cyberivy
Neo SecurityAI SecurityAI AgentsEnterprise SecuritySecOpsMCPAgentic SoftwareCybersecurity

Neo turns AI agents into the next security surface

July 21, 2026

Drei Gründer von Neo stehen nebeneinander vor einer hellen Wand und schauen in die Kamera

Neo launched with $100 million to make AI agents in enterprise software visible and controllable. The interesting part is not the funding, but the new attack surface.

What this is about

Neo Security emerged from stealth on July 20, 2026 with $100 million in funding. Backers include Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures, and Merlin Ventures. That alone would not make it a strong Cyber Ivy story. The interesting part is the problem Neo is targeting: companies are about to discover that agentic behavior is spreading inside software they have already approved.

The founders come from SentinelOne, Wiz, Palo Alto Networks, and Unit 8200-linked security backgrounds. According to the company announcement, Neo wants to provide a control layer for AI agents, AI-enabled applications, browser extensions, plugins, MCP servers, and traditional software that gains new autonomous capabilities.

What Neo actually does

Neo is not pitching another chatbot interface. Its platform is meant to inventory which agentic capabilities are active inside a company, what data and systems they can reach, and which actions map back to which human, agent, application, or identity. It also promises risk analysis and policies that can block risky tool calls, API access, or data movement.

The core idea is attribution. In classic security models, a human acts inside an application, and logs usually show a user, a device, and a process. With AI agents, that becomes blurry. A user states a goal, the agent calls a tool, a plugin pulls data, a SaaS product performs a step, and everything looks like legitimate work. Neo wants to make that chain readable.

Why it matters

The relevant number in Neo’s material is a Gartner estimate: only 5 percent of enterprise applications had agentic capabilities in 2025, but 40 percent are expected to have them by the end of 2026. You do not have to accept the forecast blindly to understand the risk. Browsers, development environments, CRM systems, office suites, and support platforms are already adding autonomous functions.

That creates a new security surface inside approved software. This is harder than an unknown tool that an administrator can simply block. If a pre-approved system suddenly reads emails, closes tickets, moves files, or calls APIs, security teams need more than a denylist. They need to understand what the software is allowed to do, what it actually does, and where human approval remains necessary.

In plain language

Imagine an office where every door used to be opened by an employee badge. Now desks get small assistants that walk around using their owner’s badge and complete tasks. That can be useful. But the security team must know which assistant opens which door and why.

A practical example

A sales team uses 120 SaaS tools and introduces an AI agent that prepares offers. The agent can read CRM data, check prices in a spreadsheet, and draft messages in the email system. It processes 3,000 customer cases per week. Without control, an export of 500 records may look like normal user activity. With an agent control layer, the company could see that the export was triggered not directly by a human, but by an agent through a plugin.

A policy can then apply: offers may be prepared automatically, but customer-data exports above 50 records require approval. These boundary cases decide whether AI agents create productivity or quiet data movement.

Scope and limits

First, Neo is still a new company despite the large funding round. Whether the platform works reliably in complex, mixed enterprise environments remains to be proven in real deployments.

Second, a control layer does not fix poor permissions. If users have too many rights, agents often inherit too many rights. Without a clean identity and data model, the risk stays high.

Third, the market is loud and full of similar security promises. What matters is whether Neo can enforce policies inside applications, not merely provide inventory and dashboards. For security leaders, the right question is therefore not: do we need one more tool? It is: can we explain today which AI agents act inside approved software and with which permissions?

SEO & GEO keywords

Neo Security, AI agent security, agentic software control, enterprise AI security, SecOps, MCP security, AI software inventory, Andreessen Horowitz, Bessemer Venture Partners, SentinelOne

💡 In plain English

Neo wants to show which AI agents act inside enterprise software and which permissions they use. The simple problem is this: once software starts taking actions itself, classic user controls are no longer enough.

Key Takeaways

  • Neo emerged from stealth on July 20, 2026 with $100 million in funding.
  • The platform targets AI agents, AI-enabled applications, browser extensions, plugins, and MCP servers.
  • The key issue is attribution: companies need to map actions to humans, agents, applications, and identities.
  • According to Gartner’s estimate, 40 percent of enterprise applications could have agentic capabilities by the end of 2026.
  • Neo’s value depends on whether it can enforce policies inside applications, not just show dashboards.

FAQ

Is Neo just another AI tool?

No. Neo positions itself as a security and control layer for other AI agents and AI-enabled applications.

Why is approved software risky?

Because it already has permissions and data access. Once it gains autonomous functions, it can do more than older security models expect.

What should companies check now?

They should inventory which applications have agent features, what permissions they use, and which actions require human approval.

Sources & Context