Reco has raised $55 million in additional funding as enterprises confront a rapidly expanding security challenge: governing thousands of AI agents operating across applications, identities and sensitive corporate data. The investment includes AT&T Ventures as a strategic investor, alongside Forestay and Quadrille Capital, bringing Reco’s total funding to $140 million.
The funding reflects a broader shift from securing generative AI applications to controlling agentic AI. Unlike conventional applications, autonomous agents can access data, invoke APIs, use enterprise identities and initiate workflows. As their numbers increase, organizations face “shadow AI” risks where security teams may not even know which agents are active or what permissions they possess.
Reco addresses this through its Reco Graph, which connects agents with applications, people, accounts, permissions, APIs, sessions, workflows and MCP tools. This allows enterprises to discover agents, identify excessive privileges and understand how an apparently legitimate agent could create an unexpected path to sensitive information.
The scale of the problem is significant. CEO Ofer Klein said Reco discovered 21,000 previously unknown agents at one Fortune 100 customer. He also said about 40% of agents discovered across enterprises have potentially dangerous combinations, such as access to sensitive files while having an indirect connection to the internet. These figures are company-reported rather than independently verified.
The larger message is clear: AI governance is moving toward runtime security. Enterprises will increasingly need continuous discovery, identity controls, least-privilege access, data protection and real-time monitoring of agent actions. Securing AI will no longer mean protecting only models and prompts—it will mean governing what autonomous agents can access, decide and execute across the enterprise.





