AI Agents Are Operating Unmonitored in 80% of Companies, Creating a New Cybersecurity Battlefield

9 Sources

Share

A new report reveals that 80% of AI agents operate without IT oversight, with small and midsize businesses averaging 414 unsanctioned AI tools per 1,000 employees. Shadow AI is adding $670,000 to data breach costs, while cybersecurity experts warn that AI agents are becoming both the next major hacking victims and attack vectors as organizations struggle to manage access to sensitive data.

Shadow AI Proliferates Across Enterprise Systems

AI agents are quietly embedding themselves across corporate networks, and most organizations have no idea they're there. Reco's State of Agent Security 2026 report found that 80% of AI tools operate without IT oversight

1

3

. At small and midsize businesses, the scale is staggering: an average of 414 unsanctioned AI tools for every 1,000 employees

1

. These aren't just experimental tools. They're browser extensions, meeting assistants, CRM workflows, developer environments, and app-to-app integrations that employees activate without procurement meetings or security reviews

1

. A marketing manager switches on an AI feature in existing software. A developer connects an assistant to an internal knowledge base. Someone adds an AI meeting tool and clicks "Allow" when it requests access to files or calendars. Nobody thinks they're introducing enterprise software, yet shadow AI is now woven into the fabric of daily operations.

Source: Jerusalem Post

Source: Jerusalem Post

Data Breach Costs Surge as AI Agents Access Crown Jewels

The financial impact of unmanaged AI agents is already measurable. IBM's 2025 Cost of a Data Breach report, which studied 600 breached organizations across 17 industries, found that one in five had experienced a data breach involving shadow AI

1

. Organizations with high levels of shadow AI recorded breach costs averaging $670,000 more than those with little or none

1

. The problem extends beyond simple visibility. Reco's analysis of 500 agent tools revealed that 62% can both read local data and reach the internet, creating direct pathways for data exfiltration

3

. Ofer Klein, CEO of Reco, explains that tools appearing as harmless assistants may have permission to read email, summarize files, access customer records, connect to ticketing systems, or interact with source-code repositories

1

. To make human work easier, organizations have given AI agents access to sensitive data, customer information, and production systems—essentially handing over the crown jewels

2

.

AI Agents Emerge as Next Major Hacking Victims

Cybersecurity experts predict AI agents will become primary attack vectors and victims. Dave Gerry, CEO of Bugcrowd, told Axios during the Black Hat cybersecurity conference that "we're going to see agents as the victim" and "you're going to start to see agents getting hacked, not people"

2

. Gerry anticipates the bulk of AI agents as hacking victims will occur in enterprise environments, where most AI agents are currently deployed. "It's going to become the No. 1 attack vector that we're going to see," he warned

2

. The challenge intensifies as many enterprise-approved tools now have AI capabilities automatically enabled, creating a backlog of technical debt. "You have all of these enterprise-approved tools that now magically got AI turned on," Gerry noted. "Now, there's a backlog of all of this tech debt of things that I approved that I no longer approve"

2

. Poor identity controls already account for 60% of all Cisco incident response cases in 2024, and AI agents represent the latest evolution of insider threats

2

.

Orphaned Agents and Identity Management Failures

A particularly messy problem emerges when employees who created AI agents move on, but the agents remain active. Reco commonly finds these "orphaned agents" when entering customer environments for the first time

1

. An employee connects an agent for a three-month project through OAuth grants, API keys, or service accounts. The project ends, six months pass, and the employee moves to another department. The agent, however, continues operating with its original access to sensitive data. Normal offboarding processes for departing employees work as designed, but integrations and delegated access created by those employees receive far less attention

1

. Okta's Businesses at Work 2026 report found that 78% of organizations see controlling access and permissions for non-human identities as a major concern, but only 10% have a strategy for governing them

1

. This includes service accounts and machine identities AI agents use to access company systems. Nitin Varma, India and SAARC head at identity security company Saviynt, emphasizes that the traditional question of "who logged in" is no longer sufficient. The critical question now is which identity—human, machine, or AI—is taking action and what that identity is allowed to access

4

.

AI Supply Chain Attacks and Zero-Click Vulnerabilities

The threat landscape has shifted from employees accidentally entering trade secrets into ChatGPT to attacks targeting the AI supply chain itself. A study from early 2026 reveals that 36% of AI add-ons organizations install contain vulnerabilities or hidden malicious prompts

5

. Snyk's ToxicSkills study examined 3,984 AI agent skills and found 36% contained vulnerabilities enabling malicious prompt injection, with researchers identifying 1,467 different malicious payloads and more than 8,000 MCP servers exposed to the public

5

. Zero-click attacks have arrived in the AI world. An organization's AI agent can read an innocent meeting invitation or scan a routine document and, without any user interaction, execute malicious code that extracts sensitive information

5

. Attackers embed hidden white text in Word documents or inject malicious code into calendar meeting descriptions. Employees ask AI agents to summarize documents or review weekly meetings without suspecting the content could serve as an attack vector. The agent reads the hidden commands, interprets them as instructions, and acts without the user ever opening the file.

Source: Axios

Source: Axios

Five New Attack Vectors in Agentic AI

The transition to autonomous agents has opened five distinct attack vectors in the supply chain

5

. First, connectors provide direct access to employees' email accounts, Google Drive, Jira, or GitHub. Second, skill files expand an agent's capabilities and can be programmed to perform automated actions that attackers exploit. Third, plugins expand agent permissions and can embed malicious persistent commands that run every time the agent activates. Fourth, MCP servers connect agents to additional systems within organizations to which they previously had no access. Fifth, add-on marketplaces allow extensions to be installed at the click of a button without secure code-signing mechanisms. Reco's analysis identified 637 AI agent-related vulnerabilities across agents and LLMs

3

. Each vector enhances AI agent capabilities while simultaneously expanding the attack surface. The risk materializes during legitimate, everyday use and stems from the efficiency drive characterizing the AI revolution.

Attackers Deploy AI Models Against Human Defenders

The cybersecurity arms race has entered a new phase where AI-powered attackers face human defenders—an increasingly untenable situation. Harshil Mathur, CEO of Razorpay, stated at Global Fintech Fest 2026 that "if the threat actor is a model, your defence actor cannot be a human anymore. Your defence actor has to be a model"

4

. Attackers consistently use models to run in loops and find weaknesses across systems. Mathur noted that Razorpay's security team already uses proprietary and open-source AI models to continuously identify vulnerabilities across code and infrastructure

4

. The transitionary nature creates particular danger: some companies haven't invested heavily in cybersecurity, but attackers have AI models available. "I think that's a recipe for disaster right now," Mathur warned

4

. BCG's latest fintech report estimates Indian banks face 1.6 times the cyberattack intensity of global counterparts, yet while 76% of leaders surveyed rank AI-related attacks as a top concern, only 38% allocate more than 10% of IT spending to cybersecurity

4

.

Defending Against the Lethal Trifecta

Security teams must prioritize AI agents based on what they can actually reach rather than treating all unknown tools equally. Klein advises mapping what each agent can access, identifying current owners, watching for orphaned agents that outlive their creators, and prioritizing agents touching customer data, code, and production systems

1

. The "Lethal Trifecta" occurs when the same agent simultaneously has access to sensitive organizational information like payroll files, exposure to content from untrusted sources such as external documents, and the ability to send information outside the organization

5

. When this combination exists, a successful attack becomes a matter of time. Organizations need tiered approval processes for agents based on risk levels: Level A for low-risk read-only tools approved through self-service, Level B for tools with write permissions or access to sensitive data requiring human approval, and Level C for agents with autonomy or production environment access requiring CISO approval and advance attack-scenario exercises

5

. Rahul Sasi, CEO of CloudSEK, emphasizes that attackers are targeting the infrastructure running AI itself, and the biggest risk is what an AI agent is allowed to do

4

. If a bank gives an AI agent access to customer data, emails, and internal systems, compromising that agent could give attackers the same access. Organizations must implement comprehensive defense architecture combining phased implementation with continuous monitoring, as uniform security solutions or passive blocking are insufficient for the age of agentic AI

5

.

Source: CXOToday

Source: CXOToday

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved