The Battery led Series A from the ex Google reCAPTCHA and Safe Browsing (Chrome's malicious site warnings) team, $49M raised less than a year after publicly launching, is the first major bet on AI vs AI defense against the personalized phishing
AI-generated spear phishing has gone from rare to dominant inside a single year, slipping past the rule-based filters that protected corporate inboxes for a decade. AegisAI, a startup that builds its own large language models to defend the inbox, raised $36 million to replace those filters with AI agents.
The Series A was led by Battery Ventures, with existing investors Accel and Foundation Capital participating, per the company's press release. Co-founders Cy Khormaee and Ryan Luo previously led reCAPTCHA and Safe Browsing at Google, the two systems most readers have used to prove they are human or to be warned away from a malicious download. Total raised is now $49 million, less than a year after AegisAI emerged from stealth.
The mechanism AegisAI sells, in plain terms, is LLM-versus-LLM. Spear phishing is the targeted cousin of mass spam: instead of blasting a generic "your package is delayed" lure, the attacker researches a specific employee, mimics a real vendor, and crafts a message that reads like a peer sent it. Khormaee told TechCrunch that AI-crafted lures now bypass rule-based filters "more than half the time" and are "almost twice as effective as they used to be," a founder-stated thesis rather than an independent benchmark. Newer payloads wrap a malicious PDF inside a built-in password and a CAPTCHA so the standard scanner never even gets to look at the file. The old defenses are checklists of known-bad signals; AI-generated text has none of those tells.
AegisAI's product is an autonomous agent branded Vanguard that reads each message the way a careful human analyst would, looking for small anomalies the rule book does not have an entry for. The company says it builds its own models rather than wrapping a general-purpose LLM, on the theory that the offense is moving fast enough that a defensive model needs to be tuned to phishing specifically and updated continuously. Early customers include the crypto payments company Mesh, AI agent builder LangChain, and privacy compliance platform Lokker, all names a non-beat reader will not recognize, but a tell that the early adopters are themselves AI-heavy and so feel the new attack surface first.
The urgency numbers all come from the company's own PR Newswire release: AI-generated email attacks up five-fold in a single year, FBI-reported cybercrime losses hitting a record $20.8 billion. Both figures are widely repeated across security coverage and have not been independently re-verified here, so the "why now" reads best as the threat AegisAI is built to sell against, not a settled industry statistic. Battery general partner Dharmesh Thakker framed the bet publicly as replacing legacy rule-based email security with AI-native defense: "defend against AI with AI."
"AI will solve security" has been a category pitch for at least a decade, from next-generation antivirus to extended detection and response, or XDR, to secure access service edge, branded SASE. Each wave arrived with a venture-funded category bet and a thesis that the old layer was finished; each one settled into a feature inside a larger platform rather than replacing the rules it claimed to obsolete. If independent testing still shows rule-based filters catching the bulk of spear-phishing attempts, as some published benchmarks suggest, then AegisAI is selling the right answer to a real but narrow slice of the threat, and the $36 million is a category bet in name only until outside data catches up.
The next data point to track is whether Hoxhunt and the handful of other phishing-research shops that publish simulation data extend their benchmarks to AI-native defenders. Third-party benchmark data will settle it. The working mental model Battery is underwriting holds: when AI offense outruns a rules-based defense, the next capital bet is agentic AI, not smarter rules, and the founders of the filters most readers have already learned to click are the ones making it.