Island Raises $400M: The Agentic Control Plane for Enterprise AI
Enterprises are deploying AI agents faster than they can govern them. Island just raised $400 million to close that gap.
On September 24, 2026, Island, the Dallas-based enterprise security company, announced a $400 million Series F at a $6.4 billion valuation, more than doubling its valuation from 2024. Evolution Equity Partners led the round, with Sequoia Capital, Coatue Management, Prysm Capital, Cyberstarts, Insight Partners, J.P. Morgan Growth Equity Partners, Alta Park Capital, Georgian, G Squared, Squarepoint, and cybersecurity entrepreneur Dmitri Alperovitch all participating.
The company’s ARR has doubled every fiscal year. Island now employs 1,000 people and plans to reach 1,500 by mid-2027 as it expands into Europe, Asia, and the Middle East.
The funding round is a data point in a broader shift: enterprise AI security is no longer primarily about stopping external attackers. It is about governing what internal AI agents are allowed to do.
From Enterprise Browser to Agentic Control Plane
Island launched as an enterprise browser, the first company to argue that embedding security directly into the application where employees work is more effective than intercepting traffic from outside it. That insight proved correct. The company was named a Customers’ Choice in the 2026 Gartner Peer Insights Voice of the Customer for Secure Enterprise Browsers, based on 331 verified reviews, and received the Frost & Sullivan 2026 Global Zero Trust Browser Security Company of the Year award.
Over the past two years, Island expanded beyond the browser into endpoint protection, SASE (Secure Access Service Edge) networking, and data loss prevention. Each expansion extended the same policy engine and audit trail into another surface where enterprise work happens.
The agentic control plane is the logical endpoint of that expansion. AI agents do not live in a single layer of the enterprise technology stack. They run in browsers, on endpoints, across networks, and through APIs. A security product that only sees one of those surfaces can only govern part of what an agent does. Island governs all of it.
“Agents do not operate in a single layer of the technology stack, so they cannot be governed from one,” said Dan Amiga, CTO and co-founder of Island. “Island’s control plane unifies five critical layers: last-mile control, network, data, identity, and observability. Together, they tell the enterprise who or what is acting, what it can reach, what data it can use, what it is doing, and whether that action should be allowed.”
The Governance Gap Driving the Round
The timing of Island’s Series F reflects a specific inflection point in enterprise AI adoption. Organizations that spent 2024 and early 2025 running pilots are now deploying agents at production scale. As that deployment accelerates, a structural gap has emerged: the tools enterprises use to govern human employees do not extend to AI agents.
Human employees are governed through identity systems, application permissions, network controls, and browser policies. AI agents interact with the same applications, the same APIs, and the same data but arrive with none of those existing constraints applied. They may hold persistent API keys, access data outside their intended scope, or take actions that a human employee would never be permitted to take.
This is not a theoretical risk. Enterprise security vendors including Hush Security and Zenity have both raised significant rounds this year addressing specific parts of the agent governance problem, such as just-in-time permissions and agent discovery. Island’s bet is that governance fragmented across point tools creates audit and policy gaps. One control plane covering the full chain of work is more defensible.
Richard Seewald, Founder and Managing Partner at Evolution Equity Partners, framed the investment thesis this way: “Island has already shown it can create a category, displace legacy technologies, and accelerate customers’ business transformation from the browser to the network. By extending its vision to safeguard browsers, endpoints, networks, and data, Island built the essential control layer for the next generation of enterprise computing.”
Island’s Five-Layer Agentic Architecture
Island’s agentic control plane runs across five interconnected layers, all governed by a single policy engine and writing to a single audit trail:
| Layer | What It Controls |
|---|---|
| Last-mile (browser) | Inline control over prompts, tool calls, files, and sub-agent invocations |
| Endpoint | Discovery of every agent, MCP server, skill package, and extension on the endpoint |
| Network | Traffic inspection and policy enforcement across the enterprise network |
| Data | Data loss prevention rules applied to agent outputs and file access |
| Identity and observability | Just-in-time credential issuance, non-human identity management, full audit trail |
The browser layer matters for a specific reason that Island’s engineering team has emphasized: when an AI agent interacts with a web application through a browser, its traffic is indistinguishable from human traffic at the network or endpoint level. Only a control inside the browser can tell them apart and apply different policies.
Four product modules govern the agentic workflow specifically:
Agentic Endpoint Posture discovers every agent running on an endpoint, including its MCP servers, skill packages, and browser extensions, and removes what policy flags as unauthorized.
Agentic Identity inventories non-human identities and issues credentials through an MCP gateway on a just-in-time basis. No agent holds a standing API key with persistent access.
AI Protect enforces policy inline as an agent operates, covering prompts, tool calls, file access, and sub-agent spawning. It returns a reason when blocking an action so the agent can self-correct rather than silently failing.
AI Cost and Experience tracks usage, cost, and performance per agent from live session data rather than estimates, which matters for finance and procurement teams managing AI spend at scale.
All five layers write to a single audit trail exportable for SOC 2, ISO 27001, and EU AI Act conformance requirements.
What This Means for Enterprise AI Leaders
The Island round is a signal, but the signal matters because of what it reveals about how enterprises are thinking about the AI agent adoption problem.
A year ago, the primary concern was whether AI agents could do useful work. That question has largely been answered. The current concern is whether organizations can govern agents at the scale needed to trust them in production. That is a different problem, and it requires infrastructure that most enterprises have not yet built.
Several specific implications stand out:
A single governance layer beats multiple point tools. Agents operate across every surface where enterprise work happens. A governance architecture that covers only some of those surfaces leaves gaps that agents, or attackers using agents, will find. Island’s competitive advantage is five years of investment in browser and network control that it can now apply to agentic activity without a separate integration project.
Just-in-time identity is a non-negotiable for production AI agents. Persistent API keys held by AI agents are a security incident waiting to happen. Organizations running production agents on standing credentials are taking on risk that grows with every agent they add. The credential issuance and revocation pattern Island uses is already the standard for human identity in zero-trust architectures. It is overdue as the standard for agent identity.
The audit trail is the governance product. AI Act compliance, enterprise procurement requirements, and SOC 2 audits all require a record of what automated systems did and why. A control plane that cannot produce that record at the right granularity will fail procurement at regulated enterprises. Island’s single audit trail covering browser, endpoint, cloud, and internal resources is designed specifically to satisfy that requirement.
For enterprise teams evaluating agentic AI governance, the Island round accelerates a market that was already moving fast. To understand how an agentic control layer fits into your organization’s AI deployment architecture, connect with the Enera team.
Sources: Island GlobeNewswire announcement | CNBC coverage | Channel News Asia | Island agentic control plane blog