AI didn’t just make spam better. It weaponized it.
Hackers are now using artificial intelligence to launch attacks on a scale humans can’t match. Email is the battlefield. AI tools scrape personal data—coworkers’ names, active projects, travel itineraries—in seconds. They don’t guess. They craft bespoke messages that look authentic because they know exactly what you care about.
Existing defenses are failing. Rule-based systems rely on old-school “if-then” logic. Too slow. Too rigid. When an attacker spends weeks researching a target, a simple blacklist doesn’t cut it.
That’s where AegisAI steps in.
The Human-In-The-Loop Defense
Cy Khormaee and Ryan Luo know this intimately. Both are former Google security executives who built safe browsing tech and reCAPTCHA. Last year, they left Big Tech to start AegisAI.
Their insight? You can’t stop AI with algorithms. You need AI agents.
AegisAI’s software analyzes each incoming message the way a human analyst would. It looks for subtle anomalies. It reads the context. It spots the tiny cracks in a facade that checklist-based filters miss entirely.
It’s not just theory. The company has already onboarded dozens of clients, including crypto firm Mesh, AI startup LangChain, privacy platform Lokker, and others. This traction just secured a $36 million Series A round. Battery Ventures led the charge. Accel and Foundation Capital participated.
Total capital raised: $49 million.
Why Traditional Security Fails Against AI
The stakes are high. Khormaee says AI-powered attacks bypass existing security controls more than half the time.
“They’ve researched you,” he explained. “They understand everything about you, and they are targeting attacks that are perfectly bespoke to you.”
Consider a malicious PDF. Standard filters see a standard file extension. They might let it pass. But if that PDF has a built-in password and a CAPTCHA screen before you even see the content, it’s designed to trick human eyes and AI bots alike. AegisAI sees the trap. It flags the anomaly.
Dharmesh Thakker, a general partner at Battery Ventures, saw the shift happening. He noticed the velocity of email attacks accelerating. He wanted to bet on a company that would defend AI with AI.
“The bad guys are using email to attack using AI at a much faster pace than humans can keep up with,” Thakner told TechCrunch. Defending against that isn’t just an IT ticket. It’s a board-level priority.
Who Competes in the Agentic Security Space?
AegisAI isn’t alone. The market is heating up.
Competitors like Lightspeed-backed Ocean are also trying to displace legacy giants like Proofpoint and Mimecast. Newer entrants such as Abnormal Security are chasing similar goals. All use AI to analyze context and detect impersonation.
So why AegisAI?
Because the founders helped secure Gmail. The most popular email system on the planet. Thakker believes that specific pedigree gives them the edge. It’s not just code. It’s institutional knowledge of how email systems break and how to patch them.
What Comes Next
The focus is currently email. But the ambition is broader.
Khormaee sees this as the foundation for a new category. He wants to expand into general data security. The core thesis is simple: build highly advanced agents capable of deep investigation.
“Whoever masters that,” Khormaee says, “becomes the next dominant security company.”
The tools are changing. The threats are adapting. And the race to build the right defense is moving faster than anyone predicted.





























