TL;DR

Neo raised $100M from a16z and Bessemer to build a real-time control layer for agentic AI software in enterprises. 5% of apps were agentic in 2025. 40% will be by end of 2026.

Neo emerged from stealth on Monday with $100 million in funding from Andreessen Horowitz and Bessemer Venture Partners, with Craft Ventures and Merlin Ventures also participating. The company, founded by former SentinelOne, Wiz, and Palo Alto Networks executives, is building what it calls a real-time control layer for agentic software in the enterprise. The problem it addresses: AI agents are being embedded into browsers, developer tools, SaaS platforms, and legacy applications faster than security teams can track them.

The scale of the shift is the pitch. Only 5% of enterprise applications had agentic capabilities in 2025, according to Gartner. By the end of 2026, 40% will. That means software that can reason, act, invoke tools, chain workflows, and inherit user permissions is proliferating inside environments where security was built for deterministic applications and human users. Neo gives SecOps teams an inventory of every AI agent and agentic-enabled app running across the organisation, scores their capabilities and risks, maps actions back to the responsible user or agent, and enforces policy before risky activity occurs.

Enterprise security was built for a world where software behaved predictably. That world is changing fast,” said CEO Nick Warner, who designed SentinelOne’s go-to-market operation and took the company public in 2021. Straiker raised $64M for a similar agentic security play earlier this year, and the category is forming rapidly as every major enterprise software vendor adds autonomous capabilities to products already approved for internal use. The security challenge is not rogue AI tools. It is approved software that has quietly gained the ability to act on its own.

Neo’s platform covers AI agents, AI-enabled applications, browser extensions, MCP servers, plugins, and traditional software acquiring agentic features. It enforces controls natively, blocking risky tool calls, API access, and data movement without handing enforcement to another product. NewCore raised $66M to give AI agents corporate identities, addressing the authentication side of the same problem. Neo is betting that the bigger market is the control layer: not who the agent is, but what it is allowed to do. At $100 million in seed-stage capital, a16z and Bessemer are betting that whoever builds that layer first owns the category.