AI Infrastructure Security

Neo Launches With $100M to Secure the Enterprise's Shift to Agentic Software

Neo emerged from stealth with $100 million and a pitch that enterprise software is turning agentic faster than security teams can track it. The startup, built by former SentinelOne, Wiz, and Palo Alto Networks veterans, is selling a control layer that inventories agentic software, attributes its actions, and blocks the risky ones before they run.

Updated on July 20, 2026
Neo Launches With $100M to Secure the Enterprise's Shift to Agentic Software

Neo, a Boston security startup, emerged from stealth on July 20, 2026, with $100 million to secure the wave of agentic software moving into enterprises. The company took the funding from Andreessen Horowitz and Bessemer Venture Partners, with Craft Ventures and Merlin Ventures also participating, and it calls itself an agentic software control company. Its founding team comes from SentinelOne, Wiz, and Palo Alto Networks, which is a large part of why two of the biggest names in venture capital wrote a check this size on day one.

Neo is aiming at a problem its founders argue existing security tools were never built to see. Software that used to behave predictably is gaining the ability to reason, call tools, and move through workflows on its own, often carrying a real employee's permissions while it does so. The company is selling a real-time control layer meant to tell a security team what agentic software is running, what it can do, who or what is behind each action, and where to stop it.

"Enterprise security was built for a world where software behaved predictably. That world is changing fast. AI agents and agentic capabilities are being embedded into browsers, developer tools, SaaS platforms, and traditional applications, giving software the ability to reason, act, invoke tools, and move through workflows with valid user permissions. Neo gives enterprises the real-time control layer they need to understand what agentic software can do, govern how it behaves, and secure adoption without slowing down the business."

Nick Warner, CEO and Co-Founder, Neo

The launch is a bet that securing agentic software is a category of its own rather than a feature of the tools companies already run. It also arrives in a part of the market that is filling up quickly, a point that even Neo's own backers make out loud.

Conditions Driving This Change

  • Employees are adopting AI agents from the bottom up, bringing autonomous software into companies faster than security teams can inventory or approve it.

  • Established software vendors are adding agentic features to products enterprises already run, so tools that were reviewed and cleared as static applications quietly gain the ability to act on their own.

  • Gartner projects that agentic capabilities, which appeared in about 5 percent of enterprise applications in 2025, will reach 40 percent of them by the end of 2026.

  • Agentic software can act independently, inherit a user's permissions, chain tools together, and move across workflows in ways that look legitimate to security tools built for an earlier era.

  • Security teams are being asked to govern autonomous behavior inside approved business applications, often without a way to see what that software can do or to stop it in real time.

  • Attribution has become harder, because an action taken by an agent under a user's credentials needs to be traced back to the agent rather than blamed on the person whose permissions it borrowed.

  • Investors are treating agentic security as a fundable new category, which has drawn a crowd of startups and incumbents toward the same control-layer problem.

"Enterprise software is becoming agentic, changing how applications behave, what they can access, and how work gets done. Employees are rapidly adopting AI agents and software vendors are embedding agentic capabilities into products enterprises already use. Organizations need visibility into what this software can do and the ability to govern its behavior in real time. Nick, Shlomi, Eran, and the Neo team have built category-defining security platforms before, and we believe they're uniquely positioned to build the control layer this new generation of enterprise software requires."

Zane Lackey, General Partner, Andreessen Horowitz

Neo Platform capability

What it does

Capability and Risk Intelligence

Assesses what agentic and traditional software can do, what it can reach, and whether it is configured safely

Granular Software Control

Enforces group- and identity-specific policies for tool calls, API access, data movement, and agent workflows

Native Enforcement

Blocks risky activity and malicious models and redirects out-of-bound prompts without handing enforcement to another tool

Neoverse-Powered Software Inventory

Catalogs AI agents, AI-enabled applications, plugins, extensions, MCP servers, and software turning agentic, drawing on Neo's Neoverse knowledge base

Real-Time Attribution

Ties each action back to the human, agent, application, or identity responsible, producing an audit trail

What AI Security Looked Like Before This

Enterprise security tools were designed around a set of assumptions that held for a long time. Applications did what they were configured to do, humans were the ones taking actions, and data moved along paths a security team could map in advance. A firewall, an endpoint agent, or an identity system could reason about that world, because the actors in it were people and the software mostly sat still.

Agentic software breaks those assumptions quietly. An application that a company approved as a static tool can gain a feature that lets it reason and act, and it does so under the permissions of whoever is using it, which makes its activity look like ordinary user behavior. A security tool watching for a human doing something unusual has little to say about an agent doing something permitted but unintended.

The result was a growing blind spot inside approved software. Companies could see their sanctioned applications and their human users, and they had little visibility into the autonomous behavior appearing inside those same applications. Attribution suffered most, because an action an agent took with a user's credentials landed in the logs as the user's action, which is a poor foundation for either security or accountability.

What It Looks Like Now

Neo is selling a layer that sits where that behavior happens. The Neo Platform builds an inventory of agentic and traditional software, from AI agents and AI-enabled applications to browser extensions and MCP servers, and enriches it with a knowledge base the company calls Neoverse that tracks what those tools can do and how they can go wrong. On top of the inventory it adds capability and risk assessment, real-time attribution, policy enforcement, and the ability to block a risky action natively rather than passing the job to another product.

The founders' track record is doing a lot of the work in the market's response. Nick Warner built and ran the go-to-market organization at SentinelOne and served as its chief operating officer when it went public in 2021, Shlomi Salem led detection engineering there for more than a decade, and Eran Shirazi previously co-founded a software company and led a vulnerability research group in the Israeli military's Unit 8200. The backers are betting that a team which has built enterprise security platforms before can build one for agents.

"Agentic AI is creating a new security category as enterprise environments transform, becoming largely composed of software that can reason, act, and invoke tools on its own. Neo combines a clear architectural view of how to control this new software layer with a founding team that has built enterprise-grade security platforms at scale before. That combination matters in a crowded market. Vision is important, but execution will determine the companies that define this next era of security, and Neo is tackling one of agentic security's hardest problems."

Elliott Robinson, Partner, Bessemer Venture Partners

Our Take

AI Security Take

The problem Neo describes is real, and GAIG has been documenting its edges for months, from agent tooling that can be turned with a poisoned file to an autonomous agent that recently breached a major AI platform. Software that acts on its own inside approved applications is a genuine gap between the security tools most companies run and the behavior those tools were built to watch. A layer that inventories agentic software, attributes its actions, and enforces policy where the action happens is a sensible shape for an answer.

The harder question is the one Bessemer's own partner named, which is that the market is crowded and execution will decide it. Neo is describing capabilities that overlap with several groups of vendors at once, including the agent-identity companies, the runtime-enforcement and gateway platforms, and the AI security tools already selling discovery and control, so a buyer will have to work out where Neo's native enforcement and its software inventory genuinely differ from what those others provide. A hundred million dollars and a proven team buy a strong start, and the platform still has to show it does something the incumbents cannot.

Related Articles

AI Governance Platforms vs Monitoring vs Security vs Compliance AI Policy & Standards

Mar 1, 2026

AI Governance Platforms vs Monitoring vs Security vs Compliance

Read More
OpenAI to acquire Promptfoo Accelerating agentic security testing and evaluation capabilities in OpenAI Frontier AI Runtime Controls

Mar 9, 2026

OpenAI to acquire Promptfoo Accelerating agentic security testing and evaluation capabilities in OpenAI Frontier

Read More
Onyx Security and Kai Launch Agentic AI Security Platforms With $165M in Combined Funding AI Model Security

Mar 12, 2026

Onyx Security and Kai Launch Agentic AI Security Platforms With $165M in Combined Funding

Read More

Stay ahead of Industry Trends with our Newsletter

Get expert insights, regulatory updates, and best practices delivered to your inbox