Reco's $55M Round Signals AI Agent Visibility as an Enterprise Control Gap
What happened
Agentic security firm Reco announced a $55 million funding round led by AT&T Ventures, raising its total funding to $140 million. Reco Graph maps every AI agent deployed in an enterprise. It tracks each agent's identity, permissions, accessible data, and external tool connections. Those connections run via Model Context Protocol (MCP) servers, which let agents take actions in external systems. Reco integrates with OpenAI, Anthropic, and Microsoft Copilot deployments. The round follows a broader pattern of enterprise tooling investment. Recent drivers include 68 MCP server security vulnerabilities in a single month and audit findings that 91.8% of MCP servers lack proper authentication controls.
Why it matters
- ·Most organizations cannot enumerate which AI agents are running, what permissions they hold, or which external systems they can reach. Without that inventory, least-privilege enforcement, access reviews, and incident response are impossible in practice.
- ·Regulatory pressure is tightening around agent identity and access controls. The Five Eyes Guidance on the Careful Adoption of Agentic AI Services and the IMDA Model AI Governance Framework now treat agent permission management as a baseline requirement, not an advanced practice.
- ·Vendor concentration risk is real here. Relying on a single third-party tool for the entire agent visibility layer creates a new single point of failure. Compliance teams must assess what happens to their agent monitoring program if that vendor changes terms, is acquired, or experiences an outage.
Governance controls affected
What to do now
- ☐Ask your engineering or IT team to produce a list of every AI agent currently running in production, including what user account or system identity each agent operates under and what it is permitted to do.
- ☐Review whether your existing access management reviews cover AI agent identities the same way they cover human employee accounts, and flag any gaps to your identity and access governance team.
- ☐Assess your current MCP server inventory: identify every external tool connection an AI agent can use, confirm each connection is authenticated, and document who approved each one.
- ☐Evaluate any agentic visibility or monitoring vendor, including Reco, against your standard third-party AI vendor due diligence process before procurement, treating agent monitoring tooling as a high-dependency system.
- ☐Confirm your AI incident response playbook covers scenarios where an agent acts outside its approved permissions, including who is notified, what logs are preserved, and how access is revoked.
What to watch next
The market for tools that provide visibility into AI agent behavior is expanding rapidly alongside regulatory guidance that treats agent identity and permission governance as an audit-ready requirement. Compliance teams should watch for the NIST AI Risk Management Framework and the EU AI Act to produce more specific agent-layer controls as enforcement activity matures. Funding rounds in this space follow earlier investments in firms like Rig Security. The market is treating agent visibility as a distinct, non-negotiable control domain. Organizations that have not yet formalized agent identity governance should treat that gap as a priority before the next external audit cycle.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
