Screenshot of Reco State of Agent Security 2026 report highlighting 80% AI tools without oversight

Almost all AI tools are now running with no oversight from IT — putting companies in the firing line

Enterprises are racing to embed AI, yet 80% of those tools operate without IT oversight, exposing a massive blind spot that can turn productivity gains into data‑leak catastrophes.

Scale of Uncontrolled AI Deployments

The Reco State of Agent Security 2026 report found that smaller firms deploy 414 AI tools per 1,000 employees without any formal approval, a mix of browser extensions and workflow add‑ons that slip past traditional procurement gates. Those “shadow” agents multiply the attack surface, because each tool inherits the permissions of the user who installed it.

Beyond the obvious SaaS apps, the study shows AI agents nesting inside existing software, effectively piggy‑backing on trusted platforms. This hidden integration means security teams often never see the code executing, making it impossible to apply standard hardening or patch cycles.

Technical Vulnerabilities Exposed

Reco’s analysis of 500 agent tools revealed that 62% can both read local data and reach the internet, a combination that creates a direct conduit for exfiltration. When an agent can harvest files and simultaneously contact external servers, the data loss vector bypasses network segmentation and endpoint detection.

The same report catalogued 637 AI‑agent‑related vulnerabilities, ranging from insecure credential storage to command‑injection flaws. Each vulnerability represents a potential foothold for attackers, especially when agents run with elevated user rights inherited from the host application.

Organizational Attitudes and Policy Gaps

Telemetry from 62 enterprise‑scale businesses across finance, healthcare, retail, and telecom (Jan 1–Aug 1 2026) paints a “free‑for‑all” mindset toward AI adoption. Even where formal review processes exist, employees routinely bypass them for low‑level tools, eroding the intended control framework.

This circumvention is not merely procedural; it translates into operational risk. When policies are ignored, data governance collapses, compliance audits flag violations, and the organization becomes a prime target for nation‑state and ransomware actors seeking to exploit the unmonitored agents.

What This Actually Means For You

  1. Inventory blind spots now. Without a clear list of active AI agents, you cannot assess exposure or prioritize remediation.
  2. Prioritize agents that access local files and external networks. Those represent the highest data‑exfiltration risk.
  3. Enforce a centralized approval workflow. Even low‑impact extensions must pass a security review before deployment.
  4. Integrate agent telemetry into existing SIEM solutions. Real‑time alerts on anomalous outbound traffic can catch misuse early.
  5. Educate staff on the hidden costs of “quick‑add” AI tools. Awareness reduces the temptation to sidestep IT.

Immediate Action Steps

Start by running an automated discovery scan across endpoints to surface any unknown browser extensions, scripts, or embedded agents. Cross‑reference the findings with your asset inventory and flag any that lack a documented approval record.

Next, institute a policy that mandates all AI‑related software—regardless of perceived simplicity—be logged in a central repository before use, and tie that repository to your existing patch‑management and endpoint‑detection platforms.

Frequently Asked Questions

How many AI tools are used without IT approval?

The Reco report indicates that smaller companies employ 414 AI tools per 1,000 employees without any IT sign‑off, highlighting a pervasive shadow‑IT problem.

What percentage of AI agents can read local data and access the internet?

Analysis of 500 agents showed that 62% have both local data read capability and internet connectivity, creating a direct path for data exfiltration.

What are the main security risks of unmonitored AI agents?

Unmonitored agents expose organizations to credential leakage, command injection, and unauthorized data transfer, as evidenced by the 637 vulnerabilities catalogued in the study.

What Do You Think?

Given the clear trade‑off between rapid AI adoption and hidden security exposure, should enterprises sacrifice speed for stricter oversight, or is there a middle ground that preserves both innovation and safety?

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.