Key Takeaways
- Former Google security leads just raised $36M to fight AI-crafted spear phishing with AI agents that read email like humans do
- Rule-based email defenses now miss over half of AI-powered attacks — they're effectively obsolete
- Battery Ventures backed AegisAI because its founders built Gmail's security; that pedigree matters in a crowded field
- The arms race has shifted: attackers use AI to research victims at scale, defenders must use AI to spot anomalies no checklist catches
Google's former safe browsing and reCAPTCHA architects didn't wait for the market to catch up. Cy Khormaee and Ryan Luo left the company that secures the world's most popular email system to build something Gmail's own defenses can't handle: an AI that reads incoming mail the way a suspicious human would — scanning for the tiny, contextual anomalies that rule-based filters inevitably miss.
The number that should terrify every CISO: AI-powered attacks now bypass existing controls more than half the time. That's not a marginal degradation. That's a structural collapse of the "if-then" logic that has underpinned email security for two decades. Attackers aggregate co-worker names, active projects, travel itineraries — whatever the open web and breached databases offer — and craft messages that look indistinguishable from legitimate internal traffic. No static rule set catches a malicious PDF with a built-in password and CAPTCHA designed specifically to fool spam filters. AegisAI's agents do.
Battery Ventures' Dharmesh Thakker didn't bet on the technology alone. He bet on the pedigree. "The bad guys are using email to attack us using AI at a much faster pace than we can keep up with," he told TechCrunch. His firm led the $36 million Series A because Khormaee and Luo spent a decade stopping exactly these threats at Google scale. That experience compounds: they know which anomalies matter because they've seen the attacks that slipped through Gmail's own nets.
The market is already crowded. Lightspeed-backed Ocean, Abnormal Security, and others are chasing the same displacement of Proofpoint and Mimecast. But AegisAI's early traction — dozens of customers including Mesh, LangChain, and Lokker in under a year — suggests the founders' thesis holds: agentic analysis beats heuristic checklists when the adversary generates infinite variations. The $49 million total capital gives them runway to prove it at scale.
Skepticism is warranted. "AI agents" has become a fundraising incantation. Khormaee's claim that his system spots threats traditional tools "may miss entirely" is the kind of absolute language that collapses under red-team pressure. PDF attachments with embedded CAPTCHAs are a clever demo, but attackers adapt faster than demos update. The real test isn't whether AegisAI catches today's spear phishing — it's whether its agents generalize to tomorrow's morphing tactics without drowning security teams in false positives.
That false-positive risk is the silent killer in this category. Security ops teams already drown in alerts. An AI that flags every anomalous contextual signal becomes noise, not signal. Khormaee and Luo know this from Google; they've operated at the scale where precision determines whether a product gets deployed or shelved. Their agents must prove they triage like senior analysts, not junior ones.
Thakker's conviction — that defending against AI-driven email attacks becomes "priority number one for a lot of companies" — reflects a shift already visible in budget cycles. Legacy vendors are bolting on LLM features as fast as marketing allows. But bolting doesn't rewrite architecture. AegisAI's bet is that agentic reasoning, built from the ground up by people who've seen the full spectrum of email abuse, creates a defensible moat.
The $36 million says Battery Ventures believes the moat exists. The market will decide within eighteen months.