
San Francisco-based startup AegisAI, founded by former Google security executives, has raised a $36 million Series A as it tries to counter phishing attacks shaped by generative AI.
AegisAI, an email security startup founded in 2025 by former Google security executives Cy Khormaee and Ryan Luo, has raised $36 million in a Series A round led by Battery Ventures, with Accel and Foundation Capital also participating. The company says the round brings its total funding to $49 million.
The startup is building what it describes as an agentic email security platform. Its core pitch is simple: AI-powered phishing has become convincing enough that traditional rule-based filters are no longer enough on their own. AegisAI says its system uses AI agents to review email the way a human analyst would, looking at language, sender behavior, context, and other signals instead of depending mainly on reputation lists or signatures.
According to the company’s announcement and site, AegisAI was created by the team behind Google Safe Browsing, reCAPTCHA, and Web Risk. The company is headquartered in San Francisco.
The funding arrives as AegisAI argues that AI is changing the speed and quality of phishing attacks. In its State of the AI Threat in Email report, the company says it analyzed more than 20,000 phishing, scam, and malware emails and found that AI-generated spear phishing rose from 2.8% of observed phishing attacks in 2025 to 13.9%. The same report says those messages were 75% more effective at bypassing traditional email filters.
The company also says 72.6% of successful AI email attacks came from compromised legitimate accounts, which allowed the messages to pass standard authentication checks. That finding points to a familiar weakness in email security: if an account is already trusted, filters can miss abuse carried out from inside that trust boundary.
AegisAI’s product pitch is built around speed and low disruption. The company says customers can deploy the platform by API in about five minutes, without changing MX records, and that the system works with Microsoft 365 and Google Workspace. It also says the platform is SOC 2 Type II certified and claims it can reduce false positives by more than 90%.
That positioning places AegisAI in a crowded but still fast-moving market that includes vendors such as Microsoft Defender for Office 365, Google Workspace security, Proofpoint, Mimecast, and Abnormal Security. AegisAI’s bet is that email defense now needs to be AI-native, not just AI-assisted. That is an interpretation of the company’s strategy, but it fits the direction of its product and funding story.
The broader interest in the company reflects a simple reality: attackers can now use AI to write more believable messages, study targets faster, and scale personalized lures with less effort. TechCrunch reported that AegisAI’s founders say AI lets criminals gather details about coworkers, projects, and even travel plans to make phishing emails look authentic.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.

