Endpoint security has gone through two distinct eras. The first was antivirus — static file signatures that were easily bypassed by anyone with patience and a hex editor. The second was endpoint detection and response (EDR), pioneered by companies like CrowdStrike and SentinelOne, which shifted focus from file hashes to process behavior and became the dominant enterprise defense architecture for over a decade.
Both generations shared a foundational assumption: a human sits at the keyboard, clicks something, a program runs, and security tooling watches what that program does next. That assumption is now obsolete.
The Agentic Endpoint Problem
Microsoft embedding Copilot into Windows has effectively made AI agents a default component of the modern enterprise endpoint. These agents run with user-level privileges, reading files, executing code, calling external APIs, and shuttling data between applications — continuously, autonomously, and often without direct human initiation.
This creates a problem that no existing security tool was architected to solve: attribution. When an action occurs on the endpoint, was it the person at the keyboard, or the AI agent acting on their behalf? EDR tools, DLP systems, and Zero Trust frameworks all assume they can answer that question. Increasingly, they can't.
As a16z frames it, reworking existing platforms to handle human-versus-agent attribution wouldn't be a feature update — it would mean rebuilding from scratch. Most incumbents, the firm argues, will bolt on basic AI discovery capabilities and call it done.
What Neo Is Building
Neo is designed specifically for this third generation of endpoint security, which a16z describes as agentic software control. Rather than retrofitting behavioral detection logic, Neo anchors its approach to three questions at the moment of execution:
- Is this action coming from a verified human or an AI agent?
- Is that agent operating within correctly configured guardrails?
- What enforcement happens when malicious or negligent behavior occurs?
Answering those questions in real time — and acting on the answers autonomously — is the core technical bet.
The Team
The founding team draws heavily from SentinelOne's operational and research leadership:
- Nick Warner scaled SentinelOne through its IPO across multiple executive leadership roles
- Shlomi Salem spent over 11 years leading threat research at SentinelOne
- Eran Shirazi brings a technical co-founding background, previously serving as CTO of EasySend
The combination of commercial go-to-market instincts, deep threat research expertise, and engineering credibility is precisely the profile that enterprise security buyers respond to — and that recruiting top security talent requires.
Why This Matters for the Market
The transition from antivirus to EDR created category-defining, billion-dollar companies. a16z is explicitly drawing that parallel here, arguing the shift to agentic endpoints is "at least just as large, and arguably more urgent."
For founders and security teams, the implication is direct: the controls you've relied on for the past decade were built for a threat model that assumed human intent behind every action. As agentic workflows become standard — not just in Microsoft's ecosystem, but across the enterprise software stack — that gap will widen fast.
a16z has led Neo's Seed round. Financial terms were not disclosed.



