Posture tells you what an agent can reach. Runtime has to control what it's doing right now.

.png)
Reco already maps every agent's blast radius: its identity, its permissions, what it's connected to, what it's actually doing. That's posture, and it answers the question a security team asks first: what could go wrong here?
It doesn't answer the second question. What's happening right now, and can I stop it? That's runtime, and it's what we're expanding with three new capabilities: Browser Guard, prompt and tool-call analysis, and Smart Remediation.
Enforcement without a new gateway
Most runtime security today means routing traffic through a new piece of infrastructure: a gateway or proxy that inspects every prompt and model call before it's allowed through. That means new change management, a new point of failure, and months before a security team sees value.
We built AI Runtime to enforce at the points that already exist: the browser, the app, the endpoint. No new proxy to stand up, no traffic to reroute.
Browser Guard: visibility where shadow AI actually starts
Most personal AI use doesn't go through a sanctioned tool. It happens in a browser tab, through a personal account, outside anything IT provisioned. Browser Guard is built for that gap specifically.
Phase one is live now in early access: discovery. It shows which employees are using which AI tools, through which accounts, and how often. Phase two adds blocking and policy enforcement at the browser level, targeted for early access on July 29.
Prompt, response, and tool-call analysis: context at the moment it matters
This is the part of AI Runtime that inspects every prompt, every AI response, and every tool call in real time, and checks it against the Reco Graph: which agent is involved, how risky that agent is, what it's connected to (including every MCP server it reaches), and who's behind it, including that user's full SaaS and AI footprint.
That context is what makes blocking possible instead of just logging. Targeting general availability in October.
Smart Remediation: closing the loop
A risk finding only matters if something happens after it. Smart Remediation, which shipped in July, takes a finding and turns it into a specific action: scope this permission down, revoke this connection, update this policy. It factors in what the agent actually needs to do its job, so it won't recommend killing access the agent depends on. That's the difference between a list of flagged agents and a fix.
None of this replaces posture. It runs on top of it. An enforcement decision is only as good as the identity, permission, and connectivity context behind it, and that's what Reco already builds for every agent in your ecosystem.
See it at Black Hat
We're at Black Hat USA 2026, August 2-7, booth No. 1644, with live demos of AI Runtime running alongside the rest of the Reco Platform. If you're there, stop by. If not, get in touch and we'll set up a walkthrough.

Gal Nakash
ABOUT THE AUTHOR
Gal is the Cofounder & CPO of Reco. Gal is a former Lieutenant Colonel in the Israeli Prime Minister's Office. He is a tech enthusiast, with a background of Security Researcher and Hacker. Gal has led teams in multiple cybersecurity areas with an expertise in the human element.
Gal is the Cofounder & CPO of Reco. Gal is a former Lieutenant Colonel in the Israeli Prime Minister's Office. He is a tech enthusiast, with a background of Security Researcher and Hacker. Gal has led teams in multiple cybersecurity areas with an expertise in the human element.

.png)

