The rapid proliferation of artificial intelligence within the corporate environment has birthed a phenomenon now widely recognized by Chief Information Security Officers (CISOs) as "AI sprawl." While the initial wave of enterprise AI focused on centralized large language models (LLMs) and internal chatbots, the current frontier has shifted toward autonomous AI agents—software entities capable of executing tasks, accessing databases, and interacting with third-party applications with minimal human intervention. As these agents become embedded across corporate networks, the challenge of securing them has birthed a secondary "vendor sprawl," where a new generation of cybersecurity startups is racing to provide governance and protection for this decentralized workforce. Leading this charge is Reco, a security firm that recently announced a $55 million funding round to expand its footprint in the burgeoning AI agent security market.
The Evolution of AI Sprawl and the Rise of Shadow Agents
AI sprawl refers to the unmanaged and often undocumented deployment of AI tools and agents across an organization’s digital infrastructure. Unlike traditional software, which is typically vetted through a centralized procurement process, AI agents can be deployed by individual departments or even individual employees using low-code platforms or browser extensions. This decentralization creates a "shadow AI" problem that mirrors the "shadow IT" challenges of the early cloud era, but with significantly higher stakes due to the autonomous nature of the technology.
According to Ofer Klein, co-founder and CEO of Reco, the speed of deployment is currently outstripping the capacity of security teams to maintain oversight. In a recent engagement with a Fortune 100 customer, Reco’s platform identified over 21,000 AI agents that the company’s IT department was unaware existed. These agents were often integrated into critical workflows, possessing permissions to read, write, and share data across various platforms.
The risks associated with these "shadow agents" are not merely theoretical. In one instance involving a major financial services institution, Reco identified an active AI agent that had been configured by a former employee. Despite the individual’s departure from the company, the agent retained its access to Salesforce and was programmed to exfiltrate sensitive data to an external domain that fell outside the company’s visibility. This highlight’s a critical vulnerability: agents often inherit the permissions of the user who created them, and without proper lifecycle management, they can continue to operate as "zombie" entities with high-level access.
Reco’s Strategic Funding and Market Position
To address these escalating risks, Reco has secured $55 million in new capital, an extension of its $30 million Series B round finalized in February. This brings the company’s total funding to $140 million. The extension saw participation from prominent investors including Forestay, Quadrille Capital, and the venture arm of AT&T—a company that is also a Reco customer.
The financial metrics of the startup reflect the intense demand for AI security solutions. Since the beginning of the year, Reco’s valuation has more than doubled, now estimated to be in the high hundreds of millions of dollars. The company reports annual recurring revenue (ARR) in the double-digit millions and anticipates tripling that figure by the end of the fiscal year. Currently, Reco serves more than 100 enterprise customers, with the financial services sector accounting for approximately 40% of its business—a reflection of the industry’s strict regulatory requirements and high-value data assets.
The new capital is earmarked for aggressive scaling, including global hiring, expanded sales operations, and the development of new strategic partnerships. As enterprises transition from AI experimentation to full-scale production, Reco aims to position its "context graph" technology as the foundational layer for agentic governance.
Technical Paradigms: How Agent Security Differs from Traditional Cyber Defense
Securing an AI agent requires a fundamental shift in defensive strategy. Traditional cybersecurity often focuses on "perimeter" defense or "static" permissions. However, AI agents are dynamic; they use tools, make API calls, and interpret natural language prompts to perform actions. This complexity necessitates a multi-layered security approach:
1. The Context Graph and Identity Mapping
Reco’s primary innovation is the use of a context graph to map the relationships between agents, applications, human users, and data permissions. By integrating with over 280 SaaS applications, the platform can see not just that an agent exists, but exactly what it is authorized to do. If an agent designed for "meeting summaries" suddenly attempts to access a payroll database, the context graph identifies this as an anomaly based on the agent’s stated purpose and the user’s actual needs.

2. Tool and MCP Vetting
AI agents interact with the world through "tools"—small pieces of code or API connectors. A significant risk arises when agents use unvetted or malicious tools. The industry is currently moving toward standardized protocols like the Model Context Protocol (MCP) to manage these interactions. Security vendors are now offering services to vet these tools in real-time, ensuring that an agent doesn’t inadvertently download a malicious "add-on" to complete a task.
3. Prompt and Response Inspection
Unlike traditional software that follows a rigid logic gate, agents respond to natural language. This opens the door to "prompt injection" attacks, where a malicious actor (or even a corrupted data source) provides instructions that trick the agent into bypassing its security constraints. Modern security platforms now monitor "runtime" interactions, inspecting the prompts sent to the agent and the resulting "tool calls" it makes to prevent unauthorized actions.
The Competitive Landscape: A Crowded Field of Specialized Defense
Reco is far from alone in this space. The sudden urgency of AI security has created a gold rush among both established cybersecurity giants and well-funded startups.
- CrowdStrike: The endpoint security leader recently unveiled "Falcon Guardian," a suite of controls designed to protect the devices where agents run and to detect anomalous behavior in AI workloads.
- HiddenLayer: This startup recently raised $100 million, focusing on protecting the integrity of the AI models themselves against adversarial attacks. CEO Chris Sestito has noted that as agents move into production, the potential for catastrophic financial or reputational damage shifts from theoretical to "full scale" almost overnight.
- Cymphony: Focused on data access, Cymphony recently highlighted a case where a public U.S. company discovered that 85,000 sensitive files had become accessible to AI agents due to misconfigured permissions.
- Zenity: This vendor focuses on the governance of "low-code/no-code" AI, helping companies find and resolve unapproved AI usage that bypasses traditional IT department oversight.
This variety of offerings suggests that "AI Security" is not a monolithic category but a collection of specialized disciplines, ranging from data governance to model integrity and runtime monitoring.
A Chronology of Enterprise AI Security
The journey to Reco’s latest funding round can be viewed through the lens of the broader AI evolution:
- Late 2022 – Early 2023 (The LLM Explosion): Following the release of ChatGPT, enterprises focused on "Shadow AI" at the browser level—blocking or monitoring employee access to public web-based chatbots to prevent data leakage.
- Mid 2023 (The Platform Integration Era): Companies began integrating LLMs into their own tech stacks via APIs. Security concerns shifted toward "Prompt Injection" and the protection of API keys.
- Early 2024 (The Rise of the Agent): The focus shifted from "chat" to "action." Frameworks like LangChain and AutoGPT made it easy to build agents that could execute code. Reco raised its initial Series B of $30 million to address this shift.
- Late 2024 – Present (Production-Scale Governance): As thousands of agents enter production, the focus has landed on end-to-end ecosystem security. Reco’s $55 million extension reflects the market’s realization that agent security is a permanent and complex requirement of the modern enterprise.
Analysis of Implications for the Modern CISO
The emergence of autonomous AI agents represents a paradigm shift for corporate governance. For the CISO, the primary challenge is no longer just "who" has access to data, but "what" has access. AI agents act as proxies for human users, but they operate at machine speed and can be triggered by external inputs that the user may not fully control.
The financial data provided by Reco—specifically the tripling of its revenue—indicates that security is no longer an afterthought in AI deployment; it is becoming a prerequisite. Organizations are beginning to realize that the "ROI" of AI can be instantly negated by a single data breach or a misconfigured agent that deletes a database.
Furthermore, regulatory pressure is mounting. With the implementation of the EU AI Act and increasing scrutiny from U.S. regulators regarding AI safety and data privacy, companies are legally obligated to maintain a "clear inventory" of their AI assets. Platforms like Reco provide the automated discovery necessary to satisfy these compliance requirements.
As the industry moves forward, the "context-aware" approach championed by Reco is likely to become the standard. In an environment where 21,000 unknown agents can exist in a single company, manual auditing is impossible. The future of cybersecurity will be defined by AI-driven systems designed to watch, govern, and, if necessary, terminate other AI systems. Reco’s successful funding round is a clear signal that the market views this "AI-on-AI" defense as one of the most critical investment areas for the coming decade.
