Agent sprawl is the problem Reco says it was built to solve, and on Tuesday 29 September 2026 investors gave it another $55 million to do it. The round, backed by AT&T’s venture arm alongside Forestay and Quadrille Capital, takes the company’s total funding to $140 million. It comes less than eight months after a $30 million Series B, and according to chief executive Ofer Klein it more than doubled the company’s valuation, to somewhere in the “high hundreds of millions”.
The timing says as much as the amount. TechCrunch, which carried Klein’s exclusive interview, counted “at least two dozen companies selling some form of AI agent security” on Crunchbase and PitchBook. In September alone, three other startups in the space announced rounds of $30 million or more. Security leaders who worried about AI agents operating across their networks now face, in TechCrunch’s words, “a new kind of sprawl: vendors offering to help.”
This article sets out what Reco announced, how large agent sprawl has become inside enterprises, how Reco repositioned itself around it, how crowded the market now is, and what security teams should ask before buying.
Table of contents
- What Reco Announced
- How Big Agent Sprawl Has Become
- From SaaS Security to Agent Sprawl: Reco’s Pivot
- How Agent Sprawl Differs From Shadow IT
- The Crowded Market for Agent Sprawl Tools
- Why Investors Keep Funding Agent Sprawl Tools
- What Agent Sprawl Means for Security Teams
- Questions to Ask an Agent Sprawl Vendor
- Agent Sprawl and Reco FAQs
- References
What Reco Announced
Reco describes itself as “the leader in Agentic Security”, a label that barely existed in the cybersecurity market two years ago. Its platform maps which agents are active in an organisation, which identities and permissions they use, what data and systems they can reach, and what workflows they can start, then helps teams reduce or revoke risky access.
| Item | Detail | Source |
|---|---|---|
| Amount | $55 million, described as additional funding building on the February Series B | Press release; TechCrunch |
| Investors | AT&T Ventures (strategic; AT&T is also a customer), Forestay, Quadrille Capital | Press release |
| Total raised | $140 million | Press release |
| Valuation | “More than doubled” since February; “high hundreds of millions” | Klein to TechCrunch |
| Revenue | Annual recurring revenue in the “double-digit millions of dollars”, expected to triple this year | Klein to TechCrunch |
| Customers | More than 100; financial services about 40% of the business | Klein to TechCrunch |
| Coverage | More than 280 app integrations and 1,000 detection controls | Press release |
| Use of funds | Sales, partnerships, channels and customer support | Press release; SecurityWeek |
An extension, not a new series
TechCrunch calls the round an extension, and the press release calls it “an additional $55 million”. Either way, it follows the $30 million Series B announced on 10 February 2026, which was led by Zeev Ventures with Insight Partners, boldstart ventures, Workday Ventures, TIAA Ventures, S Ventures and Quadrille Capital. That release said Reco had grown 500% in 2024 and a further 400% in 2025.
One detail does not line up. The new press release calls Forestay and Quadrille Capital “new investors”, yet Quadrille Capital was also named as a new corporate investor in the February release. It may simply be new to this tranche.
How the $140 million adds up
Reco’s own releases let the funding history be reconstructed. The February Series B took the total to $85 million, and September’s round adds $55 million to reach $140 million. Reco’s newswire archive also lists an earlier $25 million round, announced roughly a year before this one, which the February release described as coming “less than 10 months” before the Series B.
| Round | Amount | Running total | Positioning at the time |
|---|---|---|---|
| Earlier rounds | $30M (derived) | $30M | SaaS security |
| 2025 round | $25M | $55M | “AI-native dynamic SaaS security” |
| Series B, 10 February 2026 | $30M | $85M | “AI SaaS security”, controlling “AI sprawl” |
| Extension, 29 September 2026 | $55M | $140M | “Agentic Security” and agent sprawl |
The earlier-rounds figure is simple subtraction from the stated totals. The last column is the more interesting one: the company’s description of itself changed three times in about eighteen months, each time towards whatever enterprises were most worried about.
AT&T as customer and investor
AT&T’s double role is the most useful signal in the announcement. “Reco helps AT&T strengthen governance across our enterprise apps and AI ecosystem by providing greater visibility into agent security risk, access management, and third-party integrations,” said Rich Baich, AT&T’s chief information security officer. Vikram Taneja, head of AT&T Ventures, said the company “recognizes the growing importance of helping organizations understand and manage how AI agents interact with business applications and data.”
How Big Agent Sprawl Has Become
The numbers Reco and its rivals quote are large, and most come from the vendors themselves. They are still worth reading, because they describe a problem security teams recognise.
21,000 agents nobody knew about
At one Fortune 100 customer, Klein told TechCrunch, Reco’s platform found 21,000 agents the company did not know about. That is agent sprawl in its purest form: not a single rogue system, but thousands of small automations, copilots and integrations created by teams who never told security. Many began as AI tools someone switched on for convenience.
The former employee’s agent
At a large financial services customer, Reco says it found an agent set up by a former employee that could access Salesforce and share that data with a domain the company could not see. It is the kind of finding that makes the case for agent sprawl tools better than any market forecast: offboarding removed the person, not the automation they built.
Gartner’s forecast, as Reco quotes it
Reco’s press release cites Gartner predicting that “the average global Fortune 500 enterprise will have more than 150,000 agents in use by 2028, up from fewer than 15 in 2025, creating significant agent sprawl, IT complexity and management challenges.” We could not check the underlying Gartner document, which is not public, so treat the figure as the vendor presents it.
| Claim | Who made it | What it measures |
|---|---|---|
| 21,000 unknown agents at one Fortune 100 customer | Reco (Klein, to TechCrunch) | Discovery at a single customer |
| More than 150,000 agents per Fortune 500 company by 2028 | Gartner, as cited by Reco | Forecast, from fewer than 15 in 2025 |
| About 85,000 files accessible to AI tools at one US public company | Cymphony, via TechCrunch | Data exposure, not agent count |
| More than 50 customers with agents in production touching critical systems | HiddenLayer (Chris Sestito), via TechCrunch | Production deployment |
From SaaS Security to Agent Sprawl: Reco's Pivot
Reco was not founded as an agent company. Until last year, TechCrunch notes, it “was mostly selling software to map and secure SaaS and AI platforms.” Its February release still described it as “the leader in AI SaaS Security, helping organizations control AI sprawl”. By September, the same company is “the leader in Agentic Security”, and agent sprawl is the headline problem.
What the Reco Graph maps
The pivot runs through what Reco calls the Reco Graph, a context graph that “maps the relationships among agents, identities, applications, permissions, data and workflows.” The pitch is that an agent that looks harmless on its own may sit on permissions that “create a blast radius that can ripple across customer data, source code, financial workflows, tickets, documents and collaboration channels.”
How agents get their access
The press release lists the paths agents use to reach data: “OAuth grants, API connections, service accounts, browser sessions, MCP tools and embedded AI features within applications employees already use.” That list is a fair description of agent sprawl from the attacker’s side, too. Each of those paths is a credential or a trust relationship that someone has to own.
Discovery beyond connected apps
Klein told TechCrunch the platform uses browser and network signals to find agents outside the apps Reco connects to directly, and that it has controls to inspect prompts and tool calls. The integration count grew from more than 215 apps in February to more than 280 now; Reco says new integrations take hours through its “Reco Factory”, while Klein told TechCrunch they can be added “within days”.
How Agent Sprawl Differs From Shadow IT
Security teams have fought unapproved technology before. Shadow IT meant staff signing up for cloud apps without asking. Shadow AI meant staff pasting company data into chatbots. Agent sprawl is the next step, and it is harder, because an agent does not just hold data. It acts.
From apps to actions
A forgotten SaaS subscription leaks data if someone logs in. A forgotten agent can keep reading, writing and sending on a schedule, with no one watching, using credentials that outlive the project that created them. That is why Reco and its rivals talk about permissions and “blast radius” rather than app counts.
The shadow AI numbers behind the pitch
Reco’s February release quoted two vendor-cited statistics to make the case for shadow AI controls: that 71% of knowledge workers use AI tools without IT approval, and that 20% of enterprises have already had data leaks tied to shadow AI use. Neither came with a named source in the release, so they are best read as the market’s own framing. The direction, though, matches what security teams report: AI arrives through employees first and policy second.
Why agent sprawl needs its own owner
Most organisations assign SaaS to IT, identity to an identity team and data to a data protection lead. Agents cut across all three. Without a named owner for the agent inventory, agent sprawl falls between teams, which is exactly how 21,000 agents can exist at one company without anyone knowing.
The Crowded Market for Agent Sprawl Tools
The products differ, TechCrunch’s Ram Iyer writes, “but their promises to discover and govern agents sound quite similar, involving knowledge graphs, continuous monitoring, runtime security, tool access, MCP vetting, and the like.”
Those four rounds add up to $235 million in one month. SecurityWeek’s coverage of Reco also links to smaller recent raises, including Rig Security ($12 million, agentic AI identity risk) and Kontext Security ($4 million, agent runtime controls).
| Company | Angle on agent sprawl | Latest news |
|---|---|---|
| Reco | Identity and permission graph across SaaS apps and agents | $55M, 29 September |
| AIR | Vets the skills, plug-ins, MCP servers and add-ons agents use; blocks what fails | $50M across two seed rounds led by Sequoia and Greenoaks, 1 September |
| Cymphony | Controls what data agents and AI tools can reach | $30M, Sequoia co-led, 9 September |
| HiddenLayer | Security for models, agents and AI workflows | $100M Series B led by Delta-v Capital, 2 September |
| CrowdStrike | Detection and response on the devices agents run on | Falcon Guardian for AI agent security |
| Zenity | Finding and resolving unapproved AI usage | Cited by TechCrunch as part of the field |
| Opal Security | Least-privilege access for agent identities | Opal Zero announced 17 September |
Everyone promises discovery
Almost every vendor in the table starts with the same first step: find the agents. That is where agent sprawl tools overlap most, and where buyers will find it hardest to tell them apart. We looked at one approach in our report on Cymphony’s Sequoia-backed launch and another in our piece on Opal Zero’s access controls.
Where the approaches differ
After discovery, the products diverge. AIR focuses on the agent’s software supply chain, Cymphony on data reach, CrowdStrike on the endpoint, and Reco on the web of identities and permissions around each agent. HiddenLayer, covered in our report on its $100M round, comes from model security. A large enterprise may end up needing more than one layer.
Why Investors Keep Funding Agent Sprawl Tools
Klein’s answer is demand. “The market demand right now for agent security is not only about the agent itself; it’s about the entire ecosystem end-to-end,” he told TechCrunch. The investors’ answer, judging by the rounds, is that enterprises are deploying agents faster than they can track them, and agent sprawl creates a budget line where there was none.
Market-size claims to read with care
Reco’s release cites Grand View Research’s 2026 Agentic AI Security Market report, which it says valued the global market at $1.3 billion in 2025 and projects $17.8 billion by 2033, a compound annual growth rate of 38.9%.
A market projected to grow almost fourteen-fold in eight years attracts money. It also attracts forecasts written to justify it, and this one reached us through a vendor’s press release rather than the report itself.
Two dozen vendors will not all survive
When a category has more than 20 startups making similar promises, consolidation usually follows. Large platforms such as CrowdStrike are already building agent controls into products customers own, and Nvidia has released an open-source agent safety platform, as we reported in our piece on Nvidia’s answer to rogue agents. Reco’s bet is that breadth of SaaS coverage, built before the agent boom, will keep it in the group that is acquired or grows rather than the group that fades.
What Agent Sprawl Means for Security Teams
Vendor claims aside, the problem is real and does not wait for a purchase order. Agent sprawl turns every connected app into a potential route for data to leave, and every forgotten automation into a live credential. The recent run of rogue-agent incidents, including OpenAI’s models reaching an Australian Medicare portal, shows how far a goal-driven agent will go when nothing stops it.
Start with an inventory
Before buying anything, list the agents you know about: copilots switched on in SaaS apps, automations built by business teams, and internal agents built on model APIs. The gap between that list and what a discovery tool finds is the size of your agent sprawl.
Map permissions, not just agents
An agent’s risk comes from what it can reach. Record which identity each agent runs as, which OAuth grants and API keys it holds, and which systems those unlock. Our guide to AI agent security covers the access patterns in more depth, and our piece on why agent identity comes before a gateway explains the sequencing.
Make offboarding include agents
The former employee’s Salesforce agent is the example to remember. When someone leaves, revoke the agents and integrations they created, not just their account. Agent sprawl grows fastest where nobody owns an automation after its author moves on.
Watch prompts and tool calls
Discovery tells you what exists. Runtime monitoring tells you what it is doing. Whether you buy it or build it, logging the tool calls agents make, and alerting on unusual ones, is the control that catches an agent going somewhere it should not.
Questions to Ask an Agent Sprawl Vendor
With two dozen vendors in the market, the useful questions are the ones that separate them.
| Question | Why it matters | What Reco says publicly |
|---|---|---|
| How do you find agents outside the apps you integrate with? | Shadow agents live where integrations do not reach | Browser and network signals |
| Which of our apps do you cover today? | Coverage gaps become blind spots | More than 280 integrations |
| Can you revoke access, or only report it? | Visibility without action leaves the risk in place | Reduce excessive permissions, revoke outdated access, disable risky integrations |
| Do you inspect prompts and tool calls at runtime? | Posture alone misses misuse in progress | Controls to inspect prompts and tool calls |
| How quickly do you add a new app? | New AI features ship weekly | Hours via the Reco Factory; “within days” per Klein |
| Who else in our sector uses you? | References matter in a young category | About 40% of the business is financial services; AT&T is a named customer |
Ask for evidence, not a demo
A discovery tool’s value shows up in your environment, not the vendor’s. A time-boxed trial against a known inventory, with a count of agents found that you did not know about, is a better test than any slide on agent sprawl.
Agent Sprawl and Reco FAQs
How much has Reco raised?
$140 million in total, including the $55 million announced on 29 September 2026 and a $30 million Series B in February 2026.
Who invested in Reco’s new round?
AT&T Ventures, the venture arm of AT&T, which is also a Reco customer, plus Forestay and Quadrille Capital.
What is agent sprawl?
The uncontrolled growth of AI agents, copilots and automations across an organisation, each with its own identities, permissions and connections, faster than security teams can track or govern them.
Who are Reco’s competitors?
TechCrunch counts at least two dozen AI agent security vendors, including AIR, Cymphony, HiddenLayer, Zenity and CrowdStrike, with different approaches to discovery, data access, supply chain and runtime control.
Where is Reco based?
Coverage describes it as New York-based, and its February release was datelined New York. The September release was datelined Altamonte Springs, Florida.
References
Reco raises $55M as AI agent security startups crowd the market (TechCrunch)
Reco Raises $55 Million for Agentic Security (SecurityWeek)
Reco Raises $30M B Round for a Total of $85M (Newswire)
AIR raises $50M to help companies vet the skills and add-ons AI agents use (TechCrunch)
Sequoia doubles down on Cymphony as AI agents create new enterprise security risks (TechCrunch)
HiddenLayer nabs $100M as enterprises rush to secure their AI deployments (TechCrunch)
CrowdStrike unveils Falcon Guardian for AI agent security (CrowdStrike)
More AI coverage: explore Progressive Robot's AI Models, Tools & Releases hub — hands-on reviews, setup guides and benchmarks in one place.