top of page

Island Series F Funding Raises the Stakes for Enterprise AI Security

20 hours ago
12 min read

Island raised $400 million in Series F funding at a $6.4 billion valuation, turning an enterprise-browser bet into a much broader enterprise AI security campaign.

Evolution Equity Partners led the round, which Island announced on September 24, 2026. Existing investors also participated. The financing brings Island’s reported outside investment above $1 billion and more than doubles its valuation since 2024.

Yet the Island Series F funding is not mainly a browser story. Island now wants to govern employees and AI agents across browsers, endpoints, networks, applications, and automated tool calls. That ambition places the company against security platforms with larger distribution networks, especially Palo Alto Networks, Microsoft, Google, and Netskope.

Island’s new capital gives it room to expand. It does not settle whether enterprises want another control plane, or whether they will prefer AI security inside platforms they already operate.

Island Series F Funding Backs a Larger Security Platform

The financing supports Island’s attempt to move from one controlled workspace into the policy layer for enterprise AI activity.

The company’s funding announcement described Island as an “agentic control plane for enterprises.” That language is more expansive than the enterprise-browser identity that established the company.

Island launched in 2020 around a straightforward observation. A growing share of corporate work happens inside a browser, but ordinary consumer browsers give security teams limited control over what users do there.

Its response was a managed browser built on Chromium, the open-source browser foundation also used by Google Chrome and Microsoft Edge. Island added corporate identity, access, monitoring, and data controls directly to that workspace.

The model gave administrators more visibility at what security vendors call the last mile. This is where a person views, copies, downloads, uploads, prints, or captures sensitive information.

Traditional security tools can inspect network traffic or identify activity on an endpoint. However, they often lack the application context needed to distinguish an approved task from an unsafe action.

An enterprise browser can apply policy at the moment of interaction. It can block a file upload, restrict copy and paste, prevent a screenshot, or limit access from an unmanaged device.

That proposition attracted customers looking for alternatives to virtual desktop infrastructure, or VDI. VDI streams a remotely hosted desktop to the user, keeping applications and data inside a controlled environment.

VDI remains useful for specialized applications and tightly regulated workflows. It can also introduce infrastructure costs, latency, administrative work, and an unfamiliar experience for employees.

Island positioned its browser as a lighter option for work centered on web applications. Contractors could use approved resources without receiving a managed laptop. Employees could access corporate applications while administrators retained policy control.

The company reported 450 customers when it announced a $250 million Series E in March 2025. That round valued Island at $4.8 billion and brought its reported funding at the time to about $730 million.

The new financing pushes Island’s valuation to $6.4 billion. It also provides capital for a product expansion that reaches beyond browser sessions.

According to independent coverage, Island now combines browser controls with endpoint posture, data loss prevention, private application access, and zero-trust networking.

Zero-trust access continuously evaluates identity and context instead of trusting a user because they entered a corporate network. Data loss prevention, or DLP, applies rules intended to stop sensitive information from leaving approved systems.

Those functions are familiar parts of enterprise security. Island’s wager is that it can coordinate them closer to the place where people and agents actually perform work.

That changes the meaning of the funding. Investors are financing a wider control architecture, not simply growth for a specialized browser.

Why AI Agents Changed Island’s Pitch

AI agents make browser-level context more valuable because they can read data, invoke tools, and take actions faster than human users.

Generative AI initially created a data-governance problem for enterprises. Employees could paste customer records, confidential documents, or source code into public chatbot interfaces.

Security teams responded with application blocks, approved AI subscriptions, DLP policies, and employee guidance. Those measures assumed a person remained responsible for each prompt and action.

AI agents complicate that model. An agent can receive a broad objective, inspect multiple resources, call external tools, edit records, and move files through a connected workflow.

The risk is not limited to an unsafe prompt. It includes the agent’s identity, inherited permissions, tool selection, generated commands, data movement, and final action.

A sales agent might collect account information from a customer relationship platform before drafting an outreach message. A coding agent might inspect a repository, install a package, execute a command, and open a pull request.

A support agent could read a ticket, consult an internal AI knowledge base, update a customer record, and trigger a refund workflow. Each step crosses a different security boundary.

Conventional security products see parts of this chain. An identity platform sees which credentials were used. An endpoint product sees processes and files. A network service sees traffic between destinations.

Those records do not always reveal why an agent performed an action or which prompt initiated the sequence. Island argues that its platform can connect more of that context.

In March 2026, the company introduced a collection of enterprise AI controls. These included AI Protect, AI Browser, AI Automation, and AI Publish.

Island says AI Protect applies policies across AI applications, desktop software, browser extensions, and connectors. It can distinguish corporate and personal accounts while recording prompts, responses, files, and agent activity.

AI Browser brings governed AI providers and corporate context into Island’s browser. Administrators can determine which data, applications, and knowledge sources users can access through that interface.

AI Automation lets organizations create browser-based agents with defined permissions and approval points. AI Publish applies shared identity, monitoring, and data controls to internally developed AI applications.

These are company claims, not independently verified measures of product effectiveness. Still, they reveal why Island wants the market to view it as more than a browser supplier.

The browser is one control point in this design. Island also offers an extension for other browsers, a desktop component, networking capabilities, integrations, and an MCP gateway.

Model Context Protocol, or MCP, is a standard that lets AI applications connect with tools and data sources. It expands what agents can accomplish, while creating another area that administrators must inventory and govern.

Island says its policy engine can inspect prompts, files, tool calls, and agent actions. It also says the platform can connect these events in a common audit trail.

That design targets a real operational gap. Security teams need to know what an agent accessed, which authority it used, and what the agent changed.

However, seeing activity is not the same as understanding intent. Controls also need accurate classifications, usable policies, and reliable enforcement that does not stop legitimate work.

The funding gives Island more resources to improve those capabilities. It also increases expectations that the platform can operate across complicated enterprise environments, not just controlled browser deployments.

Palo Alto Networks Defines the Main Competitive Pressure

Island must prove that an independent control plane offers more useful context than security functions bundled into an established platform.

Palo Alto Networks represents the clearest competitive pressure. It acquired enterprise-browser startup Talon in 2023 and incorporated the technology into Prisma Access Browser.

Prisma Access Browser combines browser controls with Palo Alto’s secure access service edge, or SASE, platform. SASE brings networking and security functions into a cloud-delivered architecture.

The combination gives Palo Alto an important distribution advantage. Existing customers can add browser capabilities to identity, network, threat detection, and DLP systems they already operate.

Palo Alto can also connect browser events with signals from its wider portfolio. That reduces the number of vendors and management consoles an organization must support.

The company said more than 100 customers had adopted its Talon-powered browser soon after the acquisition. It later made browser access available to qualified SASE customers, increasing competitive pressure on standalone suppliers.

Island’s counterargument rests on architecture and neutrality. It says enforcement should happen at the endpoint and browser, where the platform can see the user’s or agent’s action before data moves.

Network-centered controls often inspect traffic after an application has generated it. Encryption and application-specific behavior can also limit what a network service understands.

Island argues that inline controls within the work environment offer richer context. A policy can evaluate the user, device, account, application, content, action, and destination together.

The independent model might also appeal to enterprises that do not want their browser controls tied to one network-security vendor. Island can position itself across mixed technology environments.

Yet independence brings its own burden. Island must integrate with identity providers, endpoint tools, cloud applications, data systems, and security operations platforms that customers already use.

It must also show that its additional control layer simplifies operations. A platform that creates duplicate policies or fragmented alerts would weaken its consolidation pitch.

Competition is no longer limited to Island and Palo Alto. Microsoft is building more AI capability directly into Edge for Business.

In May 2026, Microsoft announced agentic browsing controls in limited preview. The company emphasized tenant protections, DLP, and centrally managed policies.

Microsoft starts with an enormous installed base across Windows, Microsoft 365, Entra identity, Defender, and Purview. It can connect AI activity with tools many organizations already license and administer.

Google has a similar structural advantage through Chrome Enterprise and Google Workspace. Netskope offers an enterprise browser alongside its cloud-security platform. Other vendors use extensions to apply controls without requiring a full browser replacement.

The competitive divide is therefore not simply Island versus another startup. It is an independent, interaction-focused control plane against browsers and security features bundled into larger platforms.

Island can win if customers value deeper controls and consistent policy across mixed environments. Platform vendors can win if acceptable security arrives through software already deployed.

The $400 million round allows Island to compete longer and invest across more product areas. It cannot erase the distribution advantage held by Microsoft, Google, and major security vendors.

That is the pressure behind the valuation. Island must turn technical context into measurable operational value before bundled alternatives become sufficient for most buyers.

The Tradeoff Is Visibility Versus Complexity

A unified audit trail sounds attractive, but broader visibility can create deployment, privacy, and policy challenges that funding alone cannot resolve.

Island’s central promise is that one policy system can govern people and agents across several work surfaces. The value rises as the platform observes more context.

The same breadth raises difficult questions. Enterprises must decide how much employee and agent activity the platform records, who can inspect it, and how long those records remain available.

Prompt and response logs might contain sensitive corporate data. Detailed browser events can expose employee behavior. Tool-call records can include credentials, customer details, or internal system information.

Security teams need that evidence for investigations and compliance. Privacy, legal, and labor teams may impose strict limits on its collection and use.

A useful control plane must support granular retention, access, redaction, and regional data requirements. It must also make those settings understandable to administrators.

Policy accuracy presents another challenge. Blocking every unapproved transfer protects information, but it can also interrupt valid work.

AI workflows are especially variable. The same tool call can be safe in one project and unsafe in another. Context can depend on the user, record, destination, purpose, and current approval state.

False positives create friction. False negatives create exposure. Automated agents increase the consequences because they can repeat an incorrect action across many records.

Island says its controls can distinguish action types and apply identity-aware boundaries. Buyers still need evidence showing how those controls perform under real workloads.

The enterprise-browser model also faces adoption friction. Users have years of accumulated bookmarks, extensions, authentication patterns, accessibility settings, and habits inside their existing browsers.

Some organizations can mandate a managed browser. Others must support a mix of corporate devices, personal devices, contractors, mobile users, and specialized applications.

Island’s extension and desktop offerings reduce its dependence on a complete browser switch. They also create questions about whether every deployment provides the same visibility and enforcement depth.

The company’s VDI replacement argument needs similar qualification. Browser-centered work can move into an enterprise browser, but many organizations still rely on native applications and specialized desktop software.

VDI can isolate an entire computing environment. A browser controls activity inside or around its own workspace. The two approaches overlap, but they are not interchangeable in every scenario.

Industry observers identified this adoption issue before the latest AI push. An enterprise-browser analysis noted growing interest while describing overall awareness and adoption as relatively limited.

The category has expanded since then. AI gives buyers another reason to examine browser controls, especially when employees use public models or agents interact with web applications.

However, a stronger problem does not guarantee one architecture will dominate. Enterprises might combine identity controls, network security, endpoint agents, browser policies, and application-specific governance.

That possibility challenges Island’s consolidation story. Its platform can reduce complexity only if customers retire other products or materially simplify their operation.

Island has not publicly provided enough information to determine how much current revenue comes from newer AI products. The funding announcement also did not disclose updated customer totals or retention metrics.

The valuation therefore reflects confidence in future expansion as well as demonstrated demand for the original browser. Investors are backing a transition that remains in progress.

What the Valuation Says About Enterprise AI Security

The $6.4 billion valuation signals investor belief that AI governance will become an operational security layer, not a narrow compliance feature.

Island’s previous growth established that enterprises would pay for more control inside browser-based work. The new valuation assumes that foundation extends naturally into AI-agent governance.

That assumption has logic. Browser interfaces remain central to software-as-a-service applications, internal portals, and cloud administration.

Agents increasingly interact with the same applications through browsers, APIs, connectors, and MCP tools. Their actions can cross identity, endpoint, network, and data boundaries within one task.

A product that correlates those actions can help incident responders reconstruct what happened. It can also enforce approval requirements before an agent completes a high-risk step.

The opportunity extends beyond blocking threats. Organizations also want to understand AI adoption, tool costs, model usage, workflow performance, and duplicated subscriptions.

Island says it can track AI usage and cost across people, teams, projects, and agents. Those features bring chief information officers and finance leaders into a buying conversation traditionally led by security teams.

This broader audience supports a larger potential market. It also creates product tension.

Security teams prioritize control, evidence, and incident response. Business leaders prioritize productivity, adoption, and faster workflows. Employees want tools that do not interfere with routine work.

A platform serving all three must balance strict enforcement with usability. Excessive control can drive employees toward unsanctioned tools. Weak controls can undermine the platform’s purpose.

Investor Richard Seewald framed Island’s advantage around its ability to see and govern interactions between people, agents, applications, and data. That is an investment thesis, not proof of market leadership.

The strongest evidence still comes from adoption, expansion, renewals, and the removal of older infrastructure. Island’s March 2025 announcement said annual recurring revenue had more than doubled each year.

That historical statement does not reveal current revenue or the contribution from AI products. The company also has not disclosed profitability, cash use, or a timeline for a public offering.

The valuation matters because it raises the benchmark for the next stage. Island must grow into a category that includes AI governance, endpoint security, data controls, browser management, and secure access.

That puts the company near several heavily funded and publicly traded vendors. Each can describe part of its existing portfolio as an AI control plane.

Island needs more than a broad label. It needs a defensible mechanism connecting context from the browser, endpoint, network, identity layer, and agent workflow.

If that connection produces faster investigations, fewer tools, safer AI deployments, or lower infrastructure requirements, the platform can justify its expansion.

If customers use only selected browser features, the larger control-plane narrative will remain ahead of deployment reality.

The Island Series F funding therefore validates demand for the problem more clearly than it validates one final solution. Enterprises recognize that autonomous software requires stronger oversight.

They have not yet agreed on where that oversight should live.

Three Signals Will Test Island’s AI Security Expansion

Island’s next phase will be judged by adoption, platform consolidation, and competitive response rather than another funding headline.

The first signal is customer adoption of Island’s newer AI controls. Updated customer totals matter, but product usage matters more.

Buyers should watch whether existing browser customers add AI Protect, AI Automation, MCP governance, or agent identity features. Expansion within current accounts would support Island’s claim that its browser provides a natural foundation.

Adoption by customers that did not start with the Island Enterprise Browser would be even stronger evidence. It would show that the broader control plane can stand on its own.

The second signal is measurable infrastructure consolidation. Island says its architecture can reduce reliance on VDI, VPNs, standalone DLP, secure web gateways, and other tools.

Case studies should identify what customers removed, which workloads moved, and where legacy systems remained necessary. Clear operational outcomes would strengthen the platform argument.

Limited deployment around contractors or selected web applications would still provide value. It would not prove that Island can become the common governance layer for an entire enterprise.

The third signal is the response from large platform vendors. Palo Alto Networks can deepen the connection between Prisma Access Browser and its SASE portfolio.

Microsoft can integrate agentic browsing with Entra, Purview, Defender, Edge, and Microsoft 365. Google can connect Chrome Enterprise controls with Workspace identity, data, and AI services.

These vendors do not need to reproduce every Island capability. They need to make their bundled options sufficient for customers already committed to their platforms.

Island can counter through deeper interaction context, cross-platform coverage, faster product development, and a more focused user experience. The new financing gives it resources to pursue those advantages.

Enterprise buyers should test the claims against their own workflows. Start with a high-risk process involving sensitive data, unmanaged devices, contractors, or an AI agent that performs real actions.

Measure policy accuracy, user friction, investigation time, integration effort, and the systems that remain necessary. Those results will reveal more than a feature checklist.

Island’s $6.4 billion valuation turns the company into a major test of the independent AI-security platform model. The question is whether one control plane can govern both human and agentic work without becoming another complex layer.

For security and technology leaders, the next move is practical: identify one agent workflow that lacks a complete audit trail, then test which architecture can actually govern it.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page