Island Series F Funding Raises the Stakes in AI Agent Security
Island raised $400 million at a $6.4 billion valuation, turning its latest financing into a major bet on AI agent security. The Island Series F funding was led by Evolution Equity Partners and announced on September 24, 2026. It arrives as companies struggle to control software agents that can independently access applications, data, and internal systems.
The financing gives Island more capital to expand beyond its original enterprise browser. The company now wants to provide a shared control layer for human employees and autonomous software. That strategy puts Island against larger security platforms, particularly Palo Alto Networks, Microsoft, Google, and other vendors already embedded inside corporate technology stacks.
The central question is therefore larger than whether Island can sell more browsers. Island must prove that an independent security platform can govern agent activity better than bundled tools from established vendors. Its valuation reflects confidence in that possibility, but it does not settle the contest.
What the Island Series F Funding Changes
Island is financing a transition from a secure browser company into a broader control platform for human and automated work.
The company’s funding announcement identifies the round as a Series F led by Evolution Equity Partners. Existing and new investors also participated. Named participants include Sequoia Capital, Coatue Management, Cyberstarts, Insight Partners, Prysm Capital, and J.P. Morgan Growth Equity Partners.
Island says the new financing brings its valuation to $6.4 billion. That figure is about one-third higher than its valuation following the previous round. The company raised $250 million at a reported $4.8 billion valuation in March 2025.
The latest valuation is more than twice Island’s reported level in 2024. During that year, Island raised $175 million at a valuation near $3 billion. Its previous funding history shows how rapidly investors have repriced the company.
Island had 450 customers when it announced the 2025 round. Those customers included businesses across finance, technology, retail, and other regulated industries. The company now says millions of users rely on its platform, although it has not published a current customer count.
Revenue disclosure remains limited because Island is privately held. The company says annual recurring revenue has doubled during every fiscal year since its 2022 product launch. It has not disclosed the underlying ARR figures in its official announcement.
The capital will support research, product development, and international expansion. Chief executive Mike Fey told CNBC that Island plans to enter more markets across Europe, Asia, and the Middle East. The company also expects to expand its workforce from 1,000 people to 1,500 by mid-2027.
That hiring target makes the round operationally significant. Adding 500 employees represents a 50 percent increase from the company’s stated workforce at the announcement. Island must recruit those employees while preserving product quality, sales efficiency, and customer support.
The planned expansion also indicates that Island sees a market larger than enterprise browsing alone. A secure browser can control work performed inside its own environment. AI agents, however, can move among browsers, cloud services, endpoints, APIs, and private applications.
Island describes its answer as an agentic control plane. A control plane is the policy layer that decides who can act, which resources they can reach, and what actions remain permitted. Island says its platform applies those decisions across identity, network, endpoint, data, and activity records.
This transition creates the article’s main tension. The Island enterprise browser established a useful enforcement point for employee activity. The new strategy asks customers to trust Island across a much wider portion of their infrastructure.
The Island Series F funding gives the company time and resources to attempt that expansion. It does not guarantee that buyers will consolidate several security functions around an independent vendor.
Why AI Agents Make Browser Security Urgent
AI agents turn familiar browser actions into automated workflows that can operate faster and at greater scale than employees.
Traditional business software usually waits for a person to initiate each meaningful action. An employee signs in, opens a document, copies information, and submits a request. Existing security controls were designed around that human-paced sequence.
An AI agent changes the sequence. It can receive a goal, choose tools, open applications, retrieve information, and take follow-up actions. Some agents also maintain working memory or pass tasks to other agents.
These capabilities can improve productivity, but they create difficult questions. Security teams must determine which identity an agent uses, what data it can read, and which actions require human approval. They also need a reliable record of every step.
A mistake can propagate quickly when the software acts repeatedly. An agent with excessive permissions could expose confidential information, modify records, or trigger unwanted transactions. Malicious instructions hidden inside external content can also redirect an agent from its intended task.
This threat is why AI agent security has become relevant to browser vendors. Many enterprise applications are now delivered through web interfaces. Agents often interact with those interfaces directly or through browser-based automation.
Island argues that security should move closer to this work. Its browser can enforce restrictions around downloads, uploads, clipboard activity, screenshots, extensions, and access to applications. Policies can depend on the user, device, destination, and sensitivity of the information involved.
The company says it extends the same approach to automated activity. Its platform promises identity governance, data boundaries, cost controls, human approvals, and a unified audit trail. These remain company claims that enterprise buyers must validate in their own environments.
Island co-founder and chief technology officer Dan Amiga has described five layers in the company’s model: last-mile control, network, data, identity, and observability. Observability means collecting enough activity data to understand what happened and why.
The approach is attractive because agents rarely remain inside one security layer. An agent might begin in a browser, query a private application, call an external model, and write results into cloud storage. A browser-only policy cannot govern that entire path.
Yet the browser remains a valuable checkpoint. It sits between users, web applications, downloaded content, and many AI interfaces. Security teams can use that location to block sensitive transfers without redirecting every interaction through a remote desktop.
That advantage matters for contractors and employees using unmanaged devices. Companies often want to grant application access without gaining full control over a personal computer. A dedicated work browser can isolate corporate sessions and restrict data movement.
The category first gained attention during the shift toward remote and hybrid work. An earlier analysis of enterprise-browser adoption found that organizations valued controls over downloads, applications, and network activity. It also identified employee resistance to changing browsers as an adoption barrier.
AI agents now give vendors a second reason to promote the model. The browser is no longer only where employees view information. It is becoming one of several places where software can read data and take consequential actions.
That shift does not make every agent a threat. It does make authorization and accountability more important. Companies need to distinguish an approved agent from an unauthorized tool, then limit each approved agent to its assigned role.
The broader demand is not simply for more threat detection. Buyers want controls that can prevent an agent from exceeding its intended scope. They also need records detailed enough for incident response, compliance, and internal review.
Island is betting that these requirements will favor enforcement near the work itself. The funding suggests its investors share that view. Customers must still decide whether Island should own that enforcement or connect into a platform they already use.
Island Versus the Security Platform Bundle
Island’s primary contest is an independent control plane against security features bundled into larger enterprise platforms.
Palo Alto Networks offers the clearest comparison. It acquired Talon Cyber Security in 2023 and integrated Talon’s enterprise browser into the Prisma security portfolio. The resulting Prisma Access Browser can operate alongside Palo Alto’s secure access service edge products.
Secure access service edge, commonly shortened to SASE, combines networking and security services through a cloud-managed architecture. It can include private application access, web filtering, data controls, and threat inspection. Vendors use the model to apply consistent policies across offices, devices, and remote users.
Palo Alto completed the Talon acquisition with an explicit bundling strategy. It said qualified SASE customers would receive the enterprise browser without an additional charge. That approach can reduce the incentive to buy a separate browser platform.
Microsoft presents another form of the same pressure. Edge for Business works with Microsoft Entra ID, Purview, and endpoint management products. Organizations already committed to Microsoft can manage browser identities and data policies within a familiar administrative environment.
Google also has a strong distribution advantage. Chrome is already widely used inside businesses, and Chrome Enterprise adds management and security controls. Some customers will prefer extending an existing browser instead of asking employees to install a dedicated alternative.
Netskope, Zscaler, Seraphic Security, and other vendors offer additional combinations of secure browsers, browser extensions, data controls, and zero-trust access. This makes the competitive boundary difficult to define. Products with different architectures increasingly compete for the same security budgets.
Island’s answer is depth and independence. It argues that building controls into the browser creates more precise enforcement than adding policies around a consumer browser. It also says a common policy engine can replace several disconnected tools.
That pitch can appeal to companies frustrated by complicated stacks. A security team might otherwise combine a virtual private network, data loss prevention software, endpoint management, remote browser isolation, and virtual desktops. Each system creates separate policies and activity logs.
The Island enterprise browser can restrict copying, downloading, uploading, printing, and screen capture within a work session. It can also change permissions based on the application, identity, device condition, or data involved. Those controls are easier to understand when applied at the point of interaction.
Island has also added connections to non-browser resources. Its platform supports protocols used for remote desktops, command-line access, and shared files. This gives administrators a path to older systems that cannot simply move into a web application.
An independent product can also work across competing cloud and productivity ecosystems. A company using Microsoft identity, Google collaboration tools, and several security vendors may value a neutral enforcement layer. That flexibility becomes more important when AI agents use models and applications from several providers.
However, platform vendors have their own advantage. They can combine browser activity with information from networks, endpoints, email, cloud workloads, and identity systems. Their installed customer bases also reduce procurement and deployment friction.
The 2025 vendor assessment from IDC illustrates the tradeoff. It identifies Island’s browser-native controls, employee-experience monitoring, and legacy application connections as strengths.
The same assessment identifies limits. It says Island lacks native streaming for some complex Windows applications. Organizations with extensive traditional software may therefore need to maintain separate application-streaming infrastructure.
IDC also notes that large deployments can require substantial planning across security, identity, and application teams. Granular policies create value, but they create administrative work as well. Organizations need the expertise to design, test, and maintain those policies.
This is why the contest cannot be reduced to a feature checklist. Island needs to show that its additional control justifies adopting another strategic platform. Incumbents need to show that their integrated offerings provide comparable control without trapping customers inside one ecosystem.
The Island Series F funding raises the stakes on both sides. Island can invest more heavily in engineering and sales. Larger vendors can use bundling, existing relationships, and acquisitions to defend their positions.
The Browser Is Becoming a Policy Enforcement Point
Island’s strategy depends on making the browser a trusted enforcement layer without turning it into a productivity bottleneck.
Consider a contractor who needs access to a customer database from a personal laptop. The company may not want to install full device-management software. It may also want to prevent downloads, screenshots, and copying into personal applications.
An enterprise browser can create a managed work session on that laptop. The organization can authenticate the contractor, restrict sensitive actions, and record activity without controlling the entire device. This arrangement offers an alternative to issuing hardware or hosting a complete virtual desktop.
A similar policy can govern employee use of generative AI. A company might permit questions involving public information while blocking confidential records from external models. The system can display warnings or require approval when a request crosses a defined boundary.
Agentic workflows make the same scenario more complex. An approved agent could gather information from several applications and generate a response. The security layer must validate each access request instead of trusting the workflow after its initial authentication.
Identity becomes central in that model. An agent needs a distinct, attributable identity rather than borrowed employee credentials. Administrators also need to know which person or service authorized the agent and what limits apply.
Data context matters as much as identity. Reading a public document presents a different risk from retrieving payroll files or product designs. Policies must recognize the difference before allowing an agent to transmit information elsewhere.
Human approval provides another control. An agent might be allowed to draft a customer response but prevented from sending it without review. It might prepare a payment instruction while requiring an authorized employee to approve the transaction.
Audit records must capture more than a successful login. Security teams need the sequence of prompts, tool calls, data access, policy decisions, and final actions. Without that chain, investigators may struggle to explain an unwanted result.
Island says its broader platform can apply one policy engine and one audit trail across these interactions. That proposition is the mechanism behind its expansion. The browser supplies a starting point, while endpoint and network controls extend coverage beyond web sessions.
This approach also recognizes a practical truth about enterprise AI. Companies will rarely standardize on one model or agent platform. Business units will adopt specialized tools, and software vendors will embed agents inside existing products.
A vendor-neutral control layer could help security teams apply consistent rules across those choices. It could also let companies change models without rebuilding every policy. That flexibility would make AI agent security less dependent on individual application vendors.
However, a control plane only works when it sees enough of the workflow. An agent using an unmonitored API or unmanaged cloud account can bypass browser policies. Island therefore needs integrations and enforcement mechanisms that reach beyond its original product.
The company must also avoid excessive monitoring. Enterprise browsers can observe detailed user activity, which raises legitimate privacy and governance concerns. Organizations need transparent policies that separate business protection from unnecessary employee surveillance.
Performance is another requirement. Controls that interrupt normal work will encourage users to seek unofficial alternatives. Security teams must test browser compatibility, application behavior, extensions, and latency before broad deployment.
This is particularly important for large companies with thousands of internal applications. Mike Fey previously acknowledged that a proprietary browser must be tested against extensive application portfolios. Compatibility work becomes an adoption cost even when the underlying browser uses Chromium.
The strongest implementation will therefore be selective. Companies can begin with contractors, unmanaged devices, sensitive applications, or teams using external AI tools. A focused deployment can reveal workflow problems before the organization applies stricter policies widely.
Security leaders should also connect browser controls with data classification and identity governance. Blocking every transfer creates frustration, while allowing every transfer defeats the purpose. Policies need enough context to distinguish approved work from genuine risk.
For knowledge workers, the issue extends beyond cybersecurity. AI systems increasingly rely on access to documents, messages, and organizational context. Teams need clear boundaries around what information enters those systems and how generated outputs return to business workflows.
A structured knowledge-blending workflow can help individuals understand how multiple information sources support a result. Enterprise governance still requires formal access rules, auditability, and security review around that process.
Island’s opportunity is to make these controls feel like part of ordinary work. Its risk is becoming another complex layer that administrators must reconcile with existing systems.
What the $6.4 Billion Valuation Does Not Prove
A large financing validates investor demand, but it does not independently validate product claims or long-term market leadership.
Island reports that annual recurring revenue has doubled every fiscal year since launch. That is an impressive growth claim, yet the company has not disclosed the corresponding revenue values in its announcement. Outsiders cannot calculate retention, margins, or sales efficiency from growth percentages alone.
The valuation also comes from a private financing transaction. It reflects negotiated expectations among the company and its investors. It is not equivalent to a continuously traded public-market value.
Hiring 500 employees adds execution risk. Recruitment must support engineering, customer service, international operations, and sales without creating unnecessary overhead. Rapid expansion can also make product decisions and internal coordination more difficult.
International growth introduces local compliance demands. Data residency, employee monitoring, privacy law, and procurement expectations differ among regions. A policy design accepted by one customer may require significant changes for another.
The product strategy itself is widening quickly. Island began with a dedicated browser and then expanded into extensions, endpoints, data protection, network access, and agent governance. Each additional layer brings new competitors and integration requirements.
That expansion can strengthen the platform if the components share meaningful policies and evidence. It can weaken the product if the result becomes a collection of uneven capabilities. Customers should examine how consistently controls operate across each environment.
Independent analysis provides a useful counterweight to company messaging. IDC found that Island offers granular browser data controls and useful performance visibility. It also identified broader analytics limitations and deployment complexity in large environments.
Some organizations may need specialized reporting tools alongside Island. Others may retain virtual desktop infrastructure for Windows applications with complex dependencies. Those requirements challenge the idea that one browser platform can replace every legacy component.
Competition adds another uncertainty. Palo Alto Networks can place browser protection inside Prisma SASE. Microsoft can connect Edge with identity, device management, and data governance. Google can build on Chrome’s existing position in employee workflows.
Smaller vendors can attack from the opposite direction. Browser extensions and lightweight agents may offer narrower controls with less deployment friction. Customers that reject a complete browser replacement still have options.
Island therefore faces pressure from both ends. Large platforms can bundle adjacent security capabilities, while focused startups can offer simpler interventions. Island must prove that its broader control plane delivers enough value to occupy the middle.
AI agent security also remains a developing category. Businesses agree that autonomous access requires controls, but purchasing patterns are not settled. Responsibility may reside with identity teams, security operations, application owners, or dedicated AI governance groups.
That ambiguity can slow deals. A product spanning several departments often needs agreement across several budgets. It also requires clear ownership after deployment.
There is a deeper architectural question. Some organizations may prefer controls inside the agent platform, where developers can define permissions and approvals. Others may favor external enforcement because it does not depend on the agent following its own rules.
Island is betting on external, infrastructure-level governance. This reduces reliance on individual models and agent frameworks. It also requires Island to observe activity across a fragmented technology environment.
The Island Series F funding does not resolve that architectural debate. It gives the company resources to compete while enterprises decide where agent governance should live.
Buyers should evaluate measurable outcomes instead of relying on valuation signals. Useful tests include blocked data transfers, reduced virtual desktop dependence, faster contractor onboarding, application compatibility, and complete agent activity records.
They should also test failure modes. An evaluation should determine what happens when an agent loses connectivity, encounters hostile instructions, changes tools, or requests access outside its assigned role.
The objective is not to eliminate every possible error. It is to constrain errors, preserve accountability, and stop a limited mistake from becoming an organization-wide incident.
Three Signals to Watch After the Island Series F Funding
The next phase will be measured by agent governance deployments, competitive responses, and Island’s ability to scale without adding customer complexity.
The first signal is product evidence. Island needs to show how its agentic control plane governs real workflows across browsers, endpoints, networks, applications, and data. Detailed customer examples will matter more than broad descriptions.
Those examples should identify the agent’s task, permitted resources, approval steps, blocked actions, and audit record. They should also explain how Island handles activity outside its browser. Evidence across several agent platforms would strengthen the company’s vendor-neutral claim.
A steady flow of production deployments would support Island’s argument that browser-centered security can expand into AI governance. Pilots that remain limited to demonstrations would weaken it. Buyers will look for sustained use inside regulated or operationally complex organizations.
The second signal is the response from platform incumbents. Palo Alto Networks, Microsoft, Google, Netskope, and Zscaler already control relevant parts of enterprise infrastructure. They can add agent policies to products customers already own.
Watch for deeper links among enterprise browsers, identity systems, AI gateways, data-loss controls, and agent platforms. Bundled products that deliver adequate governance can make Island’s independent platform harder to justify.
Acquisitions will also matter. Palo Alto’s purchase of Talon showed that larger security companies value control inside the browser. Further deals could consolidate specialist technology around established distribution channels.
The third signal is Island’s own operating discipline. Expanding from 1,000 to 1,500 employees by mid-2027 is an ambitious target. The company must translate that growth into reliable products, international support, and faster customer adoption.
Revenue growth without published figures offers only a partial view. Future financing disclosures, customer counts, executive interviews, or a possible public filing could provide clearer evidence. Retention and expansion within existing customers would be particularly useful signals.
Island must also demonstrate that a wider platform simplifies security operations. If customers need extensive professional services and several supplemental tools, the consolidation claim becomes weaker. If they retire older infrastructure while improving policy control, the claim becomes stronger.
The outcome matters beyond one startup. Browsers, agents, and enterprise applications are converging into a shared work surface. Whoever governs that surface can influence how companies authorize software, protect information, and investigate automated decisions.
Security buyers should treat Island’s valuation as a signal of competitive momentum, not a purchasing recommendation. The practical question is whether the platform controls the workflows that matter without creating new operational burdens.
Developers should ask whether agent identities, permissions, and approval steps remain portable across models. Business leaders should ask which actions truly require automation and which still require human judgment. Employees should understand what activity is monitored and why.
The Island Series F funding gives the company a substantial runway for answering those questions. Its strongest case will come from measurable customer outcomes rather than financing headlines.
For teams evaluating AI agent security, the next step is concrete: map one sensitive workflow from identity through final action. Then test where existing controls lose visibility. Does Island close that gap more effectively than the platform already in place, or does it add another console? The answer will determine whether Island becomes a durable enterprise control layer or remains primarily a well-funded browser security vendor.



