Hackers are increasingly using artificial intelligence to launch large-scale attacks, with email becoming a primary target. AI can quickly gather personal information such as details about coworkers, ongoing projects, and recent travel plans, enabling attackers to craft convincing messages that appear authentic.
Last year, former Google security executives Cy Khormaee and Ryan Luo, who previously worked on safe browsing technology and reCAPTCHA, founded AegisAI. The startup uses AI agents to neutralize these threats, known as spear phishing.
With a decade of experience preventing email hacks, the co-founders recognized that existing rule-based systems relying on if-then logic are too slow and limited to catch AI-crafted malicious emails. So they built AI agents that analyze each message the way a human would, paying attention to small anomalies that even the most detailed checklist would miss.
Less than a year after launch, AegisAI says its technology has been adopted by dozens of customers, including crypto payments company Mash, AI startup LangChain, and Google-owned privacy compliance platform Lokker. That demand helped AegisAI raise a $36 million Series A led by Battery Ventures, with participation from existing backers Accel and Foundation Capital. The new funding brings the startup's total capital to $49 million.
How AegisAI works
"AI-powered attacks bypass existing controls more than half the time now, which means they're almost twice as effective as they used to be," Khormaee told TechCrunch. "They've researched you, they understand everything about you, and they're targeting attacks that are perfectly bespoke to you."
Khormaee claims that AegisAI's agents can spot threats traditional email security systems may miss entirely. For instance, the startup's AI can catch malicious PDF attachments that look legitimate at first, including ones with built-in passwords and CAPTCHAs, which are often used to fool standard spam filters.
Investor perspective
Stay ahead of the AI curve
The most important updates, news, and content — delivered weekly.
No spam. Unsubscribe anytime.
When Dharmesh Thakker, general partner at Battery Ventures, noticed an increase in email attacks, he set out to invest in a startup that could defend against AI with AI, one aiming to replace legacy email security tools with agentic-driven defense.
"The bad guys are using email to attack us using AI at a much faster pace than we can keep up with," Thakker told TechCrunch. "Defending against that is going to be a number one priority for a lot of companies."
Competitive landscape
AegisAI is not the only startup using AI to analyze the context of every incoming email to detect fraud and impersonation attempts. Lightspeed-backed Ocean is also trying to displace established vendors like Proofpoint and Mimecast, along with newer players like Abnormal Security.
However, given that AegisAI is led by experts who helped secure Gmail, the most popular email system in the world, Thakker believes the startup has the best shot at becoming the leading new hack-prevention company.
Future plans
While AegisAI is starting with email, the startup has its sights on eventually expanding to other areas of defense, such as data security. "The core idea of building customized, highly advanced agents that can do investigations is going to [determine] who becomes the next dominant security company," Khormaee said.

