, the AegisAI co-founders recognized that current rule-based systems for preventing breaches — which depend on “if-then” mechanisms — are insufficiently fast and are limited in identifying AI-generated malicious emails. Thus, they created AI agents that rapidly assess each message as a human would, focusing on subtle discrepancies that even the most thorough checklists would overlook.
Fewer than twelve months post-launch, AegisAI reports that its technology has been embraced by numerous clients, including the cryptocurrency payments firm Mesh, AI startup LangChain, and the privacy compliance service Lokker. This surge in interest has enabled AegisAI to secure a $36 million Series A funding round led by Battery Ventures, with contributions from current investors Accel and Foundation Capital. The new capital elevates the startup’s total funding to $49 million.
“AI-driven attacks bypass current safeguards more than half the time today, signifying they’re nearly twice as effective as previously seen,” Khormaee disclosed to TechCrunch. “They’ve done their homework on you, they’re aware of everything about you, and they’re executing attacks tailored specifically to you.”
Khormaee asserts that AegisAI’s agents can identify threats that conventional email security systems might entirely overlook. For example, the startup’s AI can detect harmful PDF attachments that initially seem credible, including those with embedded passwords and CAPTCHA, commonly used to deceive standard spam filters.
When Dharmesh Thakker, general partner at Battery Ventures, observed a rise in email attacks, he aimed to invest in a startup capable of countering AI with AI, which aspires to replace traditional email security tools with agent-driven defense mechanisms.
“The adversaries are exploiting email to assault us using AI at a speed far exceeding our ability to respond,” Thakker stated to TechCrunch. “Countering that will become a top priority for numerous companies.”
AegisAI is not the sole startup leveraging AI to examine the context of every incoming email to identify fraud and impersonation attempts. Lightspeed-backed Ocean is also working to challenge established firms like Proofpoint and Mimecast, alongside newer contenders like Abnormal Security.
Nevertheless, considering that AegisAI is directed by specialists who played a role in securing Gmail, the most widely-used email platform globally, Thakker is confident that the startup has the best opportunity to emerge as the leading new hack-prevention entity.
While AegisAI is currently focusing on email, the startup aims to eventually branch out into other defense sectors, such as data security. “The fundamental concept of creating personalized, highly sophisticated agents capable of conducting investigations is going to [influence] who becomes the next dominant security firm,” Khormaee mentioned.
Whenever you make a purchase through links in our articles, we may receive a small commission. This doesn’t impact our editorial autonomy.

