3 Sources
[1]
Neo exits stealth with $100M from a16z and Bessemer to build a control layer for agentic AI software
Neo emerged from stealth on Monday with $100 million in funding from Andreessen Horowitz and Bessemer Venture Partners, with Craft Ventures and Merlin Ventures also participating. The company, founded by former SentinelOne, Wiz, and Palo Alto Networks executives, is building what it calls a real-time control layer for agentic software in the enterprise. The problem it addresses: AI agents are being embedded into browsers, developer tools, SaaS platforms, and legacy applications faster than security teams can track them. The scale of the shift is the pitch. Only 5% of enterprise applications had agentic capabilities in 2025, according to Gartner. By the end of 2026, 40% will. That means software that can reason, act, invoke tools, chain workflows, and inherit user permissions is proliferating inside environments where security was built for deterministic applications and human users. Neo gives SecOps teams an inventory of every AI agent and agentic-enabled app running across the organisation, scores their capabilities and risks, maps actions back to the responsible user or agent, and enforces policy before risky activity occurs. "Enterprise security was built for a world where software behaved predictably. That world is changing fast," said CEO Nick Warner, who designed SentinelOne's go-to-market operation and took the company public in 2021. Straiker raised $64M for a similar agentic security play earlier this year, and the category is forming rapidly as every major enterprise software vendor adds autonomous capabilities to products already approved for internal use. The security challenge is not rogue AI tools. It is approved software that has quietly gained the ability to act on its own. Neo's platform covers AI agents, AI-enabled applications, browser extensions, MCP servers, plugins, and traditional software acquiring agentic features. It enforces controls natively, blocking risky tool calls, API access, and data movement without handing enforcement to another product. NewCore raised $66M to give AI agents corporate identities, addressing the authentication side of the same problem. Neo is betting that the bigger market is the control layer: not who the agent is, but what it is allowed to do. At $100 million in seed-stage capital, a16z and Bessemer are betting that whoever builds that layer first owns the category.
[2]
Investing in Neo | Andreessen Horowitz
The endpoint security market is entering its third generation. The first was antivirus: static signatures, easily evaded, built for a world of known malware. The second was behavioral detection and response such as SentinelOne, CrowdStrike, and the EDR category they created, which watched process behavior instead of file hashes and became the standard enterprise defense for over a decade. In both of those generations, the assumption was that the endpoint followed a familiar pattern: A human clicks, a program runs, and security tooling watches for the process to misbehave. That assumption no longer holds. AI agents now run directly on the endpoint with the same privileges as the user they serve, reading files, executing code, calling APIs, and moving data between apps. Microsoft embedding Copilot into Windows made this the default configuration for the modern enterprise. The interactions on the endpoint have fundamentally changed and every control built on the old assumption (EDR, DLP, Zero Trust) breaks the moment it can no longer tell whether an action came from the person at the keyboard or the agent acting in their name. This is not a gap incumbents can patch. They built durable platforms for the behavioral-detection era, and reworking that architecture to attribute every action and intent to both humans and synthetic agents would mean rebuilding from scratch. Most will add basic AI discovery as a feature, but this new problem requires a complete rethink of what security means in the agentic age. Neo is built for this new generation from the ground up. Rather than attempting to retrofit yesterday's approach, Neo is pioneering agentic software control for a world where AI agents act continuously, often outnumbering the humans they serve. Its core bet is that security has to anchor back to a few simple questions at the moment of execution: is this action coming from a real, verified person or is it coming from an agent, is that agent configured with the correct guardrails, and what happens when malicious or negligent activity occurs. Answering that in real time, and enforcing it autonomously, is what the tools out there today were never built to do. Neo's founders are as strong as they come in security. Nick Warner scaled SentinelOne through its IPO in multiple executive leadership roles. Shlomi Salem spent over 11 years leading threat research at SentinelOne. Eran Shirazi brings deep technical grounding and prior experience co-founding and serving as CTO of EasySend. Together, they combine the commercial instincts, security depth, and credibility with top-tier security talent that this category demands. The shift from antivirus to EDR created category-defining companies. We believe this new shift is at least just as large, and arguably more urgent. We're proud to have led Neo's Seed round and to partner with Nick, Shlomi, Eran, and the rest of the Neo team as they build the security layer the agentic endpoint requires.
[3]
Neo Security bags $100M to build the secure control layer for enterprise AI agents
Agentic software control startup Neo Security Inc. said today it is exiting a years-long spell in "stealth" mode after raising $100 million in funding. The round was led by top tier venture capitalists in Andreessen Horowitz and Bessemer Venture Partners, and saw participation from Craft Ventures and Merlin Ventures. They're betting that enterprises are going to need purpose-built security to safeguard their increasingly autonomous artificial intelligence systems, and likely need it soon. Built by former executives and engineers from SentinelOne Inc., Wiz Inc. and Palo Alto Networks Inc., Neo aims to provide security operations teams with the inventory, posture intelligence, attribution and policy controls needed to manage and secure AI agents across entire organizations. The growing adoption of autonomous AI agents that can conduct work unsupervised on behalf of humans is happening at such rapid speed that traditional security systems cannot keep pace, and it means that the attack surfaces of organizations are changing and expanding faster than ever. Enterprises are adding AI-native tools, but the bigger concern is that even the traditional software they use is integrating agentic capabilities. Because of this, SecOps teams are being asked to secure autonomous software that's operating inside approved applications, but they lack the necessary control and visibility to do that properly. As per Gartner Inc., just 5% of enterprise applications had agentic features at the end of last year, but more than 40% will by the end of 2026. Co-founder and Chief Executive Nicholas Warner said existing enterprise security systems were built for a world where software behaved in a predictable way, but that's no longer true when those tools have agentic features within them. "AI agents and agentic capabilities are being embedded into browsers, developer tools, SaaS platforms and traditional applications, giving software the ability to reason, act, invoke tools, and move through workflows with valid user permissions," he said. This means that traditional software is altogether much riskier than before. It's this challenge that Neo wants to take on, introducing a real-time control layer that can fend off attacks on these evolving tools. It works by giving SecOps teams a way to inventory the full suite of agentic tools running across their enterprise, even as they add new agent functionality. This means they can understand their updated capabilities and the new risks they introduce, assess whether they're still configured safely, and then change their security policies in the event that a tool is no longer deemed safe. Andreessen Horowitz General Partner Zane Lackey said that when applications add agentic capabilities, it significantly changes how those apps behave, the things they can access, and the possible damage they can do. "Organizations need visibility into what this software can do and the ability to govern its behavior in real time," he said. "Neo's team has built category-defining security platforms before, and we believe they're uniquely positioned to build the control layer this new generation of enterprise software requires." The problem with agentic systems is that they can act independently, mimic the behavior of humans, inherit advanced security permissions from them, and move across workflows in ways that might seem legitimate to legacy security tools built for older, deterministic software. They include the Neoverse-powered software inventory, which continuously details and updates a record of every AI agent, AI-enabled application, plugin and extension, MCP servers and traditional software that has embedded its own agentic capabilities. Neo also provides capability and risk intelligence that shows what those agentic tools can do, what they can access and how they're configured, plus real-time attribution tools that ensure each agent action leaves a transparent audit trail, so its work can always be checked. There are granular software control tools for enforcing group- or identity specific security policies for tool calls, API access, data movement and agentic workflows, and finally, native enforcement controls that can instantly block risky activity and malicious models. Going forward, Neo plans to use the funds from today's round to scale its engineering and go-to-market teams to meet the rapidly growing demand for more safeguards to secure the agentic AI revolution.
Share
Copy Link
Neo Security emerged from stealth mode with $100 million in funding from Andreessen Horowitz and Bessemer Venture Partners to address a critical gap in enterprise security. Founded by former SentinelOne, Wiz, and Palo Alto Networks executives, the company is building a real-time control layer for agentic AI as autonomous capabilities spread rapidly across enterprise applications, creating security challenges that traditional tools cannot address.
Neo has emerged from stealth mode with $100 million funding led by Andreessen Horowitz and Bessemer Venture Partners, with additional participation from Craft Ventures and Merlin Ventures
1
. Founded by former executives from SentinelOne, Wiz, and Palo Alto Networks, the company is building what it describes as a real-time control layer for agentic AI software operating within enterprise environments3
.
Source: Andreessen Horowitz
The startup addresses a pressing challenge: autonomous AI agents are being embedded into browsers, developer tools, SaaS platforms, and legacy applications faster than SecOps teams can track them. CEO Nick Warner, who previously scaled SentinelOne through its IPO in 2021, emphasized that enterprise security was built for predictable software behavior—a reality that no longer holds as agentic AI software proliferates
1
.The scale of transformation driving Neo's mission is significant. According to Gartner, only 5% of enterprise applications had agentic capabilities in 2025, but that figure will surge to 40% by the end of 2026
1
3
. This means software that can reason, act, invoke tools, chain workflows, and inherit user permissions is spreading rapidly inside environments where AI security infrastructure was designed for deterministic applications and human users.The security challenge isn't rogue AI tools operating outside approved channels. Instead, it's approved software that has quietly gained the ability to act independently. Microsoft embedding Copilot into Windows made this the default configuration for modern enterprises, fundamentally changing interactions on the endpoint
2
. Traditional controls like EDR, DLP, and Zero Trust break down when they cannot distinguish whether an action came from a person at the keyboard or the agent acting in their name.Neo's platform provides security for AI agents by giving SecOps teams comprehensive inventory of every AI agent and agentic-enabled application running across the organization. The system scores their capabilities and risks, maps actions back to the responsible user or agent, and enforces policy enforcement before risky activity occurs
1
.
Source: SiliconANGLE
The platform covers AI agents, AI-enabled applications, browser extensions, MCP servers, plugins, and traditional software acquiring agentic features. It enforces controls natively, blocking risky tool calls, API access, and data movement without delegating enforcement to another product
1
. Neo also provides real-time control through attribution tools that ensure each agent action leaves a transparent audit trail, allowing organizations to verify and review agentic workflows3
.Related Stories
Andreessen Horowitz General Partner Zane Lackey positioned Neo as pioneering the third generation of endpoint security. The first generation relied on antivirus with static signatures, while the second introduced behavioral detection through companies like SentinelOne and CrowdStrike
2
. Both generations assumed a human clicks, a program runs, and security tooling watches for misbehavior—an assumption that no longer holds when enterprise AI agents run with the same privileges as the users they serve.Lackey noted this isn't a gap incumbents can patch through updates. "They built durable platforms for the behavioral-detection era, and reworking that architecture to attribute every action and intent to both humans and synthetic agents would mean rebuilding from scratch," he explained
2
. Neo's approach anchors security back to fundamental questions at the moment of execution: is this action from a verified person or an agent, is that agent configured with correct guardrails, and what happens when malicious or negligent activity occurs.The growing adoption of autonomous AI agents conducting work unsupervised means attack surfaces of organizations are changing and expanding faster than ever
3
. These systems can act independently, mimic human behavior, inherit advanced security permissions, and move across workflows in ways that might seem legitimate to legacy security tools built for older, deterministic software.Neo's founding team brings credibility to tackle this challenge. CEO Nick Warner designed SentinelOne's go-to-market operation and took the company public. Co-founder Shlomi Salem spent over 11 years leading threat research at SentinelOne, while Eran Shirazi brings technical depth from co-founding and serving as CTO of EasySend
2
.At $100 million in seed-stage capital, the investment signals that Andreessen Horowitz and Bessemer are betting whoever builds the control layer for agentic AI first owns the category
1
. Straiker raised $64 million for a similar agentic security play earlier this year, and NewCore raised $66 million to give AI agents corporate identities, addressing the authentication side of the same problem. Neo is betting the bigger market is the control layer—not who the agent is, but what it is allowed to do. The company plans to use the funding to scale its engineering and go-to-market teams to meet rapidly growing demand for safeguards securing the agentic AI revolution3
.Summarized by
Navi
[1]
[2]
15 Jun 2026•Technology

22 Apr 2026•Startups

16 Jun 2026•Technology

1
Technology

2
Science and Research

3
Policy and Regulation
