On July 20, 2026, Neo Security emerged from stealth with $100 million in funding from Andreessen Horowitz and Bessemer Venture Partners, with Craft Ventures and Merlin Ventures also participating. The Boston-based startup, founded in August 2025 by former SentinelOne, Wiz, and Palo Alto Networks executives, is building what it calls a real-time control layer for agentic software in the enterprise.

The launch signals that the agentic security category has moved from a theoretical concern to a funded priority. Enterprise software is becoming autonomous faster than any security team can inventory it.

The Scale of the Problem

Last year, 5% of enterprise applications featured agentic capabilities. By the end of 2026, Gartner projects that number will hit 40%. A separate Gartner forecast estimates that the average global Fortune 500 company will run more than 150,000 agents by 2028. Only 13% of organizations believe they currently have appropriate AI governance in place.

That trajectory is not a slow-moving shift. It is a structural change to the enterprise software layer arriving inside an 18-month window.

The challenge is not only the new AI-native tools that employees are adopting. The deeper exposure comes from software organizations already use: CRM systems, HR platforms, finance tools, productivity suites. These applications are gaining autonomous capabilities with no procurement review required. When an enterprise approves a SaaS product, it approves whatever agentic capabilities that vendor ships into it, including features that can invoke tools, chain workflows, access sensitive data, and act without step-by-step human direction.

“Most companies are flying blind,” CEO Nick Warner told ISMG. “They need to better understand the software that’s in their environment, the software that’s being downloaded in their environment and how that software is currently running in this agentic world.”

As we examined in our analysis of the enterprise AI adoption readiness gap, governance is the primary blocker preventing organizations from capturing returns on their AI investments. Neo is building the infrastructure layer that makes governance operationally possible.

Five Capabilities the Existing Security Stack Cannot Provide

Neo’s platform addresses a set of problems that no existing category of security tool was designed to solve. The key gap is visibility: traditional endpoint detection, SIEM, and cloud security tools were built to watch deterministic software with predictable behavior. AI agents behave differently. They can act independently, mimic human users, inherit permissions, and move through systems in ways that appear legitimate to every legacy detection tool.

Neo CapabilityWhat It Solves
Neoverse Software InventoryContinuously catalogs every AI agent, plugin, extension, MCP server, and agentic-enabled application across the enterprise
Capability and Risk IntelligenceMaps what each tool can access, how it is configured, and what risks it introduces as capabilities change
Real-Time AttributionCreates an audit trail tying every agent action to the responsible human, agent, or application
Granular Software ControlEnforces identity- or group-level policies for tool calls, API access, and data movement
Native EnforcementBlocks risky activity and malicious models directly without handing off enforcement to another product

The enforcement architecture is a deliberate design choice. SiliconAngle reports that Neo operates directly on the endpoint rather than routing AI traffic through a cloud proxy. This matters because AI activity is increasingly moving off the browser and onto local systems: coding assistants, desktop applications, and locally running models that never traverse enterprise networks. A gateway-based approach watching HTTP traffic misses a growing share of what enterprise AI agents actually do.

“A lot of old detection tools tried to look at software code,” Warner explained. “But now, what you actually need to look at are a lot of plain English instructions.” Neo uses AI to analyze the AI sessions it is watching, a recursive approach that gives it structural advantages over security tooling designed for binary software behavior.

The Team That Built SentinelOne’s Platform

The three co-founders have direct experience building the security platforms that defined the previous enterprise generation.

Nick Warner designed SentinelOne’s go-to-market organization and, as COO, took the company public in 2021 after more than five years in senior leadership. Before that, he led worldwide sales at Cylance and advanced technology sales at McAfee. Shlomi Salem spent over a decade at SentinelOne leading detection engineering and co-running the threat research team that built its adversary intelligence platform. Eran Shirazi co-founded customer experience company EasySend and led vulnerability research for the IDF’s Unit 8200.

That combination of go-to-market, threat research, and technical product leadership mirrors the founding team composition that SentinelOne used to become a public company. The investors noticed.

Andreessen Horowitz General Partner Zane Lackey, who led the investment, was direct about the thesis: “Nick, Shlomi, Eran, and the Neo team have built category-defining security platforms before, and we believe they’re uniquely positioned to build the control layer this new generation of enterprise software requires.”

Bessemer Venture Partners Partner Elliott Robinson framed the bet around category formation rather than product features: “Vision is important, but execution will determine the companies that define this next era of security, and Neo is tackling one of agentic security’s hardest problems.”

A New Category, Not a Feature Addition

Neo is not alone in the space, and The Next Web notes the category is forming with speed. Straiker raised $64M earlier in 2026 for an agentic AI security play focused on the browser and prompt-level controls. NewCore raised $66M to give AI agents corporate identities and formalized authorization, addressing the authentication side of the same problem.

Neo’s positioning is explicitly at the control layer rather than the identity layer: not who the agent is, but what it is allowed to do across the full enterprise software stack. At $100 million in combined funding, this is the largest single commitment the market has seen specifically for that problem.

The reason a distinct control layer is necessary rather than a feature addition to existing platforms connects directly to the discovery challenge. As we covered in our analysis of agentic resource discovery protocols, enterprises cannot govern what they cannot inventory. The ARD standard addresses how agents can self-declare their capabilities. Neo’s Neoverse approach inverts that: rather than waiting for agents to report themselves, it actively discovers what agentic software is running across the environment, whether or not that software participates in any standard protocol.

Both approaches are necessary. Standards solve interoperability for cooperating systems. Active discovery solves governance for the long tail of agentic-capable SaaS that ships updates with no coordination with enterprise security teams.

What Enterprise Leaders Should Do Now

Neo has not published pricing, detailed architecture documentation, or named customer references. eWeek reports that the company has tested its platform with organizations in financial services, transportation, and energy but has not disclosed those deployments publicly. The next proof points will be technical documentation, integration coverage across the SaaS stack, and independent performance testing.

That validation work takes time. The agentic adoption wave is not waiting for it.

The most practical starting point for security and operations leaders is inventory. Before evaluating any vendor, teams should map which applications in their environment have acquired agentic capabilities, what permissions those applications hold, and whether current identity systems can trace or revoke delegated agent authority. According to Warner, that discovery step alone surfaces gaps that most organizations do not know they have.

The enterprises that begin that inventory now are the same ones that will be able to enforce policy and respond to incidents when those capabilities become the default across the software stack. At the current adoption pace, that is not a 2027 or 2028 problem. According to Gartner’s projection, 40% of enterprise apps will have agentic capabilities by December 2026. The security posture for that environment needs to be in place before the software arrives.

If your organization is assessing where agentic security fits in your AI deployment roadmap, book a call with Enera to work through the governance gap before it becomes an incident.