Neo Security bags $100M to build the secure control layer for enterprise AI agents

WorkAI.TV Editorial Desk
4 Min Read

Share with your CISO

Neo Security is betting $100 million that the biggest unsolved problem in enterprise security isn’t a new attack vector but a new category of attacker, autonomous AI agents embedded inside software your organization already approved. Backed by Andreessen Horowitz and Bessemer Venture Partners, the stealth-mode startup built by veterans from SentinelOne and Wiz is launching a real-time control layer for agentic software that inventories every AI-enabled tool, maps its permissions and capabilities, and enforces granular policy in real time. Gartner puts agentic features in 5% of enterprise apps today and 40% by end of 2026.

What this means for your business

The stat worth sitting with is that 40% figure, because it means the threat surface isn’t theoretical and it isn’t distant. If your organization runs any modern SaaS stack, developer tooling, or productivity suite, you almost certainly already have agentic capabilities running under existing user permissions, inside applications your security team approved for a much simpler, deterministic version of that software. Whether Neo is relevant to you right now depends on how fast your vendors are shipping agent features and whether your current tooling can even see them.

The underlying problem Neo is solving has a specific shape that makes it structurally hard for incumbents to address. Traditional endpoint and identity security was built on the assumption that software does what it was told, predictably, and that humans take the actions that cross security boundaries. Agents break both assumptions. They inherit valid user credentials, they reason across workflows rather than following a fixed path, and they can move data or invoke APIs in ways that look legitimate to legacy detection tools because, technically, they are legitimate. That’s not a signature problem that existing vendors can patch. It requires a different observability model, one built around what software can do rather than what it’s currently doing.

The real risk for CISOs isn’t that they miss the Neo pitch. It’s that they treat agentic security as a 2027 budget conversation while vendors ship agentic updates in their Q3 releases. The vendors talking their book here are obvious, a16z has every incentive to declare a new category early, but the Gartner projection and the SentinelOne-Wiz pedigree on the founding team are independent signals worth weighting. I’d revisit this call if the 40% Gartner figure proves inflated, because the urgency collapses with the adoption curve. Until then, the right question isn’t whether to budget for agentic security but which of your current SaaS renewals already includes an agent capability your team hasn’t inventoried.

Concept deep-dive: Agentic permissions inheritance

When an AI agent is embedded in a SaaS tool, it doesn’t get its own access credentials. It operates under the permissions of the human user who installed or authorized it, meaning it can read, write, and act anywhere that user can. Think of it as hiring a contractor and handing them your employee badge. The agent’s actions look authorized because they are, by proxy, which is exactly why standard identity and access monitoring won’t flag the behavior as suspicious.

Based on reporting from Neo Security bags $100M to build the secure control layer for enterprise AI agents, originally published 2026-07-20 12:06:00.

TAGGED:
Share This Article