Reco adds live AI runtime controls for browser use
Thu, 30th Jul 2026 (Today)
Reco has added new AI runtime security features to its Agent Ecosystem Security platform, extending oversight of AI agents into live activity.
The update adds browser-level enforcement, real-time prompt analysis and blocking, and automated remediation. It is designed to help security teams detect risky AI activity as it happens, apply policy controls in the browser, and automatically reduce access or permissions.
The move expands a platform that has focused on mapping how AI agents connect to applications, permissions, and workflows inside an organisation. The latest update shifts that focus from visibility and posture management to direct intervention when an agent or user takes action.
One part of the release is Smart Remediation, which shipped in July. The feature turns risk findings into automated remediation steps by recommending scope changes, permission revocations, or policy updates that lower risk while preserving an agent's ability to perform its role.
Those recommendations are based on what an agent actually needs to operate. The aim is to avoid broad access cuts that could interrupt business processes or disable tools that staff depend on.
Browser controls
Another element is Reco Browser Guard, now in early access. The product targets personal and unsanctioned AI use in the browser, an area many companies struggle to monitor because employees can access public AI tools outside approved channels.
In its first phase, Browser Guard identifies which employees are using AI tools, which accounts they are using, and how often they access them. A second phase adds browser-level blocking and policy enforcement, giving security teams a way to act on that usage rather than simply observe it.
The runtime expansion also covers prompt, response, and tool-call analysis and blocking. Its policy engine now evaluates prompts, AI responses, and tool calls in real time against the Reco Graph, a data model that ties together agents, users, applications, permissions, and external connections.
That context is meant to show which agent is involved in an interaction, how risky it is, what it is connected to, and which user is behind the activity. It can also include the MCP servers an agent reaches and the wider SaaS and AI footprint of the associated user.
For security teams, the commercial pitch reflects a broader industry concern about AI systems moving beyond passive assistance and taking action across enterprise software environments. As organisations connect agents to internal applications, external services, and collaboration tools, the security challenge shifts from governing access at setup to controlling behaviour in operation.
Reco said its AI Runtime component does not require organisations to reroute traffic through a gateway or proxy. That may matter to security teams that are cautious about products requiring major network changes or adding complexity around latency and deployment.
Ofer Klein, chief executive officer of Reco, linked the distinction between posture management and runtime control to how agents behave once deployed.
"Posture tells a security team what an agent can reach, while runtime provides the control over what it's doing right now, without asking organizations to reroute their traffic through a gateway to get there," said Klein.
He also pointed to the browser as a key point of exposure for AI use by staff.
"With Browser Guard, Reco secures the interface where most personal AI use actually happens," said Klein.
Growing market
Reco is part of a growing group of security vendors building tools around AI agents rather than treating them as a minor extension of conventional software governance. The company describes its focus as securing the operating environment around agents, including identities, app connections, permissions, and workflows.
The platform includes more than 260 app integrations and more than 1,000 detection controls, and it has detected more than 1 million agents. Reco also said its customer base includes Fortune 500 enterprises, reflecting demand from large organisations trying to track both approved and shadow AI activity across their software estates.
The latest update suggests vendors in this segment are moving quickly from discovery and monitoring to enforcement and automated action. As more companies allow AI systems to interact directly with business tools, the ability to block prompts, limit tool calls, and adjust privileges in real time is becoming a central part of enterprise security design.