Neo Launches With $100M as AI Agents Test Enterprise Identity Controls | eWeek

Neo Launches With $100M as AI Agents Test Enterprise Identity Controls

Neo AI agent security platform for real-time enterprise application control

Neo’s platform is designed to help enterprises identify and control AI-enabled applications before they reach sensitive systems. Image: Screenshot from Neo

Written By
eWEEK Staff
eWEEK Staff
Jul 20, 2026
3 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Ordinary business software is gaining the ability to choose tools, access data, and act without step-by-step human direction. Cybersecurity startup Neo has launched from stealth with $100 million in combined seed and Series A funding to help companies identify and control those AI-enabled applications.

The shift gives security teams a new identity problem. They must determine which agents are active, who owns them, what systems they can reach, and whether their access can be restricted or revoked before an automated action causes damage.

Boston-based Neo was founded by former SentinelOne leaders Nick Warner and Shlomi Salem and technology executive Eran Shirazi. The company has tested its software with organizations in financial services, transportation, and energy but has not disclosed their names, its pricing, detailed architecture, or independent performance results.

Autonomous software strains existing access controls

Gartner forecasts that AI agents will appear in 40% of enterprise software applications by the end of 2026, up from less than 5% in 2025. A separate Gartner forecast projects that an average global Fortune 500 company will use more than 150,000 agents by 2028. Only 13% of organizations believe they have appropriate governance in place.

An agent needs an identity or delegated authority to access enterprise systems. That access may rely on an API key, OAuth token, service account, workload identity, or an employee’s permissions.

The risk grows as companies move from copilots to autonomous workflows. Unlike a conventional service account built for a predictable operation, an agent may choose among tools, retrieve information from several applications, and delegate work during the same process.

Security teams must connect each agent to an owner, approved purpose, permission scope, and expiration policy. Recent research into the enterprise AI governance gap also found that many organizations lack centralized visibility into their AI systems and cannot fully trace automated decisions to the models and data behind them.

Neo is betting that those gaps require a dedicated control layer. It will compete with AI-security startups as well as identity, privileged-access, cloud-security, and secrets-management vendors expanding existing platforms.

Advertisement

Neo still has to prove enforcement works

Neo must first show that it can continuously identify approved and unsanctioned agents across SaaS products, custom applications, low-code tools, browser extensions, models, and third-party integrations.

Enforcement is harder. Google DeepMind’s roadmap for security controls for AI agents outlines monitoring, access restrictions, escalation paths, and blocking mechanisms. Buyers should determine whether Neo can prevent unauthorized actions or only report risky access after detection.

They should also ask whether it supports task-specific permissions, short-lived credentials, approval controls, and reduced authority when one agent delegates work to another. Neo has not publicly documented those capabilities.

NIST launched its AI Agent Standards Initiative on February 17, 2026, with security and identity research among its three pillars. A separate identity and authorization concept paper examines how existing identification, authorization, auditing, and nonrepudiation practices could apply to software agents. Neither effort has created binding requirements.

Neo’s next proof points will be technical documentation, integration coverage, named deployments, and independent testing. Enterprises can begin by inventorying agents, assigning owners, and testing whether current identity systems can trace delegated authority and revoke access across connected applications.

Read more: The emergence of agentic ransomware that adapts during an attack shows why access restrictions and rapid containment must develop alongside autonomous enterprise software.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.