Neo Exits Stealth With $100M to Build Security Control Layer for Agentic AI Software

3 Sources

Share

Neo Security emerged from stealth mode with $100 million in funding from Andreessen Horowitz and Bessemer Venture Partners to address a critical gap in enterprise security. Founded by former SentinelOne, Wiz, and Palo Alto Networks executives, the company is building a real-time control layer for agentic AI as autonomous capabilities spread rapidly across enterprise applications, creating security challenges that traditional tools cannot address.

Neo Secures $100 Million to Build Control Layer for Agentic AI

Neo has emerged from stealth mode with $100 million funding led by Andreessen Horowitz and Bessemer Venture Partners, with additional participation from Craft Ventures and Merlin Ventures

1

. Founded by former executives from SentinelOne, Wiz, and Palo Alto Networks, the company is building what it describes as a real-time control layer for agentic AI software operating within enterprise environments

3

.

Source: Andreessen Horowitz

Source: Andreessen Horowitz

The startup addresses a pressing challenge: autonomous AI agents are being embedded into browsers, developer tools, SaaS platforms, and legacy applications faster than SecOps teams can track them. CEO Nick Warner, who previously scaled SentinelOne through its IPO in 2021, emphasized that enterprise security was built for predictable software behavior—a reality that no longer holds as agentic AI software proliferates

1

.

Enterprise AI Agents Expanding Across 40% of Applications by 2026

The scale of transformation driving Neo's mission is significant. According to Gartner, only 5% of enterprise applications had agentic capabilities in 2025, but that figure will surge to 40% by the end of 2026

1

3

. This means software that can reason, act, invoke tools, chain workflows, and inherit user permissions is spreading rapidly inside environments where AI security infrastructure was designed for deterministic applications and human users.

The security challenge isn't rogue AI tools operating outside approved channels. Instead, it's approved software that has quietly gained the ability to act independently. Microsoft embedding Copilot into Windows made this the default configuration for modern enterprises, fundamentally changing interactions on the endpoint

2

. Traditional controls like EDR, DLP, and Zero Trust break down when they cannot distinguish whether an action came from a person at the keyboard or the agent acting in their name.

Real-Time Attribution and Policy Enforcement for Agentic AI Software

Neo's platform provides security for AI agents by giving SecOps teams comprehensive inventory of every AI agent and agentic-enabled application running across the organization. The system scores their capabilities and risks, maps actions back to the responsible user or agent, and enforces policy enforcement before risky activity occurs

1

.

Source: SiliconANGLE

Source: SiliconANGLE

The platform covers AI agents, AI-enabled applications, browser extensions, MCP servers, plugins, and traditional software acquiring agentic features. It enforces controls natively, blocking risky tool calls, API access, and data movement without delegating enforcement to another product

1

. Neo also provides real-time control through attribution tools that ensure each agent action leaves a transparent audit trail, allowing organizations to verify and review agentic workflows

3

.

Third Generation of Endpoint Security Emerges

Andreessen Horowitz General Partner Zane Lackey positioned Neo as pioneering the third generation of endpoint security. The first generation relied on antivirus with static signatures, while the second introduced behavioral detection through companies like SentinelOne and CrowdStrike

2

. Both generations assumed a human clicks, a program runs, and security tooling watches for misbehavior—an assumption that no longer holds when enterprise AI agents run with the same privileges as the users they serve.

Lackey noted this isn't a gap incumbents can patch through updates. "They built durable platforms for the behavioral-detection era, and reworking that architecture to attribute every action and intent to both humans and synthetic agents would mean rebuilding from scratch," he explained

2

. Neo's approach anchors security back to fundamental questions at the moment of execution: is this action from a verified person or an agent, is that agent configured with correct guardrails, and what happens when malicious or negligent activity occurs.

Expanding Attack Surfaces Demand AI Agent Security Solutions

The growing adoption of autonomous AI agents conducting work unsupervised means attack surfaces of organizations are changing and expanding faster than ever

3

. These systems can act independently, mimic human behavior, inherit advanced security permissions, and move across workflows in ways that might seem legitimate to legacy security tools built for older, deterministic software.

Neo's founding team brings credibility to tackle this challenge. CEO Nick Warner designed SentinelOne's go-to-market operation and took the company public. Co-founder Shlomi Salem spent over 11 years leading threat research at SentinelOne, while Eran Shirazi brings technical depth from co-founding and serving as CTO of EasySend

2

.

At $100 million in seed-stage capital, the investment signals that Andreessen Horowitz and Bessemer are betting whoever builds the control layer for agentic AI first owns the category

1

. Straiker raised $64 million for a similar agentic security play earlier this year, and NewCore raised $66 million to give AI agents corporate identities, addressing the authentication side of the same problem. Neo is betting the bigger market is the control layer—not who the agent is, but what it is allowed to do. The company plans to use the funding to scale its engineering and go-to-market teams to meet rapidly growing demand for safeguards securing the agentic AI revolution

3

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved