Reco AI Agent Security Funding Rises as the Market Crowds
Reco raised $55 million for AI agent security, bringing its total funding to $140 million as more vendors chase the same enterprise problem.
The strategic round was led by AT&T Ventures, with Forestay and Quadrille Capital joining as new investors. It follows Reco’s $30 million Series B announcement in February, making the pace of investment almost as important as the total.
The Reco AI agent security funding story is therefore not just another cybersecurity deal. Investors are backing the idea that enterprises need a distinct control layer for agents operating across business applications. Reco must now prove that layer can remain distinct as startups and established security companies converge on the category.
Reco approaches the problem through the connections between agents, identities, permissions, applications, data, and workflows. That differs from products centered primarily on protecting models, filtering prompts, or scanning AI-generated code.
However, technical positioning alone will not settle the market. Security buyers already manage identity, SaaS, data, cloud, and application controls. Reco must show why agent behavior requires another platform, and why existing vendors cannot absorb the same functions.
Reco AI Agent Security Funding Reaches $140 Million
The new capital gives Reco more room to sell its agent governance model before the category consolidates.
Reco announced the $55 million strategic round on September 29, 2026. AT&T Ventures led the investment, while Forestay and Quadrille Capital participated as new backers.
The round brings Reco’s cumulative funding to $140 million. It also builds on the $30 million Series B announced in February, which had taken the company’s total to $85 million.
That sequence matters. Reco has raised more capital within several months while expanding its message from SaaS security toward enterprise agent security. The shift follows the spread of agents that can access data, call tools, and initiate actions inside business systems.
According to the funding details, Reco plans to expand its sales, partnerships, channel operations, and customer support. Those priorities suggest the company is moving from category formation toward broader commercial execution.
This was not presented as a conventional round focused only on product research. AT&T is both an investor and a customer, giving the financing a strategic dimension.
Vikram Taneja, who leads AT&T Ventures, said organizations increasingly need to understand how agents interact with business applications and data. He also said Reco’s focus on visibility and governance aligns with needs AT&T sees across enterprises.
That endorsement offers more than brand value. A large telecommunications company operates complicated identity systems, application estates, data environments, and approval processes. Those conditions resemble the environments where agent access becomes difficult to track.
Still, participation by a customer does not independently establish product performance. It shows that the problem is serious enough for a major enterprise to support a potential supplier financially.
Reco says the platform can identify active agents, determine which identities they use, and map their accessible systems. It also tracks permissions, API connections, sessions, workflows, and Model Context Protocol tools.
Model Context Protocol, commonly called MCP, is a standard that lets AI systems connect with external tools and data sources. Those connections make agents more useful, but they also expand what compromised or misdirected software can reach.
The company describes its Reco Graph as the contextual layer joining those elements. Security teams can use the graph to find excessive permissions, outdated access, risky integrations, or activity that violates policy.
This approach reflects Reco’s history in SaaS security. Modern agents often operate through the same cloud applications, authorization tokens, and service accounts that SaaS security products already monitor.
The round therefore funds both expansion and repositioning. Reco is betting that its existing view across applications can become the foundation for governing autonomous software.
That bet creates the central tension behind the funding. Reco has enough capital to pursue a large market, but many competitors have reached the same conclusion.
Agent Adoption Is Turning Access Into the Main Risk
An agent becomes a security problem when its instructions, identity, and connected systems combine into an unintended path to action.
Traditional business software usually waits for a person to choose an action. An AI agent can select tools, retrieve information, and complete several steps after receiving a broader objective.
That autonomy changes the risk calculation. Security teams must consider not only whether an application is approved, but also what an agent can do through it.
An agent connected to a customer database might summarize account activity. The same access could expose confidential records if a malicious instruction alters the task.
Another agent might update service tickets, send messages, and query financial data. Each permission may appear reasonable when reviewed separately. Their combination can create a much larger operational reach.
Reco calls that reach an agent’s blast radius. The phrase describes the systems, data, and workflows affected when an agent makes a mistake or follows hostile instructions.
The company’s agent security research says four in five AI tools in its studied environment operated without IT oversight. Reco also reported 414 unsanctioned tools per 1,000 employees at smaller and midsize organizations.
Those figures come from company research and should be treated accordingly. Reco says its methodology combined platform telemetry, analysis of published MCP servers, and public vulnerability records.
The same report examined 500 published agent tools. Reco said half could execute shell commands on a host, while 62 percent could read local data and access the internet.
That combination illustrates why security vendors are moving beyond prompt filters. A successful prompt injection matters more when the affected agent can read files, reach external systems, and execute commands.
Prompt injection is an attack that embeds hostile instructions in content processed by an AI system. The agent may follow those instructions even when they conflict with its intended task.
An employee could ask an agent to summarize a webpage. Hidden text on that page might instruct the agent to retrieve local information and transmit it elsewhere.
The vulnerability does not depend solely on the underlying model. It also depends on permissions, integrations, data access, runtime controls, and whether anyone notices unusual behavior.
Reco wants to manage that broader operating context. Its platform is designed to discover agents and connect their activity with the identities and applications around them.
This framing puts pressure on several established security categories. Identity vendors track access rights, SaaS security tools inspect cloud applications, and data security platforms map sensitive information.
Cloud security companies monitor infrastructure and workloads. Application security vendors test software and APIs. Model security specialists inspect inputs, outputs, and model behavior.
AI agents cut across these boundaries. A single workflow might involve a model provider, an identity account, multiple SaaS applications, an MCP server, and a customer database.
No single legacy category necessarily owns the complete chain. That gap creates an opening for companies such as Reco, but it also invites competitors from every adjacent market.
Reco Is Betting on Context While Rivals Build Control Points
The central contest is between a cross-application governance layer and security controls attached to individual models, gateways, identities, or workloads.
Reco launched its dedicated Agent Security product in June. The product extended its existing platform with agent discovery, ownership mapping, permission analysis, and contextual remediation.
The product announcement described agents as components inside interconnected enterprise environments. Reco argued that their risk extends through identities, applications, workflows, and integrations.
A graph-based approach is suited to that claim. Graph systems model relationships, allowing a security team to see how one agent connects with an account, token, tool, application, or dataset.
Imagine a sales agent that reads customer records, drafts emails, schedules meetings, and updates a pipeline. A list of those permissions offers useful inventory information.
A relationship graph can add ownership, recent activity, inherited access, and connections between each system. That context helps an analyst identify combinations that create unusual exposure.
Reco says teams can then narrow permission scopes, revoke stale access, disable unauthorized agents, and route findings into established ticketing workflows.
In July, the company expanded its runtime controls. Reco said the update added browser-based enforcement, real-time prompt analysis, blocking, and automated remediation.
Runtime security evaluates behavior while software operates, rather than relying only on configuration checks. That addition moved Reco closer to competitors focused on gateways and real-time intervention.
Yet the company still emphasizes context as its differentiation. Its pitch is that a security decision becomes more accurate when it includes identity, application, permission, and business relationships.
Other vendors are entering from different directions. Identity security companies can treat agents as non-human identities. Data security vendors can restrict what sensitive information agents retrieve.
Cloud and application security companies can inspect agent workloads or generated code. Model security specialists can test models, scan prompts, and enforce rules around inputs and outputs.
Large platform vendors also have distribution advantages. Microsoft, Salesforce, ServiceNow, and major cloud providers can place governance controls beside the systems where customers build agents.
Cisco has also framed agents as a distinct security challenge. Its agentic security portfolio combines identity, network, application, and AI controls within a broader enterprise platform.
The competitive question is not whether each approach addresses a legitimate risk. It is whether buyers prefer a separate cross-platform layer or controls embedded within products they already operate.
Independent platforms can offer neutrality across vendors. They may identify relationships that a single application provider cannot observe beyond its own environment.
Integrated vendors can reduce procurement and deployment friction. They also control valuable enforcement points inside identity systems, networks, browsers, cloud platforms, and business applications.
Reco integrates with providers and applications including OpenAI, Anthropic, Microsoft Copilot, Salesforce, ServiceNow, and Workday. Broad coverage is important because enterprises rarely standardize every agent on one model or platform.
Coverage alone will not secure a durable advantage. Integrations must remain current as providers change APIs, permissions, audit events, and agent architectures.
Reco’s funding gives it resources to maintain those connections and expand its channel. It does not eliminate the operating burden created by a fast-changing market.
A Crowded Market Can Validate Reco and Compress It
The same competition that confirms demand also makes it harder for Reco to defend a unique product category.
Cybersecurity investors have spent years searching for the next major control point. Endpoints, cloud infrastructure, identity, and data each produced large companies after computing behavior shifted.
AI agents look like another such shift. They combine autonomy with permissions and can act across systems that were designed around human users.
Startups see an opportunity because existing tools often divide those systems into separate dashboards. A security team may understand an employee’s account without seeing every agent using its credentials.
An application owner may know which integrations are installed without understanding how an agent chains them together. A data team may track sensitive records without observing the reasoning process that requested them.
Agent security vendors promise to connect these partial views. However, their descriptions increasingly overlap around discovery, inventory, posture management, identity, runtime monitoring, and policy enforcement.
That overlap can confuse buyers. A company evaluating several products may hear similar claims expressed through different architectural language.
The resulting category could divide into specialized layers. Some buyers might adopt identity controls for agents, runtime inspection for model interactions, and data controls for retrieval.
Others may prefer a consolidated platform that covers the full agent environment. Reco’s graph-centered strategy is closer to the second outcome.
The market may also consolidate through acquisitions. Established vendors can buy specialist technology when customers demand controls faster than internal teams can develop them.
That pattern already defines cybersecurity. A new infrastructure shift attracts focused startups, while larger vendors add features or acquire leaders as buying priorities become clearer.
The funding environment reflects this race. Industry reporting has described AI-native startups pressuring incumbents to build or acquire new capabilities.
PitchBook data cited in that reporting showed that half of cybersecurity deals in 2025 involved AI-native startups. It also found strong growth in deals involving security orchestration and automated response.
Those numbers cover a broader market than agent governance. They nonetheless show how quickly artificial intelligence has become part of cybersecurity investment and acquisition strategies.
Competition also comes from customers themselves. Large enterprises can build internal inventories, approval systems, and policy layers around their preferred agent platforms.
Internal development becomes more attractive when an organization has unusual systems or strict compliance requirements. It becomes less attractive when agents spread across hundreds of applications.
Reco must demonstrate that its platform reduces enough integration and investigation work to justify another security relationship. That proof will depend on deployment speed, coverage quality, and measurable remediation.
The company says it supports hundreds of applications and can deploy quickly. Those are company claims, and the more important evidence will come from sustained customer use.
Expansion through AT&T and other large enterprises can provide that evidence. Successful deployments could show that cross-application visibility remains necessary even when individual platforms add native controls.
The opposite result would weaken Reco’s differentiation. If customers rely mainly on controls from Microsoft, Cisco, cloud providers, or identity vendors, a separate agent layer could become harder to defend.
The Funding Does Not Resolve the Measurement Problem
Security teams still lack a settled way to measure whether agent governance reduces meaningful risk.
Finding an agent is not the same as securing it. Creating an inventory does not prove that a platform can prevent harmful actions without blocking legitimate work.
Agent behavior is difficult to classify because the same action can be appropriate in one context and dangerous in another. Reading customer records might be necessary for support but unacceptable for an unrelated workflow.
Ownership can also be unclear. An employee may configure an agent, while a platform provider hosts it and several departments depend on its output.
Permissions add another complication. Agents can inherit access from users, service accounts, API keys, browser sessions, or connected applications.
A security tool must reconstruct those paths accurately. Missing one connection can understate risk, while excessive alerts can overwhelm teams and slow adoption.
Graph-based context can help prioritize exposure, but graph quality depends on complete and timely data. Enterprise systems frequently contain stale accounts, undocumented integrations, and inconsistent ownership records.
Real-time intervention creates its own tradeoff. Blocking a suspicious request can prevent a breach, but an incorrect decision can interrupt a business process.
Security buyers will therefore need evidence beyond discovered-agent counts. Useful measures include risky permissions removed, unauthorized agents disabled, and high-impact behaviors stopped.
Buyers should also examine false positives, investigation time, integration coverage, and the operational cost of keeping policies current.
Independent testing remains limited because agent architectures change quickly. Products may also use different definitions for agents, copilots, workflows, and non-human identities.
That makes vendor comparisons difficult. One platform might count every AI-enabled application, while another counts only autonomous workflows that can take action.
Reco’s own research illustrates both the value and limitation of current evidence. Its telemetry identifies substantial unmanaged usage, but the company also sells the platform positioned to address that usage.
That does not make the findings invalid. It means buyers should distinguish between evidence that establishes a broad problem and evidence that validates one vendor’s solution.
The larger security record gives the concern credibility. Agents can reach files, business systems, communication tools, and production environments when configured with broad permissions.
In one reported incident, a misconfigured agent deleted and recreated a live cloud environment, contributing to a lengthy outage. Other cases have involved hidden instructions, unsafe plugins, exposed tokens, or excessive access.
These events support the need for controls around agent permissions and activity. They do not establish which product architecture will become standard.
Reco’s new funding gives it time to gather customer evidence. It also raises expectations around commercial growth, deployment outcomes, and product maturity.
The most persuasive results will connect visibility to prevented or contained incidents. Raw inventory growth alone could simply reflect the rapid spread of AI tools.
Three Signals Will Show Whether Reco Can Pull Ahead
Customer expansion, measurable remediation, and competitive consolidation will reveal whether Reco is building a category or occupying a temporary gap.
The first signal is adoption beyond initial discovery projects. Enterprises often purchase security tools to understand a new problem before deciding how broadly to deploy them.
Reco needs customers to move from inventories into recurring governance and runtime enforcement. That transition would show that agent security has become an operating requirement.
AT&T’s dual role as customer and investor makes its deployment especially important. Evidence of expanded usage would strengthen Reco’s case with other large buyers.
The relevant indicators include more governed agents, broader application coverage, and recurring use by security operations teams. Public customer examples should explain what changed after deployment.
The second signal is measurable remediation. Reco must show that its graph identifies exposures that existing identity, SaaS, or data tools do not surface clearly.
The strongest cases would document excessive access removed, abandoned credentials revoked, or dangerous tool combinations interrupted. They should also describe false positives and business disruption.
That evidence would help buyers distinguish agent governance from another asset inventory. It would also clarify whether contextual analysis improves daily security work.
A lack of such outcomes would weaken the category. Buyers may decide that existing products can add agent fields and dashboards without requiring another platform.
The third signal is how larger competitors respond. Product launches, partnerships, and acquisitions will indicate which control points attract enterprise spending.
An acquisition of a specialist would confirm that established vendors see strategic value in agent security. It could also make independent competition more difficult.
Native controls from major application providers deserve equal attention. If Microsoft, Salesforce, ServiceNow, and cloud companies offer sufficient cross-system governance, independent platforms face more pressure.
However, fragmented native controls could strengthen Reco. Enterprises using multiple model and application providers may need a neutral layer that connects them.
The market’s direction will become clearer as security teams move agents from pilots into production. Production use creates persistent identities, permissions, data flows, and accountability requirements.
It also exposes the limitations of controls designed for chatbots. Agents do not simply generate text. They take actions through the systems attached to them.
Reco’s $55 million round is a substantial vote for that distinction. Combined with the February financing, it gives the company resources to expand while buyer requirements remain unsettled.
The capital does not decide the race. It gives Reco a larger opportunity to prove that contextual governance belongs above individual agents and applications.
Enterprise buyers should now ask a practical question: can Reco consistently find and contain agent risks that their existing security stack misses?
The answer will determine whether Reco AI agent security funding marks the rise of a durable control layer or another crowded chapter in cybersecurity consolidation.



