Artificial intelligence agents are moving from proof of concept experiments into the everyday plumbing of large enterprises. That shift creates a new class of invisible software operators that can take actions, move data and make decisions with far less human oversight than traditional applications. Neo, a Boston based cybersecurity startup that has just come out of stealth with 100 million dollars in early financing, is positioning itself as one of the first serious attempts to put guardrails around that world of agentic software before it gets out of hand. Backers have provided Neo with 100 million in combined seed and Series A capital from Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures and Merlin Ventures to expand its engineering and go-to-market teams.
Why this funding round matters now
On 20 July 2026 Neo publicly launched with a total of 100 million dollars in combined seed and Series A funding led by Andreessen Horowitz and Bessemer Venture Partners, with participation from Craft Ventures and Merlin Ventures. For a company at this stage that is a very large war chest, especially in a market where many security and AI startups are raising far less. It signals that some of the most experienced enterprise and infrastructure investors are treating agent security and control as a foundational layer, not a niche add on.
Neo describes its focus as agentic software control, meaning security and governance for software entities that initiate actions, hold permissions and persist inside corporate environments even when no one is actively managing them. That includes AI agents, AI enabled business applications, browser extensions, plug in components, and other autonomous capabilities that sit between users, data and core systems.
The funding also lands at a moment when enterprise software is quickly gaining these agentic capabilities. Gartner has projected that by 2026 around 40 percent of enterprise applications will include agentic features, up from about 5 percent in 2025, which implies a rapid expansion of semi autonomous behavior inside corporate estates. If that shift continues, security teams will be dealing not just with vulnerable applications, but with fleets of machine operators acting on behalf of humans and systems.
From endpoint security to agentic control
Neo was founded by former SentinelOne executives, including Nick Warner and Shlomi Salem, who spent years building and scaling endpoint security platforms for large enterprises. SentinelOne grew up in the era when signature based antivirus tools were no longer enough and defenders needed behavioral monitoring and response directly on endpoints such as laptops and servers.
The founders are now arguing that something similar is happening with AI and modern software. In their view, agentic systems are closer to human operators than to static code modules. They can chain actions across multiple applications and services, maintain state over time, and use widely scoped credentials to move through an environment. This resembles a new class of machine driven operators that require continuous monitoring, behavioral control and rapid shutdown mechanisms when they drift outside acceptable policy.
Neo’s American and Israeli roots also echo a familiar pattern in cybersecurity, where transatlantic founding teams have repeatedly produced significant companies by combining US go to market depth with Israeli technical and security expertise. The company is headquartered in Boston and draws heavily on talent networks in both ecosystems.
What Neo is actually building
Neo positions its platform as a real time control layer that sits between AI powered or autonomous software and the enterprise environment. In practical terms the company says it gives security operations teams an inventory of agentic software across the organization, including AI agents, AI enabled applications, browsers, identities and more traditional software components.
According to the company and its backers, this layer provides several core capabilities. It discovers which agents and AI infused components exist, who owns them, what permissions they hold and where they operate in the environment. It then applies policy controls and behavioral guardrails so that security teams can constrain what those agents are allowed to do with data, identities and infrastructure. This is crucial in light of the misplaced trust that can occur with AI-generated outputs.
Neo highlights that it can analyze both conventional binary software and newer non binary elements such as AI skills, plug ins and browser extensions. The goal is to surface what many CISOs now worry about but cannot see clearly. These are orphaned or long forgotten workflows, automations and agents that were created for one purpose, then left running even as owners moved roles or left the company, or as business processes changed.
Neo aims to identify such entities, map their behavior, and then either sandbox them, restrict them by policy or safely deactivate them if needed. The company’s public materials emphasize that the platform is built for security operations teams rather than for AI researchers or data scientists. It promises inventory, attribution and enforcement that feel more like endpoint or network control tools than like model observability dashboards. That framing matters because it determines who inside an enterprise will actually own and operate these controls.
The structure and signal of the 100 million dollar raise
Several details of the financing are worth unpacking. Neo’s 100 million dollars combines earlier seed capital with a larger Series A round that brings in Andreessen Horowitz and Bessemer Venture Partners alongside Craft Ventures and Merlin Ventures. Earlier reporting indicates that Neo raised around 25 million dollars in a seed round in 2025, followed by more than 50 million dollars in a subsequent round, with the combined total now publicly framed as 100 million dollars of early funding.
Public disclosures note that Neo has not yet shared revenue figures, customer counts, named reference customers, valuation or the specific allocation between seed and Series A tranches. That lack of detail is common for companies at this stage, but it also reminds observers that this is a very early bet on a category rather than a later stage validation of product market fit.
The investor mix is telling. Andreessen Horowitz and Bessemer have deep histories in both cybersecurity and infrastructure software, and have backed several leading endpoint and cloud security companies over the past decade. Craft Ventures and Merlin Ventures bring additional experience in go to market scaling and security specific company building. That blend of capital suggests a belief that agentic control will become part of the long term enterprise security stack, not a passing feature wave.
Neo has indicated that it will use the capital to scale engineering and go to market teams, and to help enterprises manage the security risks that accompany rapid adoption of AI agents and autonomous business software. In other words, this is fuel for building the core product and proving the category, not for broad expansion into many adjacent areas.
Why enterprises are suddenly worried about AI agents
To understand the bet on Neo, it helps to look at how enterprise AI adoption has evolved. In the first wave, companies primarily experimented with chatbots and copilots that helped employees draft content or answer questions. Those systems were largely bounded by existing user permissions and did not independently initiate actions.
The next wave is different. Enterprises are now wiring AI systems into workflow tools, identity systems, customer support platforms and even code deployment pipelines. Many of these systems introduce agents that can act on behalf of users or teams. They might create tickets, change configurations, manipulate documents, trigger external services or move money within defined limits.
Several risks follow naturally. Control surfaces multiply as every team experiments with its own automations, browser extensions and embedded AI features. Ownership becomes murky when experimental agents are handed from one team to another or simply left running. Documentation tends to lag behind reality, especially in large organizations where people change roles often. Traditional security tools are not designed to inventory or understand the behavior of an agent that lives partly in a browser, partly in a SaaS tool and partly in a cloud function.
Security leaders are also grappling with the fact that these agents do not just process data, they can cause side effects. An agent that misinterprets instructions or is manipulated by a malicious prompt might revoke permissions, misconfigure resources or exfiltrate data through legitimate channels. As these systems grow more capable, they become attractive targets for attackers, who will look for ways to hijack or impersonate trusted agents rather than directly compromising users.
This is the world in which Neo is trying to define agentic software control as a discipline. The company’s platform is meant to give security teams a living map of this ecosystem, so that agents are treated less like mysterious black boxes and more like operational units that can be audited, governed and, when necessary, shut down.
Opportunities and risks of the agentic control thesis
If Neo and similar companies succeed, enterprises could gain a much more mature way of adopting AI. Instead of blocking new tools out of fear, security teams could allow experimentation while relying on an independent control layer to keep behavior within acceptable bounds. That is similar to how endpoint detection platforms once allowed organizations to support remote work and bring your own device programs without losing visibility into what was happening on endpoints.
For technology vendors, the existence of an independent agent control platform might actually accelerate adoption. Application providers could focus on building useful autonomous features while relying on external guardrails for policy and enforcement. In some cases, it might even become a selling point that a product integrates cleanly into an enterprise agent inventory and control plane.
However, several uncertainties remain. First, the market itself is still being defined. Many security and platform companies are exploring adjacent ideas, including AI specific monitoring, model security, data access governance and identity centric controls. It is not yet clear where the boundaries between these categories will settle, or whether agentic control will stand alone or be absorbed into broader platforms.
Second, success will depend on whether Neo can integrate deeply enough with the variety of environments that real enterprises run. Agentic behavior is emerging inside SaaS tools, custom applications, browser environments, identity platforms and infrastructure services. Delivering consistent visibility and control across all of those contexts is a significant engineering challenge.
Third, there is an adoption question inside organizations. Security teams already juggle many consoles and data sources. Neo and similar platforms will need to prove that they reduce complexity rather than add another stream of alerts. They will also need to navigate internal politics between security, IT, data and AI teams about who owns which pieces of the agent lifecycle.
Finally, there is an inherent trust issue. A control platform that can disable or modify autonomous processes is itself a high value target. Any company operating in this space will be judged not only on its features, but also on its own security posture, transparency and incident response capabilities.
How this fits into the broader AI governance landscape
Neo’s emergence is part of a broader trend where AI governance is moving from policy documents and risk frameworks into concrete technical controls. Over the past few years, organizations have experimented with guidelines for prompt engineering, model selection and data usage. Those efforts are necessary but not sufficient when software is acting autonomously in complex environments.
Technical governance layers such as Neo’s platform can complement higher level policy by encoding rules into systems that sit close to the actual behavior of agents. For example, a policy that says AI agents must not exfiltrate customer data becomes meaningful only when there is a system that can observe agent actions and block data movement that violates that policy.
At the same time, agentic control is not a substitute for other safeguards. Robust identity and access management, least privilege design, secure software development practices and vendor risk management all remain essential. In practice, a mature enterprise AI security posture will likely combine these traditional controls with new capabilities that are specific to autonomous behavior.
If this ecosystem develops as some investors expect, there may eventually be standard ways for agents and applications to declare their capabilities, permissions and provenance to control platforms. That could make it easier to reason about complex systems and to detect unexpected or malicious behavior. Neo is one of the early companies trying to push the industry in that direction.
Key takeaways and what to watch next
A few conclusions stand out from Neo’s launch and funding.
Neo puts a name and a dedicated product category around a real emerging problem: fleets of semi autonomous agents and AI infused components that operate with significant permissions and limited oversight inside enterprises.
The company is very early but heavily funded, with 100 million dollars in combined seed and Series A capital from investors with deep experience in security and infrastructure software. That level of backing is a strong signal that agentic control is expected to become a long term part of the enterprise security stack rather than a passing fad.
Neo’s founding team brings prior experience from SentinelOne and from building large scale enterprise security products, which matters in a space where real world integration and operational reliability often matter more than novel algorithms.
For practitioners, the most important questions over the next eighteen to twenty four months will be whether platforms like Neo can deliver accurate discovery across diverse environments, meaningful behavioral controls that do not drown teams in noise and smooth integration with existing security workflows.
More broadly, the rise of companies like Neo is a reminder that the AI story in enterprises is no longer just about models and prompts. It is about how to manage fleets of machine operators that act across systems with speed and persistence that humans cannot match. The organizations that succeed with AI at scale will likely be those that pair ambitious automation with equally ambitious control and governance.
Conclusion
Neo’s 100 million dollar raise is a turning point in how enterprises think about AI security and governance. It signals that the problem is no longer just model safety or data privacy but the unseen layer of abandoned and autonomous AI agents quietly operating inside corporate systems.
Neo steps out of stealth with serious capital
Neo has emerged from stealth with 100 million dollars in funding led by Andreessen Horowitz and Bessemer Venture Partners, with participation from Craft Ventures and Merlin Ventures. The company is based in Boston and was founded by former SentinelOne executives including Nick Warner, a profile that places it squarely in the tradition of seasoned cybersecurity teams building infrastructure for new technology waves.
The funding spans seed and Series A rounds and is earmarked for scaling both engineering and go to market efforts as enterprises rush to deploy agentic software. This is not a speculative bet on a future market. It is capital aimed at an urgent need that security operations teams are already feeling as AI agents spread across applications, browsers, identities and traditional software.
Neo describes itself as an Agentic Software Control company. Its platform promises real time inventory, intelligence, attribution and policy control across AI agents and AI enabled applications, giving security teams a single control layer to see which agents exist, what they can do, and who is responsible for them. In effect Neo is trying to become the governance and safety plane for autonomous software inside the enterprise.
How we got here The rise of agentic AI and invisible risk
To understand why a control platform for AI agents now attracts nine figure funding, it helps to look at the last decade of enterprise technology.
In the cloud era companies struggled first to find unmanaged virtual machines and shadow infrastructure, then to secure a growing sprawl of APIs and microservices. Endpoint security evolved from classic antivirus to behavioral detection as devices became more powerful and always connected. Each wave created a visibility problem and then a control problem. AI is following the same pattern, but faster.
Enterprises are now embedding AI agents into customer support tools, internal workflow systems, data pipelines and browser based automations at remarkable speed. Analyst projections cited in coverage of Neo note that agentic capabilities may jump from a small share of enterprise applications in 2025 to a much larger share by 2026. When almost half of the software in a company can make autonomous decisions and call tools, the risk profile changes dramatically.
Security practitioners have started to draw attention to the phenomenon of zombie or abandoned AI agents and APIs. These are agents created for experiments, proofs of concept or one off automations that never get fully decommissioned. They retain credentials and tool access, continue to run on schedules or triggers, and often fall outside normal security reviews. Research on exposed secrets and forgotten APIs indicates that large organizations routinely leak hundreds of credentials per hundred employees each year, underscoring how easy it is for an old agent somewhere to still have powerful access.
The result is a growing class of orphaned AI agents created by developers or teams that have moved on, with nobody clearly accountable for what those agents still do. This is the risk that Neo wants to make visible and controllable.
What Neo actually does in the stack
Neo’s platform is built to give security operations teams a living inventory of agentic software across the enterprise. It aims to discover AI agents, AI enabled applications, browser automations, identities and traditional software that operate with autonomous capabilities. On top of that inventory Neo attaches capability and risk intelligence, mapping which data sources agents touch and which tools they can invoke.
Attribution is a key piece of the design. Neo ties agents back to owners or responsible teams, answering basic but often missing questions such as who created this agent, what environment it runs in, and which credentials it uses. Once that map exists, policy control becomes possible. Security teams can define what classes of agent behavior are allowed, restrict access to sensitive tools and data, and enforce rules such as mandatory sandboxing or human approval for high risk actions.
From a systems perspective Neo is positioning itself as a real time control layer similar in spirit to what identity providers or cloud access security brokers did for earlier generations of technology. Those platforms did not replace the underlying services. Instead they sat across them, adding visibility, governance and fine grained policy enforcement. Neo’s bet is that AI agents now need the same kind of dedicated layer.
Why abandoned AI agents are becoming a board level concern
The idea of abandoned AI agents may sound abstract, but the underlying risk is very concrete.
First, agents often hold long lived credentials. Many were built using personal API keys or shared secrets that never got rotated when a developer left or a team restructured. If those credentials grant access to production data or financial systems, an old agent can become an unintended backdoor. Second, agents can chain tools. An innocuous looking workflow that reads a dataset can in some cases trigger other actions including code execution, data exfiltration or changes to systems of record if tool boundaries are not clearly enforced.
Third, traditional monitoring rarely treats agent activity as high risk authentication. Logs may record the calls but do not flag when an agent suddenly queries far more data or touches sources it never accessed before. Without dedicated guardrails, prompt injection attacks and manipulated inputs can drive agents to misuse their tools in ways that bypass existing controls.
Security experts now recommend steps that echo the design principles behind Neo. These include building a comprehensive inventory of all agents by scanning codebases for AI API calls, tracing each to its authentication method and documenting data access and tools. They also call for sandboxed environments, strict least privilege on credentials, automatic key rotation, circuit breakers for abnormal behavior and explicit logging of every tool invocation as a high risk event. Neo’s platform is essentially an attempt to standardize and automate these practices at scale for large enterprises.
Opportunities for enterprises and for Neo
For enterprises the upside of a control layer for AI agents is straightforward. It can reduce unknown unknowns, shrink the surface area of orphaned agents and make it easier to adopt new AI capabilities without losing governance. It also offers a way to respond to regulatory pressure. As AI oversight frameworks from regulators and standard bodies evolve, companies that can demonstrate clear inventories, ownership and enforced policies around autonomous systems will be better positioned to show compliance.
For Neo the opportunity lies in becoming part of the default security stack for AI in the same way identity providers became default for access management. The company has the advantage of experienced cybersecurity leadership and top tier backers, which strengthens its credibility with enterprise buyers who are wary of unproven security tools. The timing aligns with a surge in agentic adoption and increased board level scrutiny of AI risk.
At the same time there are significant challenges.
Enterprise environments are heterogeneous and often fragmented across clouds, legacy systems and multiple AI vendors. Discovering agents across all of those surfaces and keeping that inventory accurate in real time is technically demanding. The platform will need deep integration with developer tooling, orchestrators and security monitoring systems, as well as robust approaches to avoid false positives that can erode trust from security teams.
There is also a competitive dynamic. Other security vendors are beginning to add AI specific features to their existing platforms, from agent activity monitoring to prompt injection defenses. Neo will have to show that a dedicated agentic control layer is not only necessary but meaningfully better than incremental features bolted onto existing tools. That case will rest on how well it can capture and act on the full lifecycle of agents rather than individual events.
How this changes the AI governance conversation
Historically AI governance in enterprises has focused on model management, data privacy and ethical use of AI outputs. The arrival of agentic software shifts the conversation from static models to dynamic systems that can act, call APIs and affect real operations. Governance now needs to account for the life of an agent from creation through modification to retirement.
Neo’s emergence with substantial funding makes that lifecycle the center of attention. By framing the problem as agentic software control rather than just AI security, it emphasizes accountability and operational governance as much as technical protection. This resonates with lessons from past waves. Cloud governance only matured when companies treated infrastructure as something that needed clear ownership and policy, not just better firewalls.
If Neo and others in this space succeed, AI governance frameworks inside companies will likely evolve to include questions such as
Who owns each agent and how is that ownership documented
What data sources and tools can this agent access and under what conditions
How is behavior monitored and what thresholds trigger circuit breakers or human review
When and how is an agent retired and how are its credentials revoked
These are practical questions that boards and regulators can understand and that security teams can operationalize with the right tooling.
What to watch next
For readers at AiFlowNews the key takeaways are clear.
Neo’s 100 million dollar raise is evidence that agentic AI security is now a defined market, not a niche concern. The company is betting that enterprises will need a dedicated control layer to discover, attribute and govern both active and abandoned AI agents across their environments.
In the near term the most important signals will be how quickly Neo can demonstrate real deployments in complex organizations and whether customers report measurable reductions in unknown agents and credential risk. Over the next few years the broader test will be whether platforms like Neo become standard components of AI infrastructure alongside model hosting, data platforms and identity providers.
Enterprises that are already experimenting heavily with autonomous agents should treat this moment as a prompt to audit their environments, build basic inventories and adopt strong practices around credentials, sandboxing and monitoring, regardless of which tools they choose. Doing that groundwork will make it far easier to evaluate and integrate any agentic control platform.
The deeper shift is that AI safety and governance are moving from abstract debates about alignment and ethics to concrete questions about orphaned agents, exposed secrets and policy enforcement in production systems. Neo’s funding round does not solve those problems by itself. It does mark a significant step in recognizing that the invisible layer of agentic software inside companies needs the same level of attention and control that earlier generations of infrastructure eventually received.








