Neva SGR, the venture capital arm wholly owned by Intesa Sanpaolo Innovation Center, has backed a U.S. security startup addressing one of the most pressing challenges in enterprise technology: keeping autonomous artificial intelligence systems safe from exploitation. The move underscores Italy's growing appetite for exposure to cutting-edge AI infrastructure, even as European regulators tighten oversight of algorithmic autonomy.
Through its Neva II Fund, the Milan-based investor participated in Straiker's $64M Series A round, which closed in late June 2026 and brought the California company's total capital raised to $85M. Straiker builds an "AI-native" security platform designed to monitor, test, and defend so-called agentic AI—software agents that receive a goal and then autonomously plan, decide, and execute tasks across corporate systems without constant human oversight.
Why This Investment Matters for Italy
• Cross-border tech exposure: Italian institutional capital is now directly tied to the U.S. market's fastest-growing cybersecurity niche, which according to industry analysis is valued at approximately $1.65B in 2026 and forecast to exceed $13.5B by 2032.
• Banking sector hedge: As Intesa Sanpaolo integrates AI agents into credit risk assessment, fraud detection, and customer service workflows, securing those systems becomes a balance-sheet issue—not just a tech experiment.
• Regulatory foresight: With the EU's AI Act entering force, firms deploying autonomous agents face strict liability for algorithmic harm. Straiker's compliance-ready platform may help Italian enterprises meet upcoming audit requirements.
The Agentic AI Security Gap
Unlike conventional software, agentic AI systems do not merely follow pre-programmed instructions. They interpret objectives, reason through multi-step plans, call external tools, and modify their behavior based on environmental feedback. This autonomy introduces a new attack surface that traditional cybersecurity tools—firewalls, endpoint detection, static code analysis—struggle to cover.
Security researchers have identified more than a dozen distinct threat vectors. Prompt injection allows attackers to insert hidden commands into content processed by an agent, hijacking its logic. Tool misuse exploits an agent's legitimate access to corporate systems—such as databases, APIs, or financial platforms—to execute unauthorized transactions. Memory poisoning implants false data into an agent's long-term memory, gradually skewing its decision-making. And because agents often operate at machine speed without requiring human approval for each action, a single compromised system can cascade failures across interconnected workflows in seconds.
Straiker's Three-Layer Defense
Straiker's platform divides agent security into three distinct stages: discovery, adversarial testing, and runtime protection.
Discover AI maps every active agent, multi-agent coordination server, and agentic workflow operating within a client's environment. It scans for misconfigurations and detects more than 12,000 known vulnerabilities in agent coordination protocols. The module provides continuous posture monitoring, ensuring governance teams know exactly which agents have been deployed—critical for firms that must disclose algorithmic systems under upcoming Italian implementation decrees tied to the EU AI Act.
Ascend AI functions as an automated red team. It continuously probes deployed agents using real adversarial techniques—testing resilience against prompt injection, goal hijacking, inter-agent manipulation, data exfiltration, and identity abuse. The system draws on proprietary threat intelligence and collaborates with AI research labs to surface novel attack patterns before they reach production environments.
Defend AI delivers real-time protection with sub-second response latency. It monitors every agent request, tool invocation, and inter-agent communication, blocking malicious activity with a detection accuracy above 98%. The platform includes an "Agentic Kill Switch" that allows security teams to disable a compromised or malfunctioning agent within seconds—a safeguard particularly relevant in high-stakes sectors like finance, where a rogue trading bot could drain capital in minutes.
A Crowded Field, a Necessary One
Straiker's Series A round attracted significant institutional backing, including major venture firms and corporate investors recognizing that agentic AI security has moved from speculative opportunity to urgent necessity. The sector has seen explosive funding growth across 2026, with major European and U.S. competitors raising substantial rounds. Large technology incumbents are also racing to consolidate the market—Alphabet finalized the $32B acquisition of Wiz in March, while ServiceNow invested billions in acquiring cybersecurity firms to build what it calls an "AI control tower."
For Italian enterprises and banks, this consolidation underscores a critical point: the global cybersecurity landscape is shifting rapidly toward AI-native defenses, and early adoption of proven platforms will become a competitive necessity.
What This Means for Intesa Sanpaolo and Italian Enterprises
Mario Costantini, CEO and general manager of Neva SGR, framed the investment as a response to "one of the challenges of our time"—securing the adoption of agentic AI in a way that preserves enterprise trust and regulatory compliance. For Intesa Sanpaolo, the strategic rationale is clear: the bank is already deploying AI agents internally to enhance commercial effectiveness, strengthen risk management, reinforce cybersecurity, and drive operational efficiency.
By backing Straiker, Neva secures early access to a platform that could eventually be integrated into Intesa Sanpaolo's own AI governance stack. It also positions the Group as a credible advisor to corporate clients navigating the same transition—particularly small and medium Italian enterprises that lack in-house AI security expertise.
The investment aligns with Neva SGR's broader mandate. The firm manages the Neva II Fund, targeting a final close of approximately €400M for global investments, and Neva II Italia, a €100M vehicle dedicated to Italian startups. Both funds prioritize companies offering scalable solutions to global problems in sectors deemed critical for long-term economic transformation.
Regulatory Pressure and Practical Implications for Italian Businesses
As the EU AI Act moves from legislative text to enforcement reality starting in 2026, companies deploying high-risk AI systems—including autonomous agents that make credit, hiring, or compliance decisions—will face mandatory conformity assessments and transparency obligations. For Italian enterprises, this means concrete, practical requirements:
• Italian companies deploying AI agents for recruitment or credit decisions must maintain detailed, auditable logs of all agent decisions and be prepared to explain algorithmic outcomes to candidates and applicants.
• Organizations using autonomous AI systems for compliance or risk management must conduct regular impact assessments and submit documentation to the Garante per la protezione dei dati personali (Italy's data protection authority) upon request.
• Non-compliance can result in significant fines and reputational damage. Italian SMEs without established AI governance frameworks should begin documentation and security measures now to meet 2026 requirements.
Straiker's emphasis on explainability, auditability, and human-in-the-loop kill switches positions it as a compliance enabler, not just a threat detector. For Italian firms under scrutiny from regulators, demonstrating robust AI governance could mean the difference between regulatory approval and a costly enforcement action.
"Ensuring the security of artificial intelligence agents is one of the most difficult and urgent problems in the field of security today," said Ankur Shah, CEO and co-founder of Straiker. The sentiment is widely shared. As enterprises accelerate agent deployment, the question is no longer whether autonomous AI will be attacked, but how quickly defenses can adapt to threats moving at machine speed.