Share with your CISO
Neo, founded by former SentinelOne executives Nick Warner and Shlomi Salem, launched from stealth with $100 million in seed and Series A funding to build a dedicated control layer for AI agent identity and access management. The bet is that existing identity infrastructure, built for predictable service accounts, breaks down when autonomous software chooses its own tools, delegates tasks mid-process, and borrows employee credentials along the way. Gartner puts 150,000 agents inside an average Fortune 500 firm by 2028, with only 13% of organizations confident they have governance in place.
What this means for your business
If your organization has moved past AI copilots into any degree of autonomous workflow, you already have an agent inventory problem whether or not you’ve named it. The question Neo is wagering on isn’t whether enterprises need visibility into AI agents; Gartner’s numbers suggest that’s settled. The real exposure sits in whichever organization assumes its current identity platform, the system managing who and what can access enterprise resources, scales naturally to cover agents that weren’t designed into its permission model.
Neo’s specific claim deserves scrutiny before it informs a procurement decision. The company has disclosed early deployments in financial services, transportation, and energy, but has named none of them, published no independent benchmarks, and hasn’t publicly documented whether its enforcement is preventive or detective. That distinction matters enormously. A platform that flags a rogue agent after it has already exfiltrated data or triggered a downstream transaction is a forensics tool, not a control. CISOs evaluating this category should press every vendor, not just Neo, on whether they can revoke delegated authority mid-task and constrain what one agent can grant to another, because agentic chains are where conventional least-privilege thinking goes sideways fast.
The competitive landscape here is genuinely unsettled in Neo’s favor for now, but not for the reasons the funding announcement implies. The threat isn’t that dedicated AI-agent security startups will lose to incumbents on brand. It’s that the identity, privileged-access, and secrets-management vendors already have the integrations, the deployment relationships, and the audit trails that enterprises actually trust. Neo has to win on capability before those incumbents ship a credible module. The NIST AI Agent Standards Initiative and its companion identity concept paper signal that binding requirements are probably two to three years out, which means the vendor that owns enterprise deployments during the governance vacuum sets the de facto standard. That’s the clock Neo is actually racing.
Concept deep-dive: Delegated authority in agentic chains
When one AI agent assigns a subtask to another, it may pass along its own access permissions, creating a chain where downstream agents inherit credentials they were never explicitly granted. Think of it like a contractor handing a subcontractor a master key without the building owner’s knowledge. Each handoff can quietly expand the blast radius of a compromised or misbehaving agent. This is why task-specific, short-lived credentials, rather than broad inherited permissions, are the architectural floor any serious agent security platform must support.
Based on reporting from Neo Launches With $100M as AI Agents Test Enterprise Identity Controls, originally published 2026-07-20 12:48:00.

