AegisAI has raised $36 million in a Series A round led by Battery Ventures, with Accel and Foundation Capital also participating, bringing the two-year-old email security startup’s total funding to $49 million, according to a company announcement distributed via PR Newswire.

The company, founded by Google alumni Cy Khormaee and Ryan Luo, who previously worked on reCAPTCHA, Safe Browsing, and Web Risk, builds a network of autonomous AI agents that evaluate the intent and identity behind an email rather than matching it against known-bad signatures or templates. Its Vanguard agent, announced in March, investigates suspicious links and attachments independently before a message reaches an inbox. The company cites market figures showing AI-generated spear phishing grew from 2.8 percent to 13.9 percent of all phishing in 2025, a fivefold increase, and that AI-written attacks evade filters at nearly double the rate of human-written ones, with 72.6 percent of successful AI attacks passing email authentication checks entirely. The FBI reported $20.8 billion in total cybercrime losses in 2025, with phishing losses alone surging 200 percent to $215 million.

The raise is notable less for its size than for what it signals about where email security vendors think the fight has moved. AegisAI’s founder framed the shift directly: “You cannot patch human trust. If your security program still relies on template-based phishing tests and awareness training, you are training your people to spot last year’s threat.” That is a pointed argument that static, rules-based email defense and annual phishing-simulation programs are already fighting the previous generation of attacks, since generative models can now write a convincing, personalized lure faster than any signature list can catalog it. It also lines up with CyberTech’s own recent coverage of Unit 42’s finding that AI is accelerating attacks rather than reinventing them: the offense side is evolving fast enough that vendors are now racing to field equally adaptive defense, rather than betting on user training alone. For a CISO evaluating email security spend, the raise is a signal to ask incumbent vendors how their detection adapts to AI-written lures in real time, not just how large their signature database has grown.

Source: PR Newswire