Neo emerged from stealth on Monday with $100 million in funding from Andreessen Horowitz and Bessemer Venture Partners, with Craft Ventures and Merlin Ventures also participating. The company, founded by former SentinelOne, Wiz, and Palo Alto Networks executives, is building what it calls a real-time control layer for agentic software in the enterprise. The problem it addresses: AI agents are being embedded into browsers, developer tools, SaaS platforms, and legacy applications faster than security teams can track them.
The Rise of Agentic AI
The scale of the shift is the pitch. Only 5% of enterprise applications had agentic capabilities in 2025, according to Gartner. By the end of 2026, 40% will. That means software that can reason, act, invoke tools, chain workflows, and inherit user permissions is proliferating inside environments where security was built for deterministic applications and human users. This rapid adoption is driven by major vendors like Microsoft, Salesforce, and Google embedding autonomous features into products already approved for internal use. The security challenge is not rogue AI tools; it is approved software that has quietly gained the ability to act on its own.
Agentic AI represents a paradigm shift from traditional software that simply executes pre-programmed commands. These agents can make decisions, call external APIs, manipulate data, and iterate on tasks without human intervention. In a typical enterprise, an AI agent might be granted access to a customer relationship management system to update records, or to an internal database to generate reports. However, the permissions model for such agents is often inherited from the user who deploys them, creating a dangerous amplification of privileges. If a compromised agent operates under a user’s credentials, it can cause disproportionate damage by interacting with dozens of systems simultaneously.
Neo's Solution: A Real-Time Control Layer
Neo gives SecOps teams an inventory of every AI agent and agentic-enabled app running across the organization, scores their capabilities and risks, maps actions back to the responsible user or agent, and enforces policy before risky activity occurs. The platform covers AI agents, AI-enabled applications, browser extensions, MCP servers, plugins, and traditional software acquiring agentic features. It enforces controls natively, blocking risky tool calls, API access, and data movement without handing enforcement to another product.
“Enterprise security was built for a world where software behaved predictably. That world is changing fast,” said CEO Nick Warner, who designed SentinelOne’s go-to-market operation and took the company public in 2021. Warner previously held senior roles at Wiz, where he led cloud security initiatives, and at Palo Alto Networks, focusing on next-generation firewall adoption. His co-founders bring deep expertise in AI and infrastructure from their time at those same companies. The team’s combined experience in endpoint security, cloud security, and SaaS governance positions Neo to address a gap that existing security tools cannot fill.
Neo’s architecture is designed for low-latency enforcement, critical for real-time agent actions. It can inspect agent calls to APIs, evaluate the risk of the requested operation against policies, and allow or deny in milliseconds. The platform also provides a unified dashboard that shows the blast radius of each agent—what systems it can reach, what data it can access, and what actions it can perform. Security teams can define policies such as “prevent any agent from accessing finance databases” or “require human approval for agents to execute write operations on production systems.”
Industry Context and Competitive Landscape
Neo is not alone in recognizing the agentic security opportunity. Straiker raised $64 million for a similar agentic security play earlier this year, focusing on detection and response for AI agent behaviors. NewCore raised $66 million to give AI agents corporate identities, addressing the authentication side of the same problem: not just what an agent is allowed to do, but who it claims to be. Neo is betting that the bigger market is the control layer—not who the agent is, but what it is allowed to do.
At $100 million in seed-stage capital, a16z and Bessemer are betting that whoever builds that layer first owns the category. The investment is one of the largest seed rounds in enterprise security history, reflecting the urgency of the problem. Martin Casado, general partner at a16z, noted that “the trajectory of AI adoption in the enterprise is unprecedented, and security models must adapt before incidents occur. Neo’s approach of building a native control layer from day one is the right way to handle this shift.” Bessemer’s David Cowan added, “We’ve seen the dissolution of the network perimeter; now we’re seeing the dissolution of the application boundary. Neo is creating the new perimeter around agent behavior.”
The category is forming rapidly as every major enterprise software vendor adds autonomous capabilities to products already approved for internal use. Microsoft’s Copilot, Salesforce’s Einstein, and Google’s Duet AI are examples of agentic features being integrated into widely deployed tools. These features often operate with broad permissions, relying on the underlying platform’s security rather than granular agent-level controls. Neo aims to provide that granularity independently of the vendor.
Another dimension is the rise of browser-based agents. Extensions like those from Rewind AI and browser automation tools can access any website a user visits, reading and writing data. Neo can discover these extensions and evaluate the risk of their API calls, preventing data exfiltration through unauthorized channels. Similarly, MCP servers—modular control plane servers that manage agent workflows—are becoming a popular pattern in enterprise deployments. Neo integrates with them to enforce policies at the orchestration layer.
Technical Capabilities and Use Cases
Neo’s platform uses a combination of static analysis of agent code and runtime behavioral monitoring. It can inspect the capabilities declared by an agent (e.g., what APIs it claims to need) and compare those against actual behavior. This helps detect “capability creep” where an agent slowly expands its access. The platform also establishes a baseline of normal agent activity and flags deviations that could indicate compromise or misuse.
Use cases include preventing data leakage by blocking agents from sending internal data to external AI models, ensuring compliance by enforcing that agents do not access regulated databases, and reducing risk by requiring human-in-the-loop approval for high-severity actions. For example, a financial services firm might use Neo to ensure that a customer service AI agent can only read customer records, not modify them, and that any attempt to transfer data to a third-party system is blocked automatically.
Neo also provides detailed audit trails for every agent action, which is crucial for regulatory compliance. Organizations subject to GDPR, HIPAA, or SOC2 can demonstrate that agent behaviors are monitored and controlled. The platform integrates with existing SIEM and SOAR systems via APIs, allowing security teams to incorporate agent insights into their broader incident response workflows.
Market Outlook and Adoption
The Gartner prediction that 40% of enterprise applications will be agentic by end of 2026 underscores the urgency. Enterprises that delay deploying agentic security controls risk facing a wave of unmanaged, autonomous software acting on their networks. Neo’s early customers include Fortune 500 companies in healthcare, finance, and technology, according to sources close to the company. The typical deployment begins with discovery—identifying all agentic software currently in use—followed by policy definition and enforcement.
Neo plans to use the $100 million to expand its engineering team, build out go-to-market operations, and accelerate product development. The company has already opened offices in San Francisco and New York, and is hiring for roles in AI security research, platform engineering, and customer success. The founders emphasize that they are building for the long term, with a mission to become the de facto standard for agentic AI governance across the enterprise.