Reco Raises $55M as AI Agent Security Startups Crowd the Market

AI Sprawl Meets Vendor Sprawl


Terms like "AI sprawl" have become common fare on tech social media and in thought leadership as enterprises begin deploying AI agents en masse. But CISOs worried about securing swarms of agents suddenly operating across networks are likely finding themselves dealing with a new kind of sprawl: vendors offering to help.


A quick glance at public Crunchbase and PitchBook profiles turns up at least two dozen companies selling some form of AI agent security. Some vendors vet the tools agents use, while others help companies control what data their agents can reach. Still others, like CrowdStrike, are building detection and response controls on the devices agents run on, while a further group focuses on finding and resolving unapproved AI usage.


The products differ, of course, but their promises to discover and govern agents sound quite similar, involving knowledge graphs, continuous monitoring, runtime security, tool access, MCP vetting, and the like.


Reco Repositions Around Agent Security—and Raises $55M


Some vendors are even updating their products to join the bandwagon. Until last year, AI security startup Reco was mostly selling software to map and secure SaaS and AI platforms. Now, it has repositioned around a broader solution that uses a context graph to connect agents to apps, people, accounts, and permissions, giving security teams a way to see what an agent can reach and cut off access it doesn't need.


According to Reco co-founder and CEO Ofer Klein, the biggest change over the past year that spurred the startup to broaden its scope was that companies are building and deploying AI agents faster than they can keep track of. At one of the startup's Fortune 100 customers, he said, Reco's platform found 21,000 agents the company didn't know about. At a large financial services customer, the startup claims it identified an agent set up by an ex-employee that could access Salesforce and share that data with a domain the company couldn't see.


"The market demand right now for agent security is not only about the agent itself; it's about the entire ecosystem end-to-end," Klein told TechCrunch in an exclusive interview.


Why It Matters in 2026


The crowded field reflects a broader shift in the 2026 enterprise security landscape: as AI agents move from pilot projects to production deployments, security teams are being asked to govern a sprawling, fast-moving attack surface that traditional tools were never designed to handle. The funding momentum behind Reco—and the wave of competitors entering the space—signals that investors expect agent security to become a standalone category rather than a feature bolted onto existing platforms. For CISOs, the challenge now cuts both ways: securing agent fleets at scale while cutting through a vendor market that is growing just as quickly as the agents themselves.

via TechCrunch

Related