Island said it raised $400 million at a $6.4 billion valuation on Thursday, with Evolution Equity Partners leading the round, according to CNBC and CTech. The funding is interesting not only because of its scale, but because Island says it is using the money to move beyond the enterprise browser and into security controls for AI agents acting inside companies.

That shift matters because the browser, while still important, is no longer the whole workplace security perimeter. CNBC described Island as an enterprise browser company that lets businesses monitor and control browser activity as employees collaborate. CTech reported that Island now wants to apply the same idea across devices, applications, networks and data, so companies can govern both human users and AI agents from a broader control layer.

The mechanism Island is pitching is what CTech called an “agentic control plane.” In the company’s telling, the problem is structural: agents do not operate in one layer of the stack, so they cannot be governed from one. Island says the answer is to combine controls for endpoint, network, data, identity and observability, giving companies a single view of who or what is acting, what it can access and whether an action should be permitted.

For enterprises, the practical consequence is clear. If an AI agent can reach into internal applications, data stores and workflows with little supervision, then browser-only controls may catch only part of the risk. A broader policy layer could, in theory, let security teams set access boundaries, require human approval for sensitive steps and keep an audit trail across both employee and machine activity. That is the operational promise behind the round, and it helps explain why funding is flowing toward tools that sit between AI capability and corporate systems.

CNBC framed the financing against a wider scramble to secure businesses from rogue AI agents, while also noting that Island plans to invest in research and development and expand into Europe, Asia and the Middle East. The report said the company expects to grow its workforce from 1,000 to 1,500 employees by the middle of next year. CTech added that Island sees the new capital supporting growth as enterprises deploy agents that can interact with applications, data and corporate systems more independently.

The round also sets a clearer test for Island’s broader pitch. CTech says the company has expanded from its browser into endpoints, applications, network access and data protection. Island describes those parts as one policy engine and one audit trail. For a buyer, the useful question is whether that integration works across a real agent workflow, not whether the product list covers every layer on paper. A bounded trial could check whether an agent’s identity, permissions, data access, approval steps and resulting actions appear together in an auditable record.

Those checks matter because a governance claim can fail at the seams. A browser session might be visible while an agent’s later action in a separate application is not, or an approval might be recorded without a clear link to the data it released. That is an editorial test to run, not a failure reported at Island. CNBC says the company plans research and development spending alongside geographic expansion; the reporting does not provide independent results from customer deployments of the proposed control plane. The next evidence to watch is a documented deployment showing which actions are actually governed end to end.

There is a meaningful limitation in the evidence. The reports support the funding announcement and Island’s stated product direction, but they do not independently prove that the agent-control model is more effective than competing security stacks, or that enterprise demand will justify the strategy at scale. CNBC also noted a crowded field that includes Palo Alto Networks and other startups, which means Island is not buying time; it is buying room to execute in a competitive market.

The business signal is broader than one company. AI security is moving from abstract model safety debates toward day-to-day governance questions: who can invoke an agent, what data it can touch, what it can do without approval and how those actions are audited. Island’s round suggests investors think those controls are becoming budgeted infrastructure, not optional extras. If that proves correct, the winners will be the products that can enforce policy across both employees and AI agents without adding another layer of complexity. If you run security or IT for a company deploying agents, check whether your tools can enforce one policy and one audit trail across browser, identity, data and approvals before expanding agent access.