AI Agent Sprawl
Terms like AI sprawl have become common fare as enterprises start deploying AI agents en masse. But CISOs worried about securing swarms of agents operating across networks are likely finding themselves dealing with a new kind of sprawl: vendors offering to help.
A quick glance at public databases turns up at least two dozen companies selling some form of AI agent security. Some vendors vet the tools that agents use, while others try to help companies control what data their agents can reach. Some others are building detection and response controls on the devices agents run, and still others are focused on finding and resolving unapproved AI usage.
The products differ, but their promises to discover and govern agents sound quite similar, involving knowledge graphs, continuous monitoring, runtime security, tool access, and model context protocol vetting.
Expanding Security Solutions
Some startups are updating their products to join the bandwagon. Until recently, AI security startup Reco was mostly selling software to map and secure SaaS and AI platforms. Now it has repositioned around a broader solution that uses a context graph to connect agents to apps, people, accounts, and permissions, giving security teams a way to see what an agent can reach and cut off unnecessary access.
According to Reco CEO Ofer Klein, the biggest change over the past year that spurred the startup to broaden its scope was that companies are building and deploying AI agents faster than they can keep track of. At one Fortune 100 customer, Reco's platform found 21,000 unknown agents. At a large financial services customer, the startup identified an unauthorized agent set up by a former employee that could access Salesforce and share data externally.
The market demand right now for agent security is not only about the agent itself; it is about the entire ecosystem end-to-end, Klein noted.
Image Credits:Reco
Industry Concerns
Other security executives share the urgency. HiddenLayer CEO Chris Sestito noted that when agents reach production, the scale of their costs and risk escalates rapidly, with many customers having AI agents touching critical systems and sensitive assets.
Another AI startup, Cymphony, reported finding about 85,000 files accessible to AI tools and agents at a single U.S. public company.
Funding and Growth
Investor interest in agent discovery and security remains high. Reco announced it raised $55 million, building on a $30 million Series B round. Customer AT&T invested in the extension via its venture arm, alongside Forestay and Quadrille Capital.
Klein stated that the company's valuation has more than doubled since the Series B announcement, estimating it in the high hundreds of millions of dollars. Annual recurring revenue is in the double-digit millions and expected to triple during the year. The startup serves over 100 customers, with financial services accounting for roughly 40% of the business.
Product Capabilities
Reco's strategy relies on its existing coverage of SaaS applications and the AI agents they offer. The platform currently integrates with more than 280 apps, using browser and network signals to find external agents while providing controls to inspect prompts and tool calls.
The startup plans to allocate the new capital toward hiring, sales, partnerships, and customer support, bringing its total capital raised to $140 million.




