9 Sources
[1]
Shadow AI is already inside your company. Here's how to get control of it
Reco's State of Agent Security 2026 report found that 80% of AI tools in its telemetry operated without IT oversight, with SMBs averaging 414 unsanctioned AI tools per 1,000 employees. IBM found shadow AI added $670K to breach costs. The article explains how companies should triage: map what each
[2]
AI agents are poised to be the next hacking victims, cyber CEO predicts
Why it matters: Cyber defenses are tailored toward predicting and defending humans. Now, companies need to start treating the agents roaming their systems as both potential adversaries and the targets. Driving the news: Gerry's prediction during an interview at the Black Hat cybersecurity
[3]
Almost all AI tools are now running with no oversight from IT -- putting companies in the firing line
* Report claims an incredible 80% of AI tools are running in organizations without IT oversight * Browser agents and integration tools are escaping the attention of security and IT engineers * Reco's State of Agent Security 2026 report also tracked 637 vulnerabilities across agents and
[4]
The more AI banks deploy, the bigger the cyber battlefield gets
Indian banks and fintech firms face growing AI-powered cyber threats. Attackers use AI to find vulnerabilities faster than before. Financial institutions are deploying AI to detect and respond to these evolving threats. This creates a new cybersecurity arms race for the sector. Banks must also
[5]
When AI becomes a double agent
A person holding a smartphone displaying an AI folder with icons for ChatGPT, Perplexity, Gemini, Claude, and Grok among a backdrop of greenery. While organizations continue to worry about employees accidentally entering trade secrets into ChatGPT, Copilot, Claude, or Gemini, the real threat has
[6]
Security and Monitoring Must Move at the Same Pace as AI Adoption
AI permissioning should be part of the rollout plan and happen in parallel with adoption, rather than being retrofitted after an incident. As enterprises accelerate AI adoption, growing autonomy of AI systems is creating new security and governance challenges. From shadow AI and unauthorised tools
[7]
The Shadow AI Crisis: Why AI and Cybersecurity Are Colliding Inside Organisations Without IT Teams Knowing
The major threat of AI security within a company may not even be the most sophisticated cyberattack, but an employee putting confidential data into an AI tool that the IT department does not know exists. The phrase "shadow AI" describes the use of AI applications, assistants, extensions, or agents
[8]
'No principles set in place for AI agents', says a panel at Youth IGF
"There are no principles set in place specifically for AI agents," said Gowree Gokhale, an independent lawyer, to MediaNama after a panel discussion on 'Cybersecurity in the Age of AI' at the Youth Internet Governance Forum India (IGF). The event was held at IIT Bombay on September 4,
[9]
In a World of Rogue Agents, Who Gets Arrested for a Cybercrime?
The day when AI agents attack other AI agents and not humans is just round the corner and enterprises may be the worst victims The recent instances of OpenAI agents escaping a sandbox testing environment and hacking into Hugging Face and a German wiki platform suggests a serious challenge. That
Share
Copy Link
A new report reveals that 80% of AI agents operate without IT oversight, with small and midsize businesses averaging 414 unsanctioned AI tools per 1,000 employees. Shadow AI is adding $670,000 to data breach costs, while cybersecurity experts warn that AI agents are becoming both the next major hacking victims and attack vectors as organizations struggle to manage access to sensitive data.
AI agents are quietly embedding themselves across corporate networks, and most organizations have no idea they're there. Reco's State of Agent Security 2026 report found that 80% of AI tools operate without IT oversight
1
3
. At small and midsize businesses, the scale is staggering: an average of 414 unsanctioned AI tools for every 1,000 employees1
. These aren't just experimental tools. They're browser extensions, meeting assistants, CRM workflows, developer environments, and app-to-app integrations that employees activate without procurement meetings or security reviews1
. A marketing manager switches on an AI feature in existing software. A developer connects an assistant to an internal knowledge base. Someone adds an AI meeting tool and clicks "Allow" when it requests access to files or calendars. Nobody thinks they're introducing enterprise software, yet shadow AI is now woven into the fabric of daily operations.
Source: Jerusalem Post
The financial impact of unmanaged AI agents is already measurable. IBM's 2025 Cost of a Data Breach report, which studied 600 breached organizations across 17 industries, found that one in five had experienced a data breach involving shadow AI
1
. Organizations with high levels of shadow AI recorded breach costs averaging $670,000 more than those with little or none1
. The problem extends beyond simple visibility. Reco's analysis of 500 agent tools revealed that 62% can both read local data and reach the internet, creating direct pathways for data exfiltration3
. Ofer Klein, CEO of Reco, explains that tools appearing as harmless assistants may have permission to read email, summarize files, access customer records, connect to ticketing systems, or interact with source-code repositories1
. To make human work easier, organizations have given AI agents access to sensitive data, customer information, and production systems—essentially handing over the crown jewels2
.Cybersecurity experts predict AI agents will become primary attack vectors and victims. Dave Gerry, CEO of Bugcrowd, told Axios during the Black Hat cybersecurity conference that "we're going to see agents as the victim" and "you're going to start to see agents getting hacked, not people"
2
. Gerry anticipates the bulk of AI agents as hacking victims will occur in enterprise environments, where most AI agents are currently deployed. "It's going to become the No. 1 attack vector that we're going to see," he warned2
. The challenge intensifies as many enterprise-approved tools now have AI capabilities automatically enabled, creating a backlog of technical debt. "You have all of these enterprise-approved tools that now magically got AI turned on," Gerry noted. "Now, there's a backlog of all of this tech debt of things that I approved that I no longer approve"2
. Poor identity controls already account for 60% of all Cisco incident response cases in 2024, and AI agents represent the latest evolution of insider threats2
.A particularly messy problem emerges when employees who created AI agents move on, but the agents remain active. Reco commonly finds these "orphaned agents" when entering customer environments for the first time
1
. An employee connects an agent for a three-month project through OAuth grants, API keys, or service accounts. The project ends, six months pass, and the employee moves to another department. The agent, however, continues operating with its original access to sensitive data. Normal offboarding processes for departing employees work as designed, but integrations and delegated access created by those employees receive far less attention1
. Okta's Businesses at Work 2026 report found that 78% of organizations see controlling access and permissions for non-human identities as a major concern, but only 10% have a strategy for governing them1
. This includes service accounts and machine identities AI agents use to access company systems. Nitin Varma, India and SAARC head at identity security company Saviynt, emphasizes that the traditional question of "who logged in" is no longer sufficient. The critical question now is which identity—human, machine, or AI—is taking action and what that identity is allowed to access4
.The threat landscape has shifted from employees accidentally entering trade secrets into ChatGPT to attacks targeting the AI supply chain itself. A study from early 2026 reveals that 36% of AI add-ons organizations install contain vulnerabilities or hidden malicious prompts
5
. Snyk's ToxicSkills study examined 3,984 AI agent skills and found 36% contained vulnerabilities enabling malicious prompt injection, with researchers identifying 1,467 different malicious payloads and more than 8,000 MCP servers exposed to the public5
. Zero-click attacks have arrived in the AI world. An organization's AI agent can read an innocent meeting invitation or scan a routine document and, without any user interaction, execute malicious code that extracts sensitive information5
. Attackers embed hidden white text in Word documents or inject malicious code into calendar meeting descriptions. Employees ask AI agents to summarize documents or review weekly meetings without suspecting the content could serve as an attack vector. The agent reads the hidden commands, interprets them as instructions, and acts without the user ever opening the file.
Source: Axios
Related Stories
The transition to autonomous agents has opened five distinct attack vectors in the supply chain
5
. First, connectors provide direct access to employees' email accounts, Google Drive, Jira, or GitHub. Second, skill files expand an agent's capabilities and can be programmed to perform automated actions that attackers exploit. Third, plugins expand agent permissions and can embed malicious persistent commands that run every time the agent activates. Fourth, MCP servers connect agents to additional systems within organizations to which they previously had no access. Fifth, add-on marketplaces allow extensions to be installed at the click of a button without secure code-signing mechanisms. Reco's analysis identified 637 AI agent-related vulnerabilities across agents and LLMs3
. Each vector enhances AI agent capabilities while simultaneously expanding the attack surface. The risk materializes during legitimate, everyday use and stems from the efficiency drive characterizing the AI revolution.The cybersecurity arms race has entered a new phase where AI-powered attackers face human defenders—an increasingly untenable situation. Harshil Mathur, CEO of Razorpay, stated at Global Fintech Fest 2026 that "if the threat actor is a model, your defence actor cannot be a human anymore. Your defence actor has to be a model"
4
. Attackers consistently use models to run in loops and find weaknesses across systems. Mathur noted that Razorpay's security team already uses proprietary and open-source AI models to continuously identify vulnerabilities across code and infrastructure4
. The transitionary nature creates particular danger: some companies haven't invested heavily in cybersecurity, but attackers have AI models available. "I think that's a recipe for disaster right now," Mathur warned4
. BCG's latest fintech report estimates Indian banks face 1.6 times the cyberattack intensity of global counterparts, yet while 76% of leaders surveyed rank AI-related attacks as a top concern, only 38% allocate more than 10% of IT spending to cybersecurity4
.Security teams must prioritize AI agents based on what they can actually reach rather than treating all unknown tools equally. Klein advises mapping what each agent can access, identifying current owners, watching for orphaned agents that outlive their creators, and prioritizing agents touching customer data, code, and production systems
1
. The "Lethal Trifecta" occurs when the same agent simultaneously has access to sensitive organizational information like payroll files, exposure to content from untrusted sources such as external documents, and the ability to send information outside the organization5
. When this combination exists, a successful attack becomes a matter of time. Organizations need tiered approval processes for agents based on risk levels: Level A for low-risk read-only tools approved through self-service, Level B for tools with write permissions or access to sensitive data requiring human approval, and Level C for agents with autonomy or production environment access requiring CISO approval and advance attack-scenario exercises5
. Rahul Sasi, CEO of CloudSEK, emphasizes that attackers are targeting the infrastructure running AI itself, and the biggest risk is what an AI agent is allowed to do4
. If a bank gives an AI agent access to customer data, emails, and internal systems, compromising that agent could give attackers the same access. Organizations must implement comprehensive defense architecture combining phased implementation with continuous monitoring, as uniform security solutions or passive blocking are insufficient for the age of agentic AI5
.
Source: CXOToday
Summarized by
Navi
[3]
[5]
14 Aug 2026•Technology

19 May 2026•Technology

16 Jul 2026•Technology

1
Technology

2
Technology

3
Policy and Regulation
