4 min read

Israel's bid to own the agentic security frontier- 272

Israel's bid to own the agentic security frontier- 272

July 21, 2026

Three unrelated headlines from the past ten days reveal a single strategic pattern: as artificial intelligence agents begin acting autonomously inside corporate networks, Israel's cybersecurity ecosystem is moving fast to define, and dominate, the discipline built to secure them. Google's newest startup cohort is disproportionately Israeli and explicitly organized around agent governance. A Tel Aviv offensive-security firm is arguing that penetration testing itself must become agentic to keep pace. And a startup founded by SentinelOne and Wiz veterans has raised $100 million to build the oversight layer for software that no longer waits for human instruction. Read together, these are not three isolated funding stories — they are early positioning in a contest over who writes the rules for a security category that barely existed a year ago.

The clearest evidence of that positioning is institutional. Google's Gemini Startup Forum for cybersecurity selected 33 companies worldwide for its first cohort, and eleven of them are Israeli or Israeli-founded — eight based in Israel, three built in the United States by Israeli founders. Google organized the cohort around six functions, and the Israeli concentration is heaviest precisely where agentic risk is newest.

A third of Google's entire global cohort is Israeli — and specifically clustered in the categories built around

In agent governance, Capsule Security monitors the behavior of autonomous agents in real time, tracking their API calls and tool use to catch unauthorized action before it happens, while Onyx Security gives security teams a single console for discovering and policing every agent operating across a company's systems. In application security, Alt Security is building autonomous agents that conduct their own reconnaissance and validate exploits, effectively automating the penetration-tester's job. The infrastructure category includes Huskeys, which tunes firewall rules in real time to cut false positives; Native, which centralizes security posture across Google Cloud, AWS, Azure and Oracle and simulates the impact of policy changes before they ship; and QIZ Security, which maps encryption assets into a knowledge graph to help enterprises prepare for post-quantum cryptography. On the endpoint side, Glow uses cooperating AI agents to map a company's software environment and block rogue browser extensions, while the American-based, Israeli-founded trio of Bold Security, Jazz and ORION Security each attack data-loss prevention from a different angle — on-device classification, intent-aware policy enforcement, and cross-platform file-flow mapping, respectively. Rounding out the cohort, Mate Security automates alert triage inside existing security operations centers. Google's own framing was notable: the company said this year's group reflects an industry pivot from defending networks and devices toward defending the AI agents themselves.

Neo sits at the top of that stack because it doesn't test or watch individual agents — it answers who is allowed

That pivot is exactly what Terra Security is betting its business on. Its co-founder and chief executive, Gail Malachi, argues that a traditional penetration-test report is obsolete the moment it is delivered, since software environments now change daily while attackers operate continuously. Terra's answer is what it calls the first agentic offensive-security platform — AI agents paired with human experts to continuously probe an organization's web, network and AI-system attack surface rather than assess it once a quarter. Malachi frames the approach around three principles — continuous testing, context-aware assessment and sustained human oversight — and points explicitly to Israel's offensive-security talent as the advantage that makes the model viable, arguing that because attackers now operate without borders, defense has to as well.

Neo occupies the layer above both: not testing agents or monitoring individual ones, but governing the whole population of them inside an enterprise. Founded by alumni of SentinelOne, Wiz and Palo Alto Networks — including a former Unit 8200 vulnerability researcher — Neo emerged from stealth with $100 million led by Andreessen Horowitz and Bessemer, built around an inventory of every AI agent, browser extension and semi-autonomous tool operating in a company's environment, each mapped to the permissions it holds and the identity it acts under. The company cites a Gartner projection that the share of enterprise applications with agentic capabilities will jump from 5 percent in 2025 to 40 percent by the end of 2026, and its bet is that no existing security platform is built to answer the basic question that projection raises: what is allowed to act on a company's behalf, and who is accountable when it does.

An eightfold jump in a single year — the pace that gives Neo's governance pitch its urgency, and the same pace

The geopolitical reading is less about any single company than about the structure connecting all of them. Each of these firms draws on the same talent reservoir — Israeli military intelligence units, SentinelOne, Wiz — and each is entering a market window that opened only because enterprises adopted autonomous AI faster than their security stacks could adapt. Israel is not simply exporting cybersecurity products, as it has for two decades; it is attempting to define the taxonomy of a new domain of risk before rival ecosystems do, positioning its startups simultaneously as the testers, the governors and the endpoint guardians of agentic AI. Whether that produces a single dominant Israeli platform or a fragmented layer-by-layer land grab, the pattern across Google's cohort, Terra and Neo suggests the same conclusion: the state that trains the operators who build offensive tools is now positioning itself to also build the tools that govern the AI systems those operators create.