Upwind Buys Aegis to Build an AI Security Lab
The lab will study risks in AI systems and develop security agents of its own. Upwind has not set release dates for the work.
Listen to this story
The audio brief
Story brief
3 key pointsThe lab is a new line of work inside Upwind’s cloud-security business, combining Aegis’s technology and team with Upwind’s platform. Its plan runs in two directions: securing AI systems across models, agents, identities, data and infrastructure, and building AI agents for security investigations. Upwind says the team has 12 people and aims for about 25 within three months; eventual growth to 35 is only a...
- 01
Aegis initially approached Upwind about a partnership and possible investment; Upwind chose an acquisition after several months of working together.
- 02
Aegis focused on AI-agent threats and AI-assisted attacks, including automated exploitation and large-scale credential theft.
- 03
Planned research includes security benchmarks and datasets to test whether frontier models can reason about attack paths and exploitability.
Upwind is bringing an AI security startup inside its cloud-security business rather than building its new lab from scratch. On September 23, it announced the acquisition of Aegis and the launch of the Upwind AI Lab. Aegis’s team will join Upwind researchers and engineers to tackle risks in AI systems and develop AI-assisted defenses. The purchase gives the lab people and technology now; most of its proposed work still lies ahead.
A partnership turns into a purchase
Aegis first approached Upwind about a strategic partnership and possible investment. After several months of working together, Upwind chose to acquire the startup and bring its people and technology into the company. Aegis co-founders Omri Limor and Saar Ankonina will lead the new operation, which the two news accounts call Upwind AI Security Labs.
The founders began their careers together in Israel’s Unit 8200 intelligence unit, working in offensive cybersecurity. Aegis later focused on threats involving AI agents and AI-assisted attacks, including automated exploitation and large-scale theft of credentials. Those are the kinds of problems Upwind now intends to address inside its existing security business. Upwind did not disclose the acquisition’s financial terms.
Two sides of the AI security problem
One part of the lab’s plan is to secure AI systems themselves. Upwind wants to examine what is running, what it can access and how it behaves while in use, drawing on its approach to cloud security. That scope includes models, agents, identities, software connections, data and cloud infrastructure. It is a broader remit than checking an AI model in isolation: the company’s premise is that risk can arise where those parts interact.
Agents can interact with applications, retrieve information and carry out tasks. Skills and plugins give them more ways to act, but also add components that need protection. Upwind says the lab will work on scanning and attack detection, including finding exposed secrets such as credentials in stored data and data moving between systems. These are intended areas of work, not evidence that the new lab has already delivered a defense.
The other side of the plan is to use AI in security work. Upwind says it wants to build agents that can investigate incidents, connect related signals, check their reasoning and eventually take action with guardrails. The company says that requires enough context from live systems for an agent to understand workloads, identities, networks, vulnerabilities and data—not just the ability to discuss a security alert.
Upwind says the lab currently has 12 developers and researchers from Aegis and Upwind.
Upwind plans to grow the team to about 25 people within three months.
Upwind says the lab could eventually grow to 35 people; that figure is a possibility, not a hiring commitment.
What comes out of the lab
The lab is also meant to do work that may not become a customer product. Upwind proposes benchmarks, datasets and evaluations built around security scenarios to test whether frontier AI models can reason through problems such as attack paths and whether a vulnerability can be exploited. It also lists longer-range projects, including systems for retrieving relevant information, maintaining context and investigating threats autonomously.
Upwind says some projects will become products, while others will result in research, benchmarks or open technical work. Its stated aim in combining Aegis’s technology with Upwind’s platform is to shorten the path from identifying an attack technique to making a defense available to businesses. The lab’s output will therefore be judged on more than its research agenda: the unanswered question is which of these proposed capabilities becomes usable, and when.
Sources
- upwind.ioBuilding the Future: Introducing the Upwind AI Security Lab - Upwind
- thenextweb.comUpwind acquires Aegis to build AI Security Labs
- ynetnews.comUpwind acquires Israeli AI security startup Aegis, launches new cyber research lab
Reader comments
Newest comments first. Replies stay oldest first.