The first wave of AI startups were mainly aimed at making AI do more.
Now another group of founders are building businesses based on the far less glamorous question of what happens when all that software starts moving faster than the systems and security teams underneath it can handle.
Two new startups that have emerged this week are shining examples. Empirik came out of stealth on 1 September with $21 million in seed funding from Sequoia Capital, S32, Canapi Ventures and Alumni Ventures.
The company was started by Avon Puri and Sudheer Dhurjati, former infrastructure leaders who realised that AI could help solve a major problem for infrastructure engineers, namely preventing technology outages before they happen.
That world is changing at pace.. AI coding agents can now write and deploy software much faster than a human engineering team. Every new deployment can mean changes to permissions, configurations, databases and dependencies. One apparently harmless change can have consequences several layers away.
Most infrastructure software is good at telling you that something has gone wrong. Empirik wants to get in there earlier and warn you before.
Its system tracks changes across an organisation’s infrastructure, works out how those changes could ripple through interconnected systems and calculates the potential “blast radius”. Low-risk changes can proceed, while more dangerous ones can be flagged for human review.
Empirik wasn’t simply invented in a pitch deck and sent into the market. Sequoia grew the company from 2023, and the technology was developed in Sequoia’s own environment before the company spun out. Earlier this year, former Salesforce executive Kartik Chandrayana joined as CEO.
As well as Empirik, there is also AIR, which also emerged from stealth on the same day, with $50 million across two seed rounds.
AIR is tackling a different aspect of the same problem. Companies are increasingly giving AI agents access to internal systems and allowing them to use third-party tools, plugins, “skills” and MCP servers.
Those components allow an agent to do much more than simply generate text: they can access data, interact with software and perform actions on a company’s behalf. That creates a new kind of software supply chain — and with it potentially a new security nightmare.
AIR’s platform discovers the AI agents operating inside a company, identifies the tools and add-ons they’re using, checks those components, and can even block ones that fail its security criteria. The company says it currently filters out about 27% of the skills and add-ons it finds online.
As AI agents become more autonomous, security teams are having to deal with software that can effectively choose its own tools and interact with systems without a human approving every individual action.
Put the two companies together and a broader picture emerges. AI is creating an enormous amount of new activity inside companies. That activity needs infrastructure that can keep up, and security controls that can understand what autonomous software is actually doing.
That creates an opportunity for a different kind of founder.
You don’t necessarily have to build the next great AI model. You can build the infrastructure that stops those models from taking down the company. You can build the security layer that stops an agent from installing something malicious. You can build the monitoring, governance and control systems that make autonomous software usable by serious businesses.
That may turn out to be one of the less glamorous — and more durable — parts of the AI boom.
Everyone notices the agent, but who watches the watchmen? The businesses quietly forming around AI are doing exactly that and making sure the agent doesn’t break everything.