AegisAI has raised a $36 million Series A led by Battery Ventures to defend corporate inboxes against AI-generated spear phishing, bringing the startup's total capital to $49 million less than a year after launch. Accel and Foundation Capital, both existing backers, joined the round. The company says dozens of customers have signed on since it opened for business, including crypto payments firm Mesh, LangChain, and privacy compliance platform Lokker.
The founders, Cy Khormaee and Ryan Luo, spent roughly a decade at Google working on safe browsing technology and reCAPTCHA — the systems that keep Gmail, the world's most-used email platform, from drowning in fraud. They started AegisAI last year on the premise that rule-based email security, built on if-then logic, cannot keep up with attackers who use large language models to research a target and write bespoke lures in seconds.
AegisAI's product is a set of AI agents that read each inbound message the way a human analyst would, flagging small contextual anomalies that a checklist would miss. Khormaee said the agents can catch malicious PDFs that pass conventional filters, including attachments that use built-in passwords or CAPTCHA challenges to slip past spam scanners.
Key facts
- 01AegisAI closed a $36M Series A led by Battery Ventures, with participation from Accel and Foundation Capital.
- 02The round brings total capital raised to $49M, less than a year after the startup's launch.
- 03Customers include crypto payments firm Mesh, AI infrastructure startup LangChain, and privacy platform Lokker.
- 04Co-founders Cy Khormaee and Ryan Luo previously worked on Gmail safe-browsing technology and reCAPTCHA at Google.
- 05AegisAI says AI-generated attacks now bypass existing email controls more than half the time.
The threat model has shifted quickly. Attackers can now aggregate a target's coworkers, active projects, and recent travel from public data and internal leaks, then generate messages that look authentic on first read. Khormaee's claim that AI-crafted attacks bypass legacy controls more than half the time is the pitch to CISOs — the failure rate of the incumbent stack is no longer a rounding error.
The incumbents in question are Proofpoint and Mimecast, the two vendors most enterprise email security budgets still flow to, plus the newer entrant Abnormal Security, which pioneered behavioral analysis for email fraud. Lightspeed-backed Ocean is chasing the same replacement cycle with a similar agentic pitch. AegisAI's wedge is the founding team's Gmail pedigree.
Battery Ventures' Dharmesh Thakker, who led the round, said the firm went looking for a startup that could defend against AI with AI after seeing an inbound wave of email attacks at portfolio companies. He argues the founders' Gmail background gives AegisAI the credibility to displace legacy vendors during renewal cycles.
Khormaee said email is the beachhead, not the endgame. The company plans to extend its agent framework to other defensive domains, with data security cited as the next target. The bet is that the same investigative pattern — an agent that reads context, checks provenance, and reasons about intent — generalizes across security workflows that have historically relied on static rules.
The counterweight is real. Email security is one of the most crowded categories in enterprise software, and buyers are notoriously slow to rip out incumbent contracts even when detection rates lag. AegisAI has not disclosed detection benchmarks against Proofpoint or Abnormal, and dozens of customers is a starting position, not a moat. The company will need to show measurable false-positive rates and time-to-detect numbers to displace tools that are already stitched into every enterprise mail gateway.
AegisAI is one of a growing cohort of security startups arguing that agentic architectures — not bigger rule sets — are the only viable answer to attackers who now generate personalized lures at machine speed. The investment thesis at Battery, Accel, and Foundation is that email security is about to be re-platformed the way endpoint security was a decade ago, and the winner will be whoever ships the most reliable investigator agent first. Whether that winner is AegisAI, Ocean, Abnormal, or an incumbent that catches up, the category is now firmly a race between defensive AI and offensive AI — and the offensive side has a head start.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




