AegisAI emerges from stealth with a bold mission to stop phishing, malware, and business email compromise before it ever hits your inbox
Fighting AI with AI: The Rise of Autonomous Email Defenders
With AI-generated phishing attacks on the rise, two former Google security leaders are betting big on a smarter solution: a swarm of autonomous AI agents built to stop malicious emails before they reach users.
- AegisAI, founded by Cy Khormaee and Ryan Luo, just raised $13 million in seed funding from Accel and Foundation Capital.
- The company’s mission: to neutralize phishing, malware, and business email compromise (BEC) threats using a network of LLM-powered agents — no rules, no manual tuning.
The Threat Landscape Is Shifting Fast
Over 90% of cyberattacks start with a phishing email, according to CISA. And thanks to generative AI, those emails are becoming more convincing.
- A CrowdStrike study found that AI-generated phishing messages had a 54% click-through rate, compared to just 12% for human-written emails in 2024.
- That’s a fourfold increase in risk — and attackers are just getting started.
From Google to the Frontlines of Email Security
Khormaee and Luo bring serious credentials to the problem:
- Khormaee led Google’s security products like Safe Browsing, reCAPTCHA, and Web Risk, protecting 4 billion users and 4 million websites from fraud.
- Luo was part of the same team, focusing on phishing detection and behavioral analysis.
- The pair are leveraging over a decade of experience fighting adversaries to preempt the next generation of attacks.
“The sum of all evil is a PDF attachment in an email,” Khormaee quipped. “That’s where all the attacks start.”
Inside AegisAI’s Agent Network
At the core of AegisAI is a real-time, orchestrated network of LLM-based agents, each tuned to identify and neutralize different types of email threats.
- There’s an “orchestrator” agent that spots potential threats and dispatches specialized “buddy” agents to investigate further.
- These agents analyze every aspect of an email:
links, QR codes, attachments, metadata, behavioral patterns, and more. - Once they reach consensus, the orchestrator makes the final call.
Unlike traditional email security platforms that rely on predefined rules, AegisAI’s agents self-tune to detect new variants of old threats in real time — a game-changing shift in detection methodology.
Cutting False Positives by Up to 90%
AegisAI’s multi-agent approach doesn’t just find more threats — it reduces false positives too.
- The platform claims up to 90% fewer false alarms than rule-based systems, meaning less wasted time and fewer missed emails.
- It’s already in use by early customers like Lokker (data privacy software) and Mesh Connect (crypto payments).
Setup is surprisingly quick:
- Installation takes under 5 minutes via API for Google Workspace or Microsoft 365.
- After a week-long read-only pilot, the system moves into active quarantine mode.
Building a Scalable Defense for Evolving Attacks
AegisAI currently runs with 10 specialized agents, but the founders say that number could grow to 50–100 as attackers evolve.
“In two years, adversaries will understand what we’re doing,” Khormaee said. “They’ll retool and attack — and we’ll be ready.”
The platform is already being tailored to specific industries, with custom threat models for financial services, venture capital, and crypto.
A Lean Team with Global Reach
- AegisAI operates with a six-person team split between San Francisco and New York.
- The company is currently piloting with customers in the U.S. and Europe and plans to scale both technical development and go-to-market operations with the new funding.
While still early, AegisAI is uniquely positioned to lead the next generation of AI-native cybersecurity — not by playing catch-up, but by outsmarting adversaries before they even reach your inbox.








