This Startup Found 21,000 Rogue AI Agents Hiding Inside One Company

Terms like “AI sprawl” have become common fare across tech social media as enterprises deploy AI agents en masse. But CISOs worried about securing swarms of agents suddenly operating across their networks are increasingly encountering a different kind of sprawl entirely: a growing wave of vendors offering to help, and an AI agent security startup landscape becoming rapidly crowded as a result.

A quick glance at public Crunchbase and PitchBook profiles turns up at least two dozen companies now selling some form of AI agent security. Some vendors vet the tools agents actually use, while others focus on controlling what data agents can access. Others, like CrowdStrike, build detection and response controls directly on the devices agents run on, while still others focus specifically on finding and resolving unapproved AI usage across an organization.

How Reco Is Repositioning to Compete

Product approaches differ across this crowded field, though their core promises, discovering and governing agents, tend to sound remarkably similar, involving knowledge graphs, continuous monitoring, runtime security, and tool access vetting.

Some companies are even actively updating their products to join this growing wave. Until last year, AI security startup Reco mostly sold software to map and secure SaaS and AI platforms. Now, it’s repositioned around a broader solution using a context graph connecting agents to apps, people, accounts, and permissions, giving security teams clear visibility into exactly what an agent can reach, along with the ability to cut off unnecessary access.

According to Reco co-founder and CEO Ofer Klein, the biggest shift driving this broader pivot was that companies are now building and deploying AI agents faster than they can realistically track them. At one Fortune 100 customer, he said, Reco’s platform uncovered 21,000 agents the company didn’t even know existed. At a large financial services customer, the startup claims it identified an agent set up by a former employee that could access Salesforce and share that data with an outside domain the company had no visibility into whatsoever.

“The market demand right now for agent security is not only about the agent itself; it’s about the entire ecosystem end-to-end,” Klein told TechCrunch in an exclusive interview.

Other Security Startups Echo the Same Urgency

Klein isn’t alone in stressing how urgent this problem has become. Chris Sestito, co-founder and CEO of security startup HiddenLayer, told TechCrunch earlier this month that once agents reach production, the scale of associated costs and risk shifts from theoretical to “full scale really quickly,” noting that more than 50 of his own customers already have AI agents in production touching critical systems and sensitive assets.

Another AI startup, Cymphony, said it discovered roughly 85,000 files at one US public company that had become accessible to AI tools and agents without proper oversight.

Investors Are Clearly Paying Attention

There’s no shortage of investor interest in companies positioned to profit from helping enterprises find and secure this rapidly expanding web of agents, and Reco has capitalized directly on that demand. The startup announced Tuesday it raised $55 million, building on a $30 million Series B round from February. AT&T, an existing Reco customer, invested in this latest extension through its venture arm, alongside Forestay and Quadrille Capital.

Klein said the company’s valuation has “more than doubled” since the Series B was first announced, vaguely estimating it now sits in the “high hundreds of millions,” though he declined to share specific figures. Annual recurring revenue currently sits in the “double-digit millions,” he said, with expectations to triple this year. The startup now counts more than 100 customers, with financial services companies making up roughly 40% of its overall business.

What Sets This AI Agent Security Startup Apart

Reco’s core bet appears to be that its existing coverage across SaaS applications, and the AI agents those platforms increasingly offer, will help it stand out within an increasingly crowded field. The company currently integrates with more than 280 apps, and Klein says new integrations can typically be added within just days.

According to Klein, the platform also uses browser and network signals to identify agents operating outside the apps it connects to directly within a company’s environment, alongside controls specifically designed to inspect prompts and tool calls for suspicious activity.

The startup plans to use its new funding toward hiring, sales, partnerships, and customer support, bringing Reco’s total capital raised to date to $140 million, a clear signal of just how seriously investors are taking the AI agent security startup race as enterprises scramble to keep pace with their own rapidly multiplying AI deployments.

AI News

Leave a Reply

Your email address will not be published. Required fields are marked *