AegisAI Raises $36 Million to Fight AI-Generated Phishing at the Inbox
The same generative AI that lets a marketer draft a flawless cold email now lets a criminal write a flawless con. That inversion is the entire business case for AegisAI, a San Francisco email-security startup founded by former Google security leaders, which on July 23 announced a $36 million Series A to build language models and autonomous agents that read the intent behind every message before it reaches an employee's inbox.
The round was led by Battery Ventures, with returning backers Accel and Foundation Capital, and brings AegisAI's total funding to $49 million less than a year after the company emerged from stealth. AegisAI launched publicly in September 2025 with a $13 million seed, meaning it has more than tripled its capital base in roughly ten months on the strength of a threat that barely existed two years ago.
The economics of a perfect lure
For decades the best defense against spear phishing was cost. Researching a target, mapping their colleagues, impersonating a trusted vendor and timing the lure demanded a skilled human operator, a capability effectively reserved for nation-states. AegisAI's argument is that generative AI has collapsed that cost to roughly the price of a cup of coffee. Off-the-shelf models can now scrape public data on an individual, map their professional relationships, identify their most trusting contact and generate a context-aware lure at unlimited scale.
The company's own research quantifies the shift. AegisAI's State of the AI Threat in Email study, presented at the 2026 M3AAWG conference and based on more than 20,000 malicious messages, found that AI-generated spear phishing grew fivefold in 2025, from 2.8% to 13.9% of all observed phishing. Those AI-written emails evaded traditional filters at nearly double the rate of human-written attacks, reaching the inbox more than half the time, and 72.6% of successful attacks passed standard email authentication because they were sent from compromised but legitimate accounts. The FBI's 2025 Internet Crime Report told the same story from the victim's side: reported cybercrime losses hit a record $20.8 billion, with business email compromise alone accounting for $11.64 billion.
"AI-powered attacks bypass existing controls more than half the time now, which means they're almost twice as effective as they used to be," co-founder and CEO Cy Khormaee told TechCrunch. "They've researched you, they understand everything about you, and they're targeting attacks that are perfectly bespoke to you."
Fighting AI with AI
Khormaee and co-founder Ryan Luo are veterans of Google's core security group, where they helped build reCAPTCHA, Safe Browsing and Web Risk, systems that screen billions of users daily. Their thesis is that rule-based email defenses, built on if-then logic and signatures of known-bad content, are structurally unable to catch a linguistically perfect message that has never been seen before.
Instead, AegisAI deploys an orchestrated network of AI agents inside the inbox that interrogate the intent and identity behind each message, the way an attentive human would, and claims to cut false positives by up to 90% versus legacy tools. In March the company extended those agents beyond the inbox with Vanguard, which follows suspicious links and attachments across the open web, defeating adversarial CAPTCHAs and cloaked pages, and returns a full threat report in minutes. The Series A will fund general availability of Vanguard, a larger fleet of defense agents and an enterprise go-to-market push.
Early customers skew toward high-value targets: crypto payments company Mesh, AI developer platform LangChain and privacy-compliance firm Lokker, where AegisAI says it caught an attack routed through a trusted vendor's compromised Salesforce infrastructure, with no malicious link or attachment at all.
"You cannot patch human trust," Khormaee said in announcing the round. "If your security program still relies on template-based phishing tests and awareness training, you are training your people to spot last year's threat. When the attack is AI, the defense has to be AI."
Why it matters
AegisAI is a clean example of AI funding chasing AI's own second-order consequences: cheaper, better attack emails create demand for language- and intent-aware defense that pattern-matching scanners cannot provide. The pitch resonated with Battery Ventures general partner Dharmesh Thakker, who went looking for such a company after watching email attacks climb. "The bad guys are using email to attack us using AI at a much faster pace than we can keep up with," he told TechCrunch, calling AI-native email defense a coming top priority for enterprises.
The competitive field is crowding fast. AegisAI is squaring off against incumbents Proofpoint and Mimecast, the venture-backed challenger Abnormal Security, and newer entrants such as Lightspeed-backed Ocean, all racing to reposition around AI-versus-AI defense. AegisAI's wager is that a team that helped secure Gmail, the world's most-used email system, has the credibility and technical depth to win.
What to watch
The near-term test is whether AegisAI can convert stealth-era buzz and a handful of marquee logos into durable enterprise contracts before better-capitalized rivals close the gap. Watch the general-availability rollout of Vanguard and any move to expand from email into adjacent areas such as data security, which Khormaee has signaled as the longer-term prize. The deeper question is whether autonomous, intent-reading agents can stay ahead of attackers wielding the very same models, an arms race in which both sides now upgrade at machine speed.
"You cannot patch human trust. When the attack is AI, the defense has to be AI."— Cy Khormaee, Co-founder and CEO, AegisAI