Neo raises $100M to control AI agents

Enterprise security teams can see users, endpoints and approved apps. What they often cannot see is the agent now acting inside those apps. Neo launched with million for that gap: software is starting to reason, call tools and move through workflows, while many security systems still treat it like ordinary software.

Neo said on July 20 that Andreessen Horowitz and Bessemer Venture Partners backed the company, with Craft Ventures and Merlin Ventures participating. The founding team includes veterans of SentinelOne, Wiz and Palo Alto Networks, and the product is framed as “Agentic Software Control.”

The agent inherits the badge

Neo's release argues that browsers, developer tools, SaaS platforms and older enterprise applications are gaining agentic functions. Those functions can use valid employee permissions while acting with more autonomy than the human behind the account.

CEO Nick Warner said enterprise security was built for a world where software behaved predictably. In practice, that world is fading.

The problem is not only shadow AI. Approved software can change its behavior after a vendor ships an agent feature. A single identity may represent a person, a browser extension, an IDE assistant, an MCP server or an automated SaaS workflow.

What the million buys

The headline number is million. Calcalist/CTech breaks it into a million Series A and a previously completed million seed. Official materials and SecurityWeek both confirm a16z, Bessemer, Craft Ventures and Merlin Ventures among the backers.

Neo lists five core capabilities: inventorying AI agents, plugins, extensions, MCP servers and agentic apps; judging what they can access; attributing actions to a human, agent, app or identity; enforcing policies for tool calls, APIs, data movement and workflows; and blocking risky activity inside the software layer.

The 5% to 40% pressure

The company cites Gartner's estimate that agentic capabilities appeared in only 5% of enterprise applications in 2025 but could reach 40% by the end of 2026. SecurityWeek and Calcalist repeat the same frame.

That shifts the audit question. Security teams will not only ask which AI tools employees installed. They will need to know which approved products suddenly gained autonomous behavior, which data those products can touch, and whether every tool call can be replayed.

Neo's own site adds another market claim: enterprises poured billion into endpoint, network and identity security, yet that spend does not cover the layer where agents, plugins and MCP servers now run. The wording is promotional, but the architectural point is useful.

The team is part of the pitch

Calcalist says Neo has about 50 employees, including 40 in Israel. Warner previously served as president and COO of SentinelOne and helped take it public in 2021. Shlomi Salem led detection engineering at SentinelOne for more than a decade. Eran Shirazi previously co-founded EasySend and has Unit 8200 vulnerability research experience.

Merlin Ventures' Shay Michel said every major technology shift creates a new security category, and agentic AI will follow that pattern.

That category is still contested. Some vendors talk about agent identity, others about MCP gateways, browser isolation or coding-agent security. Neo is betting that “software control” can collect those surfaces into one operational view.

For buyers, the first test is basic. List every AI entry point, map inherited permissions, and keep replayable logs of who asked an agent to do what, which tool was called and where data moved. Without those three tables, automated blocking is premature.

Sources: Neo official announcement, SecurityWeek, CocoLoop, Calcalist/CTech, WSJ; checked the million round, million/ million split, Gartner 5%-to-40% agentic-app estimate, 50-person team with 40 in Israel, five platform capabilities and founder backgrounds.