AI Cybersecurity Jul 21, 2026 4 min read

Neo raises $100 million to secure the AI features hiding inside enterprise software

Boston-based Neo has emerged from stealth with $100 million to help companies discover and control AI capabilities appearing across their software estates.

Neo raises $100 million to secure the AI features hiding inside enterprise software

Enterprise software is changing faster than many security teams can catalogue it.

A routine application update can add an AI assistant, an autonomous workflow or a connection to a large language model. The software may keep the same name and sit under the same contract, yet gain new abilities to read data, generate content or act across other systems.

Neo, a Boston-based cybersecurity startup, has emerged from stealth with $100 million in seed and Series A funding to address that expanding blind spot. The financing was backed by Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures and Merlin Ventures, according to The Wall Street Journal.

The company was founded by former SentinelOne executives Nick Warner and Shlomi Salem with Eran Shirazi. Its pitch is that enterprises need a continuous inventory of the AI capabilities inside their software—not merely a list of approved applications.

Software inventory is no longer enough

Traditional security programmes assume that an application’s behaviour is reasonably predictable. Teams assess a product, approve it, manage its permissions and revisit the decision when the contract or architecture materially changes.

AI complicates that model. A vendor can introduce generative features through a cloud update. An employee can connect a third-party model to corporate data. A business application can evolve from presenting recommendations to initiating actions.

The security question is therefore shifting from “Which applications do we use?” to “Which AI capabilities are active, what can they access and what are they allowed to do?”

Neo says its platform gives companies visibility into AI-enabled applications, evaluates their capabilities and helps regulate access to sensitive information. The value proposition is a control layer across a fragmented software estate, where AI features may come from major vendors, niche tools or internal integrations.

Why investors are funding an AI control plane

The $100 million total is unusually large for a company just leaving stealth, but the scale reflects a broader bet on enterprise-security architecture.

Businesses are adopting AI through several routes at once: sanctioned copilots, developer tools, customer-service platforms, employee-created automations and software updates that switch on new capabilities. Blocking every tool is commercially unrealistic. Approving them one at a time is increasingly slow. Security vendors see an opportunity in making adoption observable and governable.

That opportunity has produced a crowded vocabulary—AI security posture management, agent security, model governance and data-loss prevention for generative AI. Neo will have to prove that it solves a distinct operational problem rather than adding another dashboard to an already crowded security stack.

Its founders’ SentinelOne background may help with buyers and investors familiar with endpoint security. It does not remove the hard product questions: how accurately the system detects new AI functions, whether it can interpret changing permissions, how quickly it responds to vendor updates and whether its policies work across competing cloud and software environments.

The real risk is capability drift

Shadow AI—the unauthorised use of public or unsanctioned models—remains a concern. Neo’s premise points to a subtler problem: approved software can itself drift into a higher-risk category.

Consider a sales platform that previously summarised customer records but later gains an agent able to draft emails, update the CRM and trigger follow-up workflows. The underlying product may be trusted, but the new chain of actions expands the impact of a compromised account, a faulty instruction or excessive data access.

This does not mean every agent is dangerous. It means security policy must account for what the feature can do, not simply who made the application. Identity, data classification, audit logs and least-privilege access become more important as software moves from answering questions to executing tasks.

What Neo must prove next

Funding gives Neo time to build product depth and win enterprise customers. It does not yet establish market leadership. The company will be judged on measurable outcomes: assets discovered, risky permissions reduced, incidents prevented, investigation time saved and the rate of false alerts.

It must also navigate a structural tension. Enterprises want AI tools to move quickly, while security teams need evidence and control. A platform that produces visibility without enabling decisions will become shelfware. One that blocks too aggressively will be bypassed.

The larger signal from Neo’s launch is that AI governance is moving closer to day-to-day cybersecurity. Policies and ethics frameworks remain important, but companies also need technical enforcement inside messy, constantly updated software environments.

Neo’s $100 million wager is that the next important security perimeter will not be a device, network or cloud account. It will be the changing capabilities of the software already inside the business.


Frequently Asked Questions

More Stories

View all →