Home · Technology · Sep 29 archive
Reco Secures $55M as AI Agent Security Market Heats Up
Developing
In Short: Klein emphasized that the market demand for agent security extends beyond just the agents themselves, encompassing the entire ecosystem end-to-end.
Reco, an AI security startup, has raised $55 million to address the growing issue of AI agent sprawl, a term that has become common in tech circles as enterprises deploy AI agents en masse.
According to Reco's co-founder and CEO Ofer Klein, the company's platform has identified thousands of unknown agents at major clients, including 21,000 at one Fortune 100 customer and an ex-employee's unauthorized access point at a large financial services firm.
Klein emphasized that the market demand for agent security extends beyond just the agents themselves, encompassing the entire ecosystem end-to-end.
The startup's platform uses browser and network signals to detect agents outside of direct app connections and includes controls to inspect prompts and tool calls.
Security startup HiddenLayer's CEO, Chris Sestito, noted that the scale of costs and risks associated with AI agents can quickly escalate once they reach production, with over 50 of his customers having AI agents in production.
Cymphony, another AI startup, reported finding about 85,000 files accessible to AI tools and agents at one U.S. public company.
The influx of investment into AI agent security solutions reflects the growing concern among CISOs about securing these agents across networks.
A quick look at public profiles reveals at least two dozen companies offering AI agent security solutions, each with varying approaches but similar promises of discovery and governance.
Until recently, Reco focused on mapping and securing SaaS and AI platforms, but it has now repositioned around a broader solution that uses a context graph to connect agents to apps, people, accounts, and permissions.
This shift aims to provide security teams with a comprehensive view of what an agent can reach and the ability to restrict unnecessary access.
The rapid deployment of AI agents and the subsequent need for robust security measures are driving a surge in vendor offerings, creating a crowded but lucrative market for AI agent security solutions.
What this adds
The rapid deployment of AI agents is leading to a new kind of sprawl, with vendors offering a variety of solutions to help companies manage and secure these agents.
The products offered by these vendors vary, but they all promise to discover and govern AI agents using similar technologies like knowledge graphs and continuous monitoring.
What's still developing
- Terms like “AI sprawl” have become common fare on tech social media and in thought leadership as enterprises start deploying AI agents en masse.
- Some others, like CrowdStrike, are building detection and response controls on the devices agents run, and still others are focused on finding and resolving unapproved AI usage.
- According to Reco’s co-founder and CEO Ofer Klein, the biggest change over the past year that spurred the startup to broaden its scope was that companies are building and deploying AI agents faster than they can keep track of.
- Security startup HiddenLayer ‘s co-founder and CEO, Chris Sestito, earlier this month told me that when agents reach production, the scale of their costs and risk goes from theoretical to “full scale really quickly,” and that over 50 of his customers have AI agents in production touching critical systems and sensitive assets.
- There’s no doubt a ton of investors are interested in companies that can make a mint out of helping companies find and secure all these agents, and Reco has capitalized on that demand: The startup on Tuesday said it raised $55 million, building on a $30 million Series B in February.
- Some vendors vet the tools agents use, while others try to help companies control what data their agents can reach.
- The products differ, of course, but their promises to discover and govern agents sound quite similar, involving knowledge graphs, continuous monitoring, runtime security, tool access, MCP vetting, and the like.
Sources
- TechCrunchlink
