The founders
Elias Manousos and Brandon Dixon aren’t first-time founders in this space. The pair previously co-founded RiskIQ, an external attack-surface management company that Microsoft acquired in 2021, then stayed on to help build Microsoft Security Copilot before leaving to start Ent. That’s two prior acts in security tooling built specifically for the moment attackers — and now AI agents — touch a real environment.
Why now
Traditional endpoint and workspace security was built to detect bad behavior after it already happened, then alert a human to investigate. That model strains further every time an AI agent is granted its own credentials and permissions and takes actions at machine speed, across apps, browsers, and local files, faster than a human review cycle — or a purely reactive detection stack — can keep up with.
What Ent does
Ent ships a lightweight on-device agent (Windows, macOS, Linux) plus a browser extension that uses computer vision and small specialized AI models to evaluate the intent behind an action — by a human or an AI agent — at the moment it happens, rather than only logging it for later review. When an action matches a customer-defined risk policy, Ent triggers a configurable, just-in-time intervention before the action completes, covering use cases like insider risk detection, AI governance, data loss prevention, and incident investigation.
The round
Ent emerged from stealth in June 2026 with $100 million in seed funding led by Decibel Partners, with Sequoia, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis, and In-Q-Tel participating — a notably large seed check reflecting both the founders’ track record and investor interest in security infrastructure built for the AI-agent era. The San Francisco company says its platform is already generally available, with Global 2000 customers live in hospitality, financial services, and defense.
Why it matters for founders
As founders wire AI agents into production systems and everyday workflows, “what is this agent actually doing right now” becomes a live security question rather than a quarterly audit item. Teams giving agents broad access to sensitive systems — finance, customer data, internal tooling — are the ones most likely to feel this gap first, and the ones Ent is explicitly building for.

