Island Raises $400 Million to Extend AI Agent...

Island raised $400 million in Series F at a $6.4 billion valuation and expanded from enterprise browser security into AI agent governance across

[SUMMARY]Island completed a $400 million Series F financing round, lifting its valuation to $6.4 billion, and expanded enterprise browser capabilities into an AI agent governance platform spanning general browsers, desktop applications, and network environments, strengthening control over identity, permissions, data, and actions.[SUMMARY]

Event Overview

Enterprise browser company Island announced that it had completed a $400 million Series F funding round, increasing its valuation from $4.8 billion in the 2025 Series E round to $6.4 billion. The company officially launched its enterprise browser in 2022, with the core goal of enabling enterprises to manage employee access to SaaS and internal web applications directly from the browser, while restricting data actions such as copy, paste, download, and upload.

In March this year, Island further launched Island Enterprise Platform, extending control from the enterprise browser to general browsers, desktop applications, and network environments. As enterprises begin adopting AI agents, Island has also extended its governance capabilities to AI agent identity and permission management, and can restrict which enterprise resources AI agents may access, which data they may use, and which actions they may perform; some actions can even require human approval.

In addition, the platform can log prompts, responses, and AI agent activity for subsequent enterprise auditing.

Technical Analysis

Island’s product evolution reflects how enterprise control models are shifting from browser security to workload and agent governance. Early enterprise browsers focused on embedding security controls directly into the user entry point, using the browser layer to restrict data exfiltration paths such as copy, paste, download, and upload. The advantage of this design is centralized control, allowing enterprises to establish consistent policies at the web access layer without relying entirely on scattered endpoint tools.

Island Enterprise Platform extends the governance boundary from a single browser to a broader work environment. This means its control plane no longer deals only with how human users use browsers, but begins to address how humans and AI agents jointly access enterprise resources. Once AI agents gain the ability to execute tasks, read data, and call systems, the risk is no longer limited to external attacks or account abuse; it also includes excessive access within authorized boundaries, misuse of data, or unintended actions by the agent itself.

From a governance perspective, Island’s key capabilities include identity control, permission boundaries, data-use restrictions, action restrictions, and human approval. These capabilities essentially insert policy gates between AI agents and enterprise assets, preventing agents from overstepping due to task automation. Combined with prompt, response, and activity logs, enterprises can later trace whether agents operated according to policy and support audits, investigations, and policy rollbacks.

This design also shows that enterprise security architecture is expanding from protecting endpoints and web pages to protecting decisions and behavior. In a world where AI agents are widespread, simply blocking network connections or file transfers is no longer enough to cover the risk, because agents may perform high-risk actions through legitimate interfaces. Therefore, integrating policy, approval, and audit into a single platform is likely to become an important direction for future enterprise AI agent governance.

Impact Scope

For organizations that have adopted enterprise browsers, Island’s expansion means security investments no longer serve only web access control, but can now extend directly into AI workflows. This is especially important for enterprises that rely heavily on SaaS, internal web systems, and automation agents, because these environments often involve sensitive data, complex authorization, and cross-system operations.

The financial sector is one of the most representative groups affected. As AI agents begin participating in querying, organizing, summarizing, and operational workflows, banks, insurers, capital markets, and other highly regulated industries face the same question: how to ensure agents do only what is permitted and that every step is traceable.

Another layer of impact lies in internal identity and permission models. Traditional IAM mainly targets human accounts, but if AI agents are treated as actionable work entities, new authorization logic and approval processes are required. Island’s positioning is to bring humans and agents into the same control plane, which will push enterprises to rethink access boundaries, data classification, accountability, and audit design.

From a market-signaling perspective, Island’s current revenue of roughly $200 million and annual growth of about 100%, combined with a $6.4 billion valuation, suggest that investors see AI agent governance not as a simple feature extension, but as an independent and scalable security category. This may also accelerate other security vendors to follow suit, integrating endpoint, browser, identity, data, and AI governance into more complete platform-based offerings.

Protection Recommendations

To address the new risks brought by AI agents, enterprises should not begin by banning automation outright, but by establishing verifiable governance boundaries. First, they should inventory which systems, data, and actions AI agents may access, then grant permissions by data sensitivity and business risk level to avoid overly broad default privileges.

Second, human approval should be built into high-risk action flows, such as data exports, permission changes, cross-system writes, or sending sensitive information externally. Island explicitly supports requiring human approval for specific actions, reflecting the need for automation and controllability to coexist, especially in highly regulated industries.

Third, enterprises should establish complete audit logs covering at least prompts, response content, agent-triggered actions, accessed resources, and approval outcomes. Without an audit trail, it is impossible to determine after the fact whether the agent followed policy, or whether the issue was model error, policy misconfiguration, or poor workflow design.

Fourth, enterprises should treat AI agents as a new category of non-human identity and include them in existing IAM, DLP, and security monitoring processes. Managing agents using only general user-account logic can easily create over-authorization, unclear accountability, and cross-system propagation risks.

Fifth, organizations that have already deployed enterprise browsers or similar control layers should regularly verify whether policies truly cover general browsers, desktop applications, and network environments, to avoid control gaps caused by workload spillover. When AI agents may switch between different interfaces, only consistent policies and visibility can reduce lateral spread and data exfiltration risks.

5-Step Remediation Checklist

  1. Inventory the systems, data, and actions that AI agents can access, and complete risk classification.
  2. Set up human approval for high-risk actions to prevent agents from automatically executing sensitive operations.
  3. Enforce least-privilege identity and access principles, and include AI agents in non-human identity management.
  4. Enable prompt, response, and activity logging to ensure auditability, traceability, and rollback capability.
  5. Regularly verify policy consistency across enterprise browsers, general browsers, desktop applications, and network environments.

References

  • ITNEWS ISC|Island Raises $400 Million to Extend AI Agent Governance Beyond the Enterprise Browser

More cybersecurity news