$400 million. That’s how much money investors just handed a company whose main job is making sure the software robots working inside big companies don’t accidentally hand over the keys to everything.
The company is Island, and on September 24, 2026, it announced a Series F round led by Evolution Equity Partners that valued it at $6.4 billion. That’s more than double where it stood in 2024. Island started out securing the enterprise browser, and it’s now expanding into broader corporate systems.
If you’re not in security, that sentence probably sounds like alphabet soup. So let’s translate it, because what’s happening here says something useful about AI agents and why they’re harder to manage than most people expect.
What an “enterprise browser” actually is
You already know what a browser is. Chrome, Safari, Firefox, Edge. The window you look at the internet through.
An enterprise browser is the same idea with a corporate supervisor bolted on. It’s a browser a company gives its employees so IT can set rules about what happens inside it. Can you copy customer data out of the CRM and paste it into a personal document? Can you download that spreadsheet to your home laptop? Can you screenshot the payroll page? A normal browser shrugs. An enterprise browser answers those questions according to policy.
Island built a business on that idea, and it worked, because the browser turned out to be where most modern work actually happens. Your company’s email, payroll, sales records, support tickets, and code review tools all live behind a login in a tab.
Now add agents to the picture
Here’s where it gets interesting for anyone following AI agents.
An AI agent isn’t a chatbot you ask questions. It’s software that takes actions on your behalf. You give it a goal, and it clicks through things, reads pages, fills out forms, and moves data around to get the goal done. A lot of the time, it does this in exactly the same place your employees work: inside a browser, logged into the same systems, with the same permissions.
Think about what that means for the security rules described above. Those policies were designed around a human being. A human who gets tired, who might make a bad judgment call at 4pm on a Friday, but who is also one person doing one thing at a time. An agent is different in a few specific ways:
- It moves fast. A mistake that a person would make once, an agent can make four hundred times in a minute.
- It follows instructions literally. If text on a webpage tells it to do something unhelpful, it may just do that, because it doesn’t have a gut feeling telling it something’s off.
- It’s hard to attribute. When a person exports a file, there’s a name attached. When an agent does it, the question becomes: which agent, acting for whom, under whose authority?
- It doesn’t log off. Agents can run on schedules, overnight, without anyone watching.
So the policy layer companies built for humans needs rethinking. Not scrapping, rethinking. The same question of “who is allowed to touch this data and move it where” still applies. There’s just a new kind of worker asking.
Why investors are paying up for this
I won’t pretend to know the full thesis behind a $6.4 billion valuation, and Island hasn’t published one. But the direction of the company tells you something. Moving from browser security outward to broader corporate systems suggests the browser alone is no longer enough of a chokepoint. Agents don’t confine themselves to a tab.
That valuation more than doubling since 2024 lines up with a pattern worth watching: security spending tends to follow whatever companies just deployed in a hurry. Businesses adopted AI agents quickly over the past couple of years. The control layer came second, as it usually does.
What this means if you’re not a security person
Three takeaways I’d hold onto.
First, when you hear that a company is “deploying AI agents,” ask what those agents are allowed to touch. That’s the real question, and it’s a question you can ask without any technical background.
Second, agent security isn’t mainly about the AI model. It’s about permissions, boundaries, and monitoring. Plain access control, applied to a new kind of user.
Third, this is a normal stage of a technology maturing. Email needed spam filters. The web needed HTTPS. Cloud needed identity management. Agents are getting their own version of that, and investors are placing sizable bets on who builds it.
$400 million is a lot of money to spend on chaperones. It’s also a signal that the agents are already inside the building.
🕒 Published: