Reco raised $55 million more to expand AI agent security, bringing total funding to $140 million and using Reco Graph to detect overprivileged access
[SUMMARY]Reco raised an additional $55 million to expand AI agent security, emphasizing that enterprises often cannot keep track of the total number of agents or the scope of their permissions; its platform connects identities, permissions, connections, and activity through Reco Graph to identify overprivileged access and anomalous behavior.
AI agent security company Reco announced that it has completed a new $55 million funding round, bringing total funding to $140 million, and plans to invest the capital in expanding sales, partnerships, channels, and customer support. The company originally focused on SaaS and AI application security risks, and in June it further launched Reco Agent Security to extend protection to the rapidly proliferating AI agents inside enterprises.
The core backdrop to this funding round is that enterprises have begun deploying large numbers of AI agents in operational workflows, but management capabilities are clearly lagging behind the pace of real-world expansion. Gartner projects that the average number of AI agents used by a Fortune 500 company will grow from fewer than 15 in 2025 to more than 150,000 by 2028, showing that agent sprawl is quickly becoming a new governance challenge.
Reco co-founder and CEO Ofer Klein said that enterprises have often already started connecting agents to applications and data sources before they have even figured out how many agents exist in their environment. Reco also said it had discovered 21,000 AI agents inside one Fortune 100 company, and that the company had previously been unaware of their existence.
The core of Reco's technology is Reco Graph, which connects identity, permissions, connections, and activity information across the enterprise environment to create visibility into AI agents. The key is not only seeing the agent itself, but linking the agent to the applications, APIs, data stores, tools, and workflows it touches so the system can infer the full range of assets it can actually reach.
Reco's monitoring logic first uses the graph to build relationships, then analyzes the agent's access scope and behavior patterns to identify anomalous activity and excessive permissions. For security teams, this means the protection focus has expanded from traditional identity governance to agent lifecycle management, including creation, connection, authorization, monitoring, and revocation.
Notably, the value of this kind of platform is not only in detecting unknown agents, but also in integrating clues scattered across SaaS, identity, workflow, and data planes into a single risk view. When AI agents inside an enterprise perform queries, synchronization, notifications, or data transfers automatically, correlation analysis is essential for distinguishing normal business automation from potential misuse.
This funding round reflects more than a single vendor's growth; it shows that AI agent governance is beginning to move into the core of enterprise security. When the number of agents reaches tens of thousands, or potentially even the hundred-thousand scale in the future, traditional access control models centered on human accounts will be difficult to apply directly to agent-based workloads.
The industries most affected are organizations that rely heavily on SaaS, data integration, and automated workflows, especially financial services. Reco says about 40% of its customers are in financial services, indicating that this sector has higher requirements for permission control, data exfiltration prevention, and audit traceability, and is also feeling the governance pressure created by AI agents earlier than others.
For large enterprises, the risk also includes shadow AI agents, meaning agents that already exist in the environment without being fully inventoried. When employees create agents on their own without bringing them into formal asset management or permission review, enterprises may unknowingly expose sensitive data, business processes, and third-party connections.
For security operations teams, this means the attack surface is expanding from endpoints, accounts, and APIs to the agent-to-application interaction layer. As long as an agent can act on behalf of a user or system identity, it can become a vehicle for permission abuse, data leakage, policy bypass, and persistent access.
Enterprises should first establish a complete inventory process for AI agents, confirming which agents exist, who created them, which applications they connect to, what permissions they hold, and whether they still align with business needs. Without basic visibility, it is not possible to move on to risk classification, privilege minimization, or anomaly detection.
Second, agents should be brought into identity governance and access review processes, with regular checks on whether their permissions are too broad, whether idle connections exist, and whether any accounts tied to departed employees remain. For agents no longer needed, a clear deactivation and revocation process should be established rather than simply disabling the front-end interface.
Third, security teams should monitor agent data flows, especially behavior connected to Salesforce, cloud storage, internal APIs, and external domains. If an agent's workflow involves moving data across systems, DLP, log correlation, and anomalous domain detection should be used together to reduce unauthorized exfiltration risk.
Finally, enterprises need to treat AI agent security as a long-term governance issue rather than a one-time project. As agents continue to scale, whether they can be reviewed at creation, continuously monitored during operation, and properly retired at end of life will directly determine whether AI automation can be deployed securely.
5-step remediation checklist