Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software

WorkAI.TV Editorial Desk
4 Min Read

Share with your CISO

Neo is betting that AI agents have already outpaced enterprise security teams’ ability to see or govern them, and $100 million from Andreessen Horowitz, Bessemer, and Craft Ventures says the market agrees. The American-Israeli startup emerged from stealth this week with a control layer for agentic software that catalogs active AI agents and MCP servers (the connectors that let agents call external tools), flags over-privileged configurations, and traces every action back to its originating identity, whether human, agent, or application. CEO Nick Warner previously ran operations at SentinelOne.

What this means for your business

The uncomfortable fact Neo is building on is one most security teams already feel but haven’t formally scoped: AI agents are operating inside enterprise environments right now with credentials, tool access, and workflow permissions that were never explicitly granted to them as autonomous actors. They inherited those rights from the human users or applications that spawned them. If your organization has deployed any AI-assisted developer tools, browser extensions, or SaaS copilots, the attack surface Neo is describing exists in your environment whether you’ve audited it or not.

The founding team’s pedigree is doing real work here. Warner, Salem, and Shirazi built detection and response programs at SentinelOne during the era when endpoint security shifted from signature-based tools to behavioral analytics. That transition looked structurally similar to this one: a new class of software behavior that legacy controls couldn’t see, followed by a scramble to build visibility first and policy enforcement second. Neo is positioning itself at the visibility layer before the enforcement market consolidates, which is historically where durable security franchises get built. The risk is that every major CASB (cloud access security broker, which governs how data moves between enterprise systems and cloud services) and identity vendor is watching the same opportunity.

The vendor to watch here isn’t Neo’s direct competitors; it’s your identity provider. If Okta, Microsoft Entra, or CyberArk extends agent identity management deep enough, a point solution governing agentic behavior becomes redundant before it reaches renewal. The question your next architecture review should answer is whether agent governance is a new control plane that warrants its own tooling, or an extension of identity and access management you already fund. Neo’s pitch assumes the former. Your renewal calendar may force the answer sooner than the category matures.

Concept deep-dive: MCP servers

Model Context Protocol servers are connectors that allow AI agents to call external tools, APIs, and data sources, think of them as the plugin infrastructure that lets an agent browse the web, query a database, or trigger a workflow. They’re increasingly embedded in developer environments and SaaS platforms. Because MCP servers mediate what an agent can actually do, misconfigured or over-permissioned ones represent a discrete class of risk that traditional network or endpoint controls weren’t designed to catch.

Based on reporting from Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software, originally published 2026-07-20 10:54:00.

TAGGED:
Share This Article