> ## Content Index
> Fetch the complete content index at: https://nexi.fund/llms.txt
> Use this file to discover other available public pages before exploring further.

# AI agents got their own security budget: Reco adds $55M and Rig Security emerges with $12M on the same day
- URL: https://nexi.fund/reco-nonhuman-identity-2026/
- Published: 2026-10-03T13:30:17.000Z
- Updated: 2026-10-03T13:30:17.000Z
- Description: On 29 September 2026 Reco added $55M to reach $140M in total while Rig Security left stealth with $12M, both betting that non-human identity governance is a market. CSA research puts the underlying gap at 20% revocation maturity and 1 in 20 identities holding full admin.
- Author: Nexi.fund Labs
- Tags: AI & Infrastructure, #mode-6, #hook-statistic, #track-B

One in five. That is the share of organizations that can revoke an API key on request, according to the Cloud Security Alliance's most recent survey of non-human identity security. The other four in five are running fleets of software agents on credentials nobody ever handed back.

On the morning of 29 September 2026, two companies announced money for the same problem from opposite ends of the stack. Reco, the Tel Aviv vendor that maps AI agents inside enterprise networks, added $55M in a round led by AT&T Ventures, alongside Forestay Capital and Quadrille Capital, bringing total funding to $140M. Rig Security, founded in 2025 and until Monday unknown outside its own website, emerged from stealth with $12M to stop agents at the endpoint. Neither company claims the category. Both are betting that the control plane for machine identities will be worth more than the agents running on it.

Legacy identity management was built for humans who log in, and for service accounts that a human created, reviewed and eventually deleted. Agents break all three assumptions at once.

What this radar covers

### Two rounds, one missing layer

Reco found 21,000 previously unknown agents inside a single Fortune 100 customer. Rig Security blocks an agent at the socket without cutting off the human whose credential it borrowed. RSA and Delinea shipped competing answers in the same week. Underneath all four stories sit two numbers from CSA and Entro research: 1 in 20 non-human identities holds full administrative privilege, and only 20% of organizations can revoke an API key at all.

Cloud Security Alliance

### 20%

of organizations have a formal process for offboarding and revoking API keys

up only 1 in 5 hold the process at all

SurveyState of Non-Human Identity Security

MeasuredA documented, repeatable revocation process

ScopeMachine and application identities, agents excluded

Entro Security, cited by CSA

### 1 in 20

non-human identities holds full administrative privilege over production

up 5% of every machine identity fleet

SourceEntro Security research, H1 2025

CountedNon-human identities with admin-equivalent rights

Baseline5% privilege inflation against human admin counts

Reco, cumulative funding

### $140M

raised in total after a $55M strategic round closed on 29 September 2026

up $55M added on 29 September 2026

RoundStrategic, extension rather than a priced stage

LeadAT&T Ventures, with Forestay Capital and Quadrille Capital

Before it$30M round closed in February 2026

## The map nobody had

Reco's pitch is discovery, and the pitch starts with a number that should worry anyone running agents in production. One Fortune 100 customer deployed Reco's platform and found 21,000 agents it had never inventoried. Not 21,000 risky ones. Twenty-one thousand that no human being had named, approved or logged.

The mechanism is a graph. Reco Graph unifies network traffic, endpoint telemetry, connected applications and identity-provider records, then resolves the resulting mess into a single inventory where every node carries an owner, a permission set and a known blast radius. An agent with an entry in that inventory can be given least privilege, can be watched, can be switched off. An agent without one is indistinguishable from ordinary east-west traffic.

Reco found 21,000 of them in a single week of deployment. Nobody owned one.

The funding scale suggests investors agree the inventory problem is the entry point rather than the destination. Reco integrates with more than 280 applications, and its CEO Ofer Klein told TechCrunch the company's valuation has more than doubled since February, when it closed a $30M round, into what he called the high hundreds of millions. That is a company estimate rather than a disclosed valuation, and it is the kind of number that travels. The number worth holding is the market one: Grand View Research puts agentic AI security at $1.3B in 2025 and $17.8B by 2033, a 38.9% compound annual rate. Reco is betting the inventory layer comes first. Every vendor in this radar is betting on something adjacent to it.

## The revocation gap

Definition

### What a non-human identity actually is

A non-human identity is any credential that authenticates a machine rather than a person: an API key, a service-account token, an OAuth client, a certificate, a CI job. An AI agent is one more thing holding one of those credentials, and it differs in three ways that break existing controls. It picks its own tools at runtime. It delegates work to other agents, forming chains where no single system holds the whole authority. And it disappears when the task ends, taking its credential with it if nobody noticed the task started.

The CSA numbers describe the floor under all of this, and the floor is lower than most security teams assume. Entro Security's research, cited in CSA's whitepaper, found 1 in 20 non-human identities holding full administrative privilege. CSA's own survey found only 20% of organizations with a formal process for offboarding and revoking API keys.

Both studies were run against machine identities as they existed before the agent wave. Nobody measured agent credentials specifically, because there is no agreed way to count them yet. Read the two figures together and the shape of the problem becomes plain: privilege accumulates on credentials faster than any organization can write off, and the apparatus for cleanup was already missing.

Frameworks have not caught up either. CSA's assessment is that SOC 2, ISO 27001, PCI DSS, NIST 800-53 and the EU AI Act all contain provisions touching identity and access management, and none of them were written with agentic credentials in mind. An auditor can certify a control that never had a way to see the agent.

The structural problem

### The borrowed credential

An agent does not authenticate as itself. It authenticates with a human's token, a service account's key, or an OAuth grant scoped for a different purpose. Every control that keys on the principal sees the human. Revoke the credential and the legitimate user loses access mid-task; leave it and the agent keeps it. There is no clean middle option in today's tooling, which is why the security case for agents stalls at the credential boundary.

## Blocking at the socket

Rig Security takes the opposite approach, and announced it on the same morning. Its platform has two named parts. RICE, the identity correlation engine, works out which actions belong to which agent. Bifrost is a lightweight sensor installed at the endpoint that separates an agent's session from the user's own and can halt the agent alone, leaving the human's session intact. The company's pitch is that this makes least privilege enforceable without a new identity system, which is a different bet from Reco's.

The funding behind it is respectable for a 2025-founded company: $12M seed, co-led by Ten Eleven Ventures and Brightmind Partners, with the CrowdStrike Falcon Fund participating. Guy Kozliner, who founded Rig Security in Tel Aviv and previously built Siemplify, told SecurityWeek the company is already in production at Fortune 200 organizations with roughly 20 employees. That is a small team claiming large deployments, and it deserves the same skepticism any such claim receives.

Two incumbents answered inside the same week. RSA introduced Agent ID, positioned around lifecycle governance for AI agents rather than endpoint enforcement. Delinea pushed continuous runtime authorization, granting and withdrawing machine access as a session runs. Both are large enough to bundle the capability into existing contracts, which is the structural disadvantage every startup in this radar faces.

## Three answers, side by side

### Where each answer intervenes

| Approach                            | Intervenes at                 | Unit of control                     | Blind spot                                    |
| ----------------------------------- | ----------------------------- | ----------------------------------- | --------------------------------------------- |
| Application graph (Reco)            | Network and application layer | Agent as a node in an account graph | Agents that never generate observable traffic |
| Endpoint enforcement (Rig Security) | Socket and endpoint           | Session attributed to an agent      | Cloud-native agents with no endpoint at all   |
| Provider-native (RSA, Delinea)      | Identity provider             | Token, grant and certificate        | Credentials that never came from the provider |

Each approach solves a different slice. The open question is whether the slice survives contact with an agent that runs entirely inside someone else's cloud.

## What breaks on Monday

The practical consequence for an engineering team is narrower than the market sizing suggests. Three checks cost a sprint and cover most of the exposure.

First, count what you cannot name. Pull every credential currently attached to an agent from your identity provider and compare that list against your inventory. Reco's 21,000 figure describes the gap that appears when nobody has ever run that comparison. Most organizations cannot produce the first list at all, because agent credentials are minted by the agents themselves through delegated OAuth grants.

Second, find the delegation chains. Any agent that can call a tool which can call another agent produces an authority path that no single review captures. Ask for a graph of which agents can reach which tools, then check how many of those paths terminate in an admin scope. Entro's 1-in-20 finding describes the endpoint of exactly those paths.

Third, test revocation before you need it. Pick one non-production agent, revoke its credential, and time how long until it stops working. Most teams find the answer is never, because the agent holds a cached token or a copy of the key in an environment variable. Twenty percent of organizations have a formal process on paper. Very few can demonstrate that the process terminates a running process.

None of these three checks requires buying anything. That is the uncomfortable part of the week's funding news: the gap both startups are selling against is measurable today with the tooling most teams already own, and CSA already measured it.

## What we wrote before

This is the third funding story on agent governance in three weeks, and the market is starting to look crowded rather than empty. In September we covered AIUC raising $40M to certify the very agents enterprises already deploy, and questioned then whether certification would arrive before the incidents did. The CSA figures in this radar are the first hard answer: the incidents already have a name and a measured prevalence. Certification has a market. So does revocation.

## The skeptic's case

Bear case

### Nobody has proven the spend

Three arguments deserve weight. First, inventory tooling monetises uncertainty, and the 21,000 figure is a vendor telling you about a customer who bought the tool to find it. Second, the incumbents are shipping the same capability inside contracts they already own, which compresses the price a startup can charge for the same outcome. Third, if agent usage collapses into a handful of platform providers, the control layer gets absorbed rather than sold. A fourth: agents that matter most run in infrastructure the buyer does not operate, so endpoint enforcement has the smallest addressable market of the three.

Key conclusions

### What to hold from this radar

First, the gap is measured and it is upstream of every vendor here. Agentic security is being sold as a new category while the underlying revocation gap is a pre-existing IAM deficiency the CSA quantified in human terms.

Second, the three architectures are complementary in description and competitive in practice. Whoever owns the inventory owns the policy, and policy is where the budget renews.

Third, the incumbents' timing is the real signal. RSA and Delinea moving in the same week as two startups suggests the category has a 2027 shape, and the fight will be over who holds the default position when agent identity becomes a line item.

Signals to watch

### Four checks over the next two quarters

- **Revocation as a purchased line item.** A named non-human identity product inside a major IAM suite would confirm the category is being absorbed rather than expanded.
- **CSA tracking agent credentials separately.** The next survey version, which should drop agent identities out of the machine identity bucket entirely.
- **Rig Security enterprise proof.** A named reference customer with production scale, rather than a Fortune 200 count.
- **Reco's next priced stage.** A conventional round after the strategic extension would convert a company estimate into a market-cleared number.

## Sources

[ Reco raises $55M as AI agent security startups crowd the market TechCrunch, 29 September 2026 · Ram Iyer ](https://techcrunch.com/2026/09/29/reco-raises-55m-as-ai-agent-security-startups-crowd-the-market/?ref=nexi.fund) 

[ Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks SecurityWeek, 29 September 2026 · Ionut Arghire ](https://www.securityweek.com/rig-security-emerges-from-stealth-with-12m-to-tackle-agentic-ai-identity-risks/?ref=nexi.fund) 

[ Alarm sounds on agentic governance as rapid deployment creates security gaps Biometric Update, 30 September 2026 ](https://www.biometricupdate.com/202609/alarm-sounds-on-agentic-governance-as-rapid-deployment-creates-security-gaps?ref=nexi.fund)