Image Not FoundImage Not Found

  • Home
  • Cybersecurity
  • Island’s $400 Million Series F Is a Bet on a Unified AI-Agent Security Control Plane
A person working late in a conference room looks at a laptop with several browser windows open, with a notebook and phone on the table.

Island’s $400 Million Series F Is a Bet on a Unified AI-Agent Security Control Plane

Island has raised $400 million in a Series F round led by Evolution Equity Partners, bringing the enterprise-security company’s valuation to $6.4 billion, according to Island’s announcement. The financing matters beyond startup arithmetic because Island is no longer selling only an enterprise browser. It is pitching itself as an “agentic control plane” for human employees and software agents moving across browsers, endpoints, applications, networks, identity systems, and data.

That is a bigger ambition, and a more consequential one. As companies give AI agents permission to browse, call tools, open files, and execute business tasks, the old security stack often sees only fragments of the workflow. A browser may see a prompt, an identity provider may see a login, a network tool may see a connection, and a data tool may see a file move. The appeal of Island’s model is that one policy layer might tie those fragments together and answer a practical question after every action: who or what did this, what was it allowed to touch, what data was involved, and should the action have been allowed at all?

The real question for buyers is whether that unified layer can make agentic work safer and more accountable in production, or whether it mainly creates another concentrated dependency that still relies on underlying tools and still needs proof.

Why the browser is no longer the whole product

Island emerged from stealth in 2022 with a secure enterprise browser that embedded access, security, and productivity controls directly in the software employees use all day. That was already a pointed critique of fragmented security architecture: if work increasingly happens in the browser, putting enforcement there can be more effective than adding yet another standalone dashboard.

Now the company is stretching that logic outward. Island says its platform spans five layers — last-mile control, network, data, identity, and observability — and that the goal is one policy engine and one audit trail for both human and agentic work. In its telling, that means identity governance, access controls, guardrails, data boundaries, human approvals, cost governance, and activity logging can travel with the session instead of being stitched together after the fact.

That expansion helps explain investor enthusiasm. Security company valuations usually rise when buyers appear willing to consolidate spending around a broader control point, not just a narrow feature. Island says it now employs about 1,000 people and has doubled annual recurring revenue in every fiscal year since launch. SecurityWeek reported that total investment in the company is now well above $1 billion. CTech reported roughly $200 million in revenue by September 2026, about 100% annual growth, and the company’s claim that eight of the world’s ten largest banks use its enterprise browser. Those figures are directionally important, even if the public record does not show audited operating detail behind them.

What the control-plane thesis gets right

Island is chasing a real security problem. AI agents compress time, widen access, and blur boundaries between employee actions and automated actions. A finance workflow may now involve a human manager, a browser session, an agent using SaaS tools, a file in cloud storage, and a private application behind zero-trust access. Each control category — IAM, PAM, SASE, DLP, endpoint security, CASB — can contribute, but each can also miss context that lives somewhere else.

A unified policy-and-audit layer could reduce that blind-spot problem. If identity, device posture, network reachability, data handling rules, approvals, and logging are tied to the same action, a security team has a better chance of enforcing least privilege before the action and reconstructing accountability afterward. SecurityWeek’s description of Island’s related capabilities points in that direction: zero-trust network access, device-posture assessment, inline data-loss prevention, controls over clipboard transfers, downloads and screen captures, and guardrails meant to keep proprietary information separate from external language models while reducing prompt-injection risk.

That combination is commercially attractive for another reason: it promises simpler governance. CISOs do not just buy prevention; they buy administrative clarity. If one platform can lower policy fragmentation, shorten integration work, and give auditors a cleaner record of who approved what, it may speed AI deployment even before it proves superior security outcomes.

The proof buyers still need

The problem is that the public case is still mostly architectural. The available reporting does not provide independent benchmarks for detection, prevention, false-positive rates, prompt-injection resistance, latency, or agent task completion under Island’s controls. It also does not show how many customers use the full cross-layer platform rather than only the browser, or how much current revenue comes from the newer agent-control model.

So the buyer test should be concrete.

Can agent sessions be bound to identities in a way that survives tool calls, browser actions, and handoffs between human and automated work? Are permissions genuinely least-privilege, or are teams broadening access just to keep workflows from breaking? Do high-impact actions require explicit approval, and can those actions be paused or rolled back? Are logs reliable, exportable, and retained long enough to support incident response and audits? Can the platform enforce data boundaries across the actual mix of SaaS apps, internal systems, networks, browsers, and agent frameworks a company uses? What measurable latency does enforcement add, and does it interfere with task completion enough that employees route around it?

Prompt-injection and tool-abuse testing matter especially here. A control plane for agents is not useful if it only governs the happy path. Buyers need to know how the system behaves when an agent is manipulated into exfiltrating data, following hostile instructions, or abusing an allowed connector. They also need an outage plan. If the policy layer is unavailable, do workflows fail closed, fail open, or strand critical operations in the middle of a task?

The new dependency risk

Island’s pitch is strongest when read as a bid to become the operating policy layer for agentic work. That could be valuable. It could also create a high-value control point with a larger blast radius if it is misconfigured, unavailable, or compromised.

This is the tradeoff underneath the $6.4 billion valuation. Consolidation can reduce gaps between tools and cut the cost of administering too many overlapping controls. But consolidation also centralizes visibility, enforcement, and failure risk. A company that routes more employee and agent activity through one decision layer may gain cleaner governance while becoming more dependent on that layer’s coverage, resilience, and integration quality.

That is why the funding should be read as a market signal, not a verdict. Investors are wagering that enterprises want a single place to express policy for humans and agents together. They may be right. The harder question, and the one buyers still have to answer for themselves, is whether Island’s control plane closes real security gaps in live workflows better than the identity, network, endpoint, DLP, and application controls they already own — and whether it does so without turning AI governance into one more concentrated point of failure.