Share with your CISO
Island is betting that the browser, not the firewall or the identity provider, is where enterprise security will ultimately be won or lost. The Dallas-based company closed a $400 million Series F at a $6.4 billion valuation, more than doubling its 2024 mark, with Evolution Equity Partners leading and Sequoia and Coatue among the participants. Founded in 2022, Island has doubled ARR every fiscal year and now employs around 1,000 people. The new capital funds expansion of its governance platform to cover both human employees and autonomous AI agents across browsers, endpoints, networks, and data.
What this means for your business
The AI agent problem arriving on CISOs’ desks right now is not primarily a model problem. It is a permissions and observability problem. An AI agent browsing internal applications, pulling from data repositories, and executing transactions on behalf of a user inherits all the access risk of that user, plus the additional risk that no human is watching in real time. Most existing security stacks were built to govern people, not processes acting autonomously at machine speed. Where you sit on this depends on one thing: whether your AI deployment roadmap already has a governance layer attached to it, or whether you are about to build agents on top of access controls that were never designed for them.
Island’s architectural argument is that the browser is the only control point that touches every interaction, human or agent, regardless of which cloud, application, or network is underneath. That is a coherent position, and the $1 billion in total funding suggests the market finds it credible. But the pitch carries the optimism typical of a company growing into a category it is simultaneously defining. The platform now claims to span last-mile browser control, SASE (the network security layer that routes and inspects traffic), data loss prevention, identity, and observability. Each of those is a mature, competitive market. Consolidating them into a single policy engine is the product vision; whether the integrations are deep enough to replace incumbents in each layer, or merely shallow enough to report on them, is the question enterprise buyers should press hard in a proof of concept.
The leading indicator to watch is not Island’s next valuation round. It is whether CISOs renewing Zscaler, Netskope, or CrowdStrike contracts in the next 12 months start treating Island as a replacement candidate rather than a complement. If Island stays in the “and also” column of the security stack, the consolidation thesis stalls regardless of revenue growth. The AI agent governance angle is the wedge that could change that calculus, because no incumbent owns that problem cleanly yet. The renewal conversation you are already scheduled to have with your SASE or DLP vendor is precisely where this framing deserves a second look.
Concept deep-dive: AI Agent Governance
AI agent governance refers to the controls that determine what an autonomous software agent is allowed to access, do, and record when it acts inside enterprise systems without a human approving each step. Think of it as the policy layer that answers four questions in real time: who or what is acting, what systems can it reach, what data can it touch, and should this specific action be permitted. Without it, every agent deployment inherits whatever permissions its sponsoring user holds, with no audit trail and no circuit breaker.
Based on reporting from Island Raises $400 Million Series F At $6.4 Billion Valuation To Expand Enterprise AI Security Platform, originally published 2026-09-24 15:31:00.

