a16z Backs Neo, a New Security Startup Built to Control AI Agents in the Enterprise
Andreessen Horowitz (a16z) has led a $100 million funding round for Neo, a startup focused on securing autonomous AI agents and agentic software inside enterprises. The company emerged from stealth on July 29, 2026, backed by a16z, Bessemer Venture Partners, Craft Ventures, and Merlin Ventures. Neo was founded by veterans of SentinelOne, Wiz, and Palo Alto Networks, three of the most successful enterprise security companies of the past decade.
The timing reflects a fundamental shift in how enterprise software operates. According to Gartner projections cited in the announcement, only 5 percent of enterprise applications featured agentic capabilities in 2025, but that number will jump to 40 percent by the end of 2026. Agentic software refers to AI systems that can reason, act independently, invoke tools, and move through workflows without constant human direction. This represents a departure from traditional software, which follows predictable, predetermined paths.
Why Does Enterprise Security Need to Rethink Its Approach?
Traditional enterprise security was designed for a different era of software. Security teams built systems to monitor human users accessing known applications through established data pathways. Agentic systems break that model. They can act independently, inherit user permissions, chain multiple tools together, and move across workflows in ways that appear legitimate to older security tools. This creates a visibility and control gap that existing security architectures cannot easily address.
Nick Warner, Neo's CEO and co-founder, explained the core challenge: "Enterprise security was built for a world where software behaved predictably. That world is changing fast. AI agents and agentic capabilities are being embedded into browsers, developer tools, SaaS platforms, and traditional applications, giving software the ability to reason, act, invoke tools, and move through workflows with valid user permissions".
Nick Warner, Neo's CEO and co-founder
"Enterprise software is becoming agentic, changing how applications behave, what they can access, and how work gets done. Employees are rapidly adopting AI agents and software vendors are embedding agentic capabilities into products enterprises already use. Organizations need visibility into what this software can do and the ability to govern its behavior in real time," said Zane Lackey, General Partner at Andreessen Horowitz.
Zane Lackey, General Partner at Andreessen Horowitz
The problem is compounded by the speed of adoption. Employees are adopting new AI tools from the bottom up, while established software vendors are adding agentic functions into products already approved for enterprise use. Security operations (SecOps) teams are being asked to govern autonomous software operating inside approved applications, often without the visibility or control mechanisms necessary to do so.
What Does Neo's Platform Actually Do?
Neo's platform provides SecOps teams with a real-time control layer designed specifically for agentic software. The company will use the $100 million in funding to scale its go-to-market and engineering teams as enterprises prioritize security initiatives around rapid agentic adoption.
The platform offers several core capabilities:
- Neoverse-Powered Software Inventory: SecOps teams receive a full inventory of AI agents, AI-enabled applications, plugins, extensions, Model Context Protocol (MCP) servers, and traditional software becoming agentic, enriched by Neoverse, Neo's continuously updated knowledge base of agentic software capabilities, risks, and behaviors.
- Capability and Risk Intelligence: Neo helps teams understand what agentic and non-agentic software can do, what it can access, and whether it is configured safely.
- Real-Time Attribution: Each action produces an audit trail, tying activity back to the human, agent, application, or identity responsible.
- Granular Software Control: Organizations can enforce group- or identity-specific policies for tool calls, API access, data movement, and agentic workflows.
- Native Enforcement: Neo enforces controls natively, enabling organizations to block risky activity, malicious models, and redirect out-of-bounds prompts without handing enforcement off to another tool.
Elliott Robinson, a partner at Bessemer Venture Partners, emphasized the importance of execution in this emerging category: "Agentic AI is creating a new security category as enterprise environments transform, becoming largely composed of software that can reason, act, and invoke tools on its own. Neo combines a clear architectural view of how to control this new software layer with a founding team that has built enterprise-grade security platforms at scale before. That combination matters in a crowded market. Vision is important, but execution will determine the companies that define this next era of security, and Neo is tackling one of agentic security's hardest problems".
"AI is fundamentally changing how software operates inside the enterprise, creating an entirely new control and security challenge. Neo is building the real-time control layer enterprises need to understand, govern, and secure agentic software at scale," noted Michael Robinson, Partner at Craft Ventures.
Michael Robinson, Partner at Craft Ventures
How Should Security Teams Prepare for Agentic Software?
As agentic capabilities proliferate across enterprise applications, security teams need to take several steps to maintain visibility and control:
- Inventory All Agentic Tools: Begin by cataloging every AI agent, AI-enabled application, browser extension, and traditional software that has gained agentic capabilities across your organization, including those adopted by employees without IT approval.
- Understand Capabilities and Permissions: For each agentic tool, document what it can do, what data it can access, what APIs it can call, and what permissions it inherits from users or systems.
- Establish Attribution and Audit Trails: Implement systems that can trace every action taken by agentic software back to the responsible human, agent, or application, creating a complete audit trail for compliance and incident response.
- Enforce Granular Policies: Move beyond broad allow/deny rules to implement identity-specific and group-specific policies that govern tool calls, API access, and data movement at the software layer itself.
- Monitor for Behavioral Anomalies: Since agentic systems can act independently and chain tools together, security teams need real-time monitoring to detect when software behaves in unexpected ways or attempts to access resources outside normal patterns.
Why Does a16z's Backing Matter?
a16z's participation in Neo's funding round signals the venture capital firm's confidence in both the market opportunity and the founding team's ability to execute. The firm has been actively investing in AI infrastructure and security startups, and Neo represents a category that did not exist two years ago. The $100 million funding round reflects the urgency enterprises feel around securing agentic software as adoption accelerates.
Neo's founding team brings deep expertise in building and scaling enterprise security platforms. CEO Nick Warner designed and built the go-to-market organization at SentinelOne and served as COO when the company went public in 2021. He has over two decades of cybersecurity leadership experience, including senior roles at Cylance, McAfee, and Forcepoint. Co-founder Shlomi Salem previously led detection engineering at SentinelOne for more than a decade and co-led the in-house threat research team. Co-founder Eran Shirazi previously co-founded customer experience company EasySend and led large enterprise research and development programs after years leading the Israeli Defense Force's Unit 8200 vulnerability research group.
The convergence of rapid agentic adoption, the lack of existing security controls, and a founding team with proven execution experience creates the conditions for Neo to become a category-defining company in enterprise security. As enterprises move from pilot projects to widespread deployment of agentic software, the demand for real-time visibility and control will only intensify.