DTWdailytechwire
Tech Intelligence, Wired Daily
Startups

Email Security Startups Bet AI Agents Can Outpace Spear Phishing at Scale

AegisAI raises $36M as former Gmail security leads argue rule-based defenses no longer catch bespoke, AI-crafted attacks

AS
Arjun S. Mehta
Staff Writer · Singapore
Jul 24, 2026
4 min read
Email Security Startups Bet AI Agents Can Outpace Spear Phishing at Scale
Email Security Startups Bet AI Agents Can Outpace Spear Phishing at ScaleCredit: AegisAI

The Checklist Problem

Corporate email defenses have long relied on rule-based logic: if a message contains certain keywords, originates from a blacklisted domain, or carries a suspicious attachment signature, flag it. But Cy Khormaee and Ryan Luo, who spent a decade building safe browsing and reCAPTCHA technology at Google, watched that approach crumble as adversaries began feeding personal details into large language models to generate perfectly contextualized phishing messages at industrial speed.

AegisAI, the startup the pair founded in 2025, just closed a $36 million Series A led by Battery Ventures, with Accel and Foundation Capital participating. The round brings total capital to $49 million and arrives less than twelve months after launch, a timeline that reflects both the urgency enterprises feel and the pedigree investors see in former Gmail security architects.

Bespoke Attacks Bypass Half of Existing Controls

Spear phishing has evolved beyond misspelled domains and generic "verify your account" templates. Modern campaigns scrape LinkedIn profiles, calendar invitations, and project management tools to assemble messages that reference real colleagues, active deals, and upcoming travel. Khormaee says AI-powered attacks now bypass legacy email security more than half the time, nearly doubling their historical success rate.

Traditional systems struggle because they evaluate messages against static signatures and heuristics. An attacker who embeds a malicious PDF behind a CAPTCHA and password layer can sail past spam filters designed to catch simpler threats. AegisAI's approach instead deploys AI agents that read each message the way a human analyst would, flagging tonal inconsistencies, unusual urgency cues, and contextual mismatches that no enumerated rule set anticipates.

The company has signed dozens of customers in its first year, including crypto payments platform Mesh, developer tooling startup LangChain, and privacy compliance vendor Lokker. That traction persuaded Dharmesh Thakker at Battery Ventures, who had been tracking a spike in email-based breaches across his portfolio, that agentic defense could displace the incumbent generation of tools.

A Crowded Field with a Gmail Advantage

AegisAI is not alone in promising context-aware, AI-native email security. Ocean, backed by Lightspeed, is pursuing the same category, and both startups position themselves as challengers to established vendors such as Proofpoint and Mimecast, as well as newer entrants like Abnormal Security. The pitch is similar across the board: replace if-then logic with models that understand nuance.

What sets AegisAI apart, according to Thakker, is founder credibility. Khormaee and Luo helped secure Gmail, which processes hundreds of millions of messages daily and has served as a testing ground for adversarial techniques at every level of sophistication. That operational experience, Thakker argues, translates into a product that anticipates attacker behavior rather than reacting to it after the fact.

Battery Ventures has a history of backing infrastructure-layer security companies, and Thakker frames the investment as a bet that whoever builds the most advanced investigative agents will define the next dominant platform in enterprise defense. Email is the beachhead, but the underlying agent architecture is designed to generalize.

Beyond the Inbox

AegisAI plans to extend its agent framework beyond email. Khormaee has pointed to data security as a natural adjacent category, where the same principle applies: legacy tools enumerate threats, while adaptive agents hunt for anomalies in real time. The company has not disclosed revenue or customer count beyond "dozens," but the Series A size and investor composition suggest strong early unit economics and a clear path toward expansion.

The funding environment for security startups has tightened over the past eighteen months, making AegisAI's ability to raise $36 million notable. Investors are demanding faster time-to-value and measurable risk reduction, and the startup's rapid customer adoption appears to have satisfied both criteria. At DailyTechWire, we've tracked a wave of security vendors pivoting from detection to prevention, and AegisAI's model fits that broader shift: rather than alert on suspicious activity, intercept it before it reaches an end user.

The Arms Race Ahead

Spear phishing is unlikely to plateau. As foundation models become cheaper and more capable, the cost of launching a thousand bespoke attacks approaches zero. Defenders face an asymmetric challenge: attackers need only one message to succeed, while security teams must catch every attempt. AegisAI's bet is that AI agents, trained on the patterns Gmail's infrastructure has observed over two decades, can tilt that asymmetry back toward defense.

Whether agent-based email security becomes a category or a feature remains an open question. Incumbents have deep customer relationships and are already integrating generative AI into their own products. AegisAI's window to establish itself as the default choice will depend on how quickly it can demonstrate measurably lower breach rates and how effectively it can scale its agent infrastructure across diverse email environments.

For now, the startup has capital, customer momentum, and a team that understands adversarial email at scale. The next twelve months will reveal whether that combination is enough to unseat a generation of rule-based defenses that no longer match the sophistication of the threats they were built to stop.

Read next
Startups

Patreon Cuts One-Fifth of Staff as CEO Cites Industry Shifts, Not AI Replacement

Arjun S. Mehta · 5 min
Startups

Infosys Names Ashiss Kumar Dash as CEO to Navigate AI Disruption

Arjun S. Mehta · 4 min
Startups

Patreon Cuts Nearly 100 Jobs as CEO Cites AI's Reshaping of Operations

Arjun S. Mehta · 5 min
Spot something wrong? Email corrections@dailytechwire.com. We log every correction publicly.