Can AI beat AI? AegisAI raises $36m to find out

AegisAI

AegisAI, an email security company that builds its own large language models to protect the inbox, has closed a $36m Series A as AI-generated spear phishing begins to outpace traditional defences.

Battery Ventures led the round, with existing backers Accel and Foundation Capital also taking part. The raise lifts AegisAI’s total funding to $49m, secured less than 12 months after the firm came out of stealth.

The capital will go towards scaling its fleet of autonomous defence agents, speeding up the general availability of Vanguard, its threat-hunting agent that operates beyond the inbox, and growing its enterprise go-to-market operation.

The company is positioning itself against a fast-emerging category of attack it calls AI spear phishing, in which criminals use LLMs to trawl the internet for details about a target and generate highly personalised lures aimed at extracting sensitive data, planting malware or diverting funds. The growing adoption of AI agents, which carry out tasks without human oversight, widens the attack surface further and could allow criminals to operate unnoticed for extended periods.

Rather than matching suspicious messages against patterns from historical scams, AegisAI’s adaptive platform deploys an orchestrated network of AI agents that reason about the intent behind an email and act on threats in real time, allowing users to identify fraud faster as phishing volumes climb sharply in the wake of ChatGPT’s launch.

The economics of targeted attacks have shifted dramatically. Where researching a victim, mapping their relationships and timing a convincing lure once demanded a skilled human operator, a capability historically associated with nation-states, off-the-shelf AI can now do all of this autonomously and at unlimited scale, for roughly the cost of a coffee.

AegisAI’s own research underlines the trend. Its State of the AI Threat in Email study, presented at the 2026 M3AAWG conference and drawing on more than 20,000 phishing, scam and malware emails, recorded a fivefold rise in AI-generated spear phishing, climbing from 2.8% to 13.9% of observed phishing during 2025.

It also found AI-written emails bypass traditional filters at almost twice the rate of human-crafted attacks, landing in inboxes over half the time, while 72.6% of successful AI attacks passed email authentication because they came from compromised legitimate accounts with credible sending histories.

AegisAI co-founder and CEO Cy Khormaee said, “The most immediate, catastrophic risk to your organization isn’t an AI agent hacking your firewall. It’s an AI model manipulating someone in your organization into handing over the keys, often through the most trusted, most vulnerable contact of the person it’s targeting.

“You cannot patch human trust. If your security program still relies on template-based phishing tests and awareness training, you are training your people to spot last year’s threat, not a capable agent crafting a novel lure just for them. When the attack is AI, the defense has to be AI.”

Stay ahead of the regulatory curve with strategic intelligence and early insight trusted by industry leaders. Subscribe to the RegTech Analyst newsletter today. 

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2018 RegTech Analyst

Investors

The following investor(s) were tagged in this article.