The same people who taught us to fear malware are now selling us protection from our own AI.
The Summary
- Neo, founded by former SentinelOne execs, raised $100M Series A to build security tools for autonomous AI agents
- Companies are deploying AI agents faster than they can track them, creating "zombie agents" that run unsupervised with access to critical systems
- Neo's pitch: enterprises need visibility and control layers before agent sprawl becomes a breach vector
The Signal
Neo launched with a thesis that sounds obvious only after someone says it out loud. Every company building agents is optimizing for deployment speed. Almost none are thinking about what happens when 50 agents are running across your infrastructure and nobody remembers who authorized the one pulling customer data at 3am.
The founders saw this coming because they built careers on a similar pattern. At SentinelOne, they sold endpoint protection after companies realized every laptop was a potential intrusion point. Now they're making the same bet on agents. The unit economics are different, but the fear is the same. You can't secure what you can't see.
"Agent sprawl is the new shadow IT, except the shadow has root access and runs 24/7."
What makes this raise interesting is the timing and the check size. $100 million for a Series A says investors believe the agent security category is real and moving fast. Index Ventures and Sequoia co-led, which means both firms think this is a platform play, not a feature. They're betting Neo becomes the de facto control plane for enterprise agent deployments.
The technical problem is harder than it sounds. Traditional security tools monitor human behavior. Agents don't behave like humans. They execute thousands of micro-tasks, make autonomous decisions, and interact with APIs in ways that look like attacks but aren't. Neo's approach involves building behavior baselines for each agent, tracking permissions drift, and flagging anomalies in real-time.
Key capabilities Neo is building:
- Agent inventory and lifecycle management across clouds
- Permission auditing for agents with database or API access
- Kill switches for agents exhibiting unexpected behavior
The market they're targeting is enterprises that have moved past POCs and are operationalizing agents at scale. That's a narrow band today, but it's widening fast. Every company running agents in production is either building internal tooling for this problem or waiting for someone to sell them a solution. Neo is betting most will buy rather than build.
The competitive landscape is messy. Cloud providers are adding agent monitoring features. Observability companies like Datadog are expanding into agent telemetry. But Neo has a structural advantage: they're security-native. They're building for compliance officers and CISOs, not just DevOps teams. That matters when the conversation shifts from "can we deploy agents" to "can we prove to auditors that our agents aren't leaking PII."
The Implication
If you're running agents in production, you should have answers to three questions right now. How many agents are live. What data they can access. Who can shut them down. If you don't know, you're the customer Neo is building for. The fact that they raised nine figures before most companies have even asked those questions tells you how fast this problem is arriving.
Watch for Neo to push hard into financial services and healthcare first. Those are the sectors where "we don't know what our agents are doing" becomes a regulatory incident fastest. The playbook is the same one SentinelOne ran: land with security teams, expand into ops, become mandatory infrastructure. The difference this time is the attack surface isn't devices. It's intelligence itself.