2 Sources
[1]
Shadow AI is already inside your company. Here's how to get control of it
Reco's State of Agent Security 2026 report found that 80% of AI tools in its telemetry operated without IT oversight, with SMBs averaging 414 unsanctioned AI tools per 1,000 employees. IBM found shadow AI added $670K to breach costs. The article explains how companies should triage: map what each agent can reach, find who still owns it, watch for orphaned agents that outlive their creators, and prioritize agents touching customer data, code, and production systems. Companies are discovering AI agents connected to email, customer data, and code without IT oversight. Finding them is only the beginning. For most of the past decade, the list of software a company ran was, at least in theory, one that somebody in IT could find. Today, however, AI is making that increasingly difficult. A marketing manager can switch on an AI feature inside software the company already pays for. A developer can connect an assistant to an internal knowledge base. Someone else can add an AI meeting tool or browser extension and click "Allow" when it asks for access to their files or calendar. Nobody necessarily thinks they are introducing a new piece of enterprise software. There is no procurement meeting or lengthy security review. Sometimes all it takes is an OAuth consent screen. Then the security team goes looking. "The first scan often finds AI inside places the organization does not think of as part of its AI program," Ofer Klein, cofounder and CEO of Reco, a company that secures agents for enterprises, said in an interview. That includes "browser extensions, meeting tools, productivity suites, CRM workflows, support tools, developer environments, and app-to-app integrations." Reco's latest The State of Agent Security 2026 report gives some sense of the scale. Four in five AI tools observed in its telemetry operated without IT oversight. At small and midsize companies, it found an average of 414 unsanctioned AI tools for every 1,000 employees. While discovering them solves one problem, it also creates another. What do you do with 400 AI tools you didn't know existed? Start with what the agent can actually reach The obvious response would be to start shutting things down. But in practice, that could create a different mess. Some of those tools may already be doing useful work. One might prepare account updates for salespeople. Another summarizes support tickets. A developer may rely on an assistant connected to a code repository. Klein says the first surprise for security teams is often not the number of AI tools employees have introduced, but how deeply some are connected to the business. "A tool that looks like a harmless assistant may have permission to read email, summarize files, access customer records, connect to ticketing systems or interact with source-code repositories," he said. There is evidence that these unmanaged tools are already showing up in real-world breaches. IBM's 2025 Cost of a Data Breach report, which studied 600 breached organizations across 17 industries, found that one in five had experienced a breach involving shadow AI. Organizations with high levels of shadow AI also recorded breach costs averaging $670,000 more than those with little or none. So instead of treating every unknown AI tool equally, the first priority becomes understanding its reach. An assistant connected only to public information presents a very different problem from an agent that can access customer records, financial systems or production code. Then find out who still owns it Here is where things get particularly messy. An employee connects an agent for a three-month project, the project ends and six months later, the employee moves to another department. The loophole, however, is that the agent is still there. Klein says Reco commonly finds these "orphaned agents" when entering a customer environment for the first time. An agent may have arrived through someone's OAuth grant, API key or service account, and its access can survive changes elsewhere in the organization. He explained that the company's normal process for handling departing employees might work exactly as designed, while integrations and delegated access created by that employee receive far less attention. This is becoming a broader identity problem, with several other reports suggesting that companies are struggling with the same issue as AI agents multiply. For example, Okta's Businesses at Work 2026 report found that 78% of organizations see controlling access and permissions for non-human identities as a major concern, but only 10% have a strategy for governing them. That includes the service accounts and other machine identities AI agents increasingly use to access company systems and data. This leaves security teams with a fairly basic problem. Someone needs to know why an agent is there, what it can access and whether it still needs to be running. When nobody does, an agent set up for a three-month project can quietly become a permanent part of the company. The dangerous agent may look perfectly normal There is a temptation to imagine agent security failures as dramatic events. An autonomous system suddenly goes rogue, does something obviously malicious and sets off alarms across the security team. But Klein believes the reality can be much less exciting. An assistant brought in to summarize support tickets might gradually be connected to other systems, or a workflow might start pulling records that were never part of its original job. In other cases, an agent may send information to the wrong channel or simply keep running long after the person who set it up has moved on. Klein says these problems are often discovered almost by accident. Someone notices an unexpected output, a security review turns up unusual app activity, or an auditor asks who owns a particular agent and nobody is quite sure. By then, it may have been operating that way for weeks or months because, from the outside, much of what it was doing looked like ordinary application activity. This is why simply finding an agent is not enough. Teams also need to know why it is there, who is responsible for it and what it is supposed to be doing. Finding everything is only the first morning According to Klein, companies tend to stall after discovery for three reasons. Nobody knows who owns some agents. Security can see that a tool exists without understanding everything it can access. And when something looks risky, the available response can feel painfully binary: leave it alone or shut it down. A more practical triage starts with the systems a company would least like to lose control of. Agents touching customer information, source code, financial workflows, production systems or external communications go to the front of the queue. From there, teams can identify an owner, examine permissions, remove access the agent no longer needs and decide when it should be reviewed again. That approach also accepts something companies may eventually have little choice but to accept: employees are going to use AI. Trying to catalogue every approved AI application will not tell a security team what is actually happening if employees can activate new capabilities inside existing software or connect agents to company systems themselves. The morning after discovering 400 unknown agents, then, the job isn't to find a giant red button and turn them all off. It's figuring out which ones have the keys to the building.
[2]
Almost all AI tools are now running with no oversight from IT -- putting companies in the firing line
* Report claims an incredible 80% of AI tools are running in organizations without IT oversight * Browser agents and integration tools are escaping the attention of security and IT engineers * Reco's State of Agent Security 2026 report also tracked 637 vulnerabilities across agents and LLMs Unmonitored deployment of AI tools is a risk to security, and puts data at risk, a new study has claimed. The report from Reco, which draws its information from disclosed vulnerabilities, analysis of 500 Model Context Protocol servers, and Reco's own platform telemetry, found four in five AI tools (80%) are running without oversight from IT departments. Of particular concern is the scale of AI applications in use. Smaller companies use 414 AI tools per 1,000 employees without IT approval, apparently a combination of browser extensions and workflows beyond the usual review and approval process. Data risks from unmonitored AI Giving AI tools to employees might unlock productivity boosts, but their use has to be approved. That's the key takeaway from the report, which highlights some concerning cybersecurity figures. For example, it assessed 500 agent tools and found "62% can both read local data and reach the internet." This represents an opportunity for data exfiltration. Elsewhere, 637 AI agent related vulnerabilities were identified in the report. The adoption of AI is wider than specific use of a SaaS application or visiting ChatGPT. Reco found that AI agents are running within other tools, and inheriting user permissions. The implications of this are clear. Operational risk Analysis of the telemetry (gathered from 62 enterprise-scale businesses in financial services, healthcare, retail, and telecommunications between January 1 and August 1 2026) reveals a free-for-all attitude towards AI adoption. While businesses may have policies and procedures in place and processes to assess, evaluate, review, and finally approve new AI-based tools, these are being circumvented for low-level applications. The rules work for SaaS procurement oversight, but not for browser extensions, and the result is "operational risk." "AI agents have moved from experimentation into daily business workflows, but our findings show only 20% of AI tools in enterprise ecosystems are currently governed by IT oversight," Reco CEO Ofer Klein noted. "That leaves organizations exposed to a new class of operational risk. Agents embedded in applications can operate through existing permissions, OAuth grants and workflow access, creating toxic combinations that expose data and trigger actions beyond what any owner approved." Organizations will need to give IT teams the resources they need to manage and restrict unauthorized AI use, as the alternative means leaving the gates open to the possibility of data exfiltration. Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Share
Copy Link
Reco's State of Agent Security 2026 report exposes a critical enterprise vulnerability: 80% of AI tools run without IT oversight, with SMBs averaging 414 unsanctioned AI tools per 1,000 employees. Shadow AI contributed $670K in additional breach costs, while 637 AI agent-related vulnerabilities were identified across analyzed systems.
A startling reality is unfolding inside enterprises worldwide: AI tools are proliferating at an unprecedented rate, and most are operating completely outside IT oversight. Reco's State of Agent Security 2026 report reveals that 80% of AI tools observed in its telemetry operated without IT oversight, creating a massive blind spot for security teams
1
2
. At small and midsize businesses, the situation is even more alarming, with an average of 414 unsanctioned AI tools deployed for every 1,000 employees1
.This ungoverned AI adoption stems from how easily employees can activate AI capabilities. A marketing manager switches on an AI feature inside existing software. A developer connects an assistant to an internal knowledge base. Someone adds an AI meeting tool or browser extension and clicks "Allow" when prompted for file or calendar access. Nobody thinks they are introducing enterprise software requiring procurement meetings or security reviews. Sometimes all it takes is an OAuth consent screen
1
.
Source: The Next Web
The first scan often uncovers Shadow AI in places organizations never considered part of their AI program, according to Ofer Klein, cofounder and CEO of Reco. These include browser extensions, meeting tools, productivity suites, CRM workflows, support tools, developer environments, and app-to-app integrations
1
. What appears as a harmless assistant may have permission to read email, summarize files, access customer records, connect to ticketing systems, or interact with source-code repositories1
.Reco's analysis of 500 agent tools found that 62% can both read local data and reach the internet, representing a clear opportunity for data exfiltration
2
. These AI agents run within other tools and inherit user permissions, creating what Klein describes as "toxic combinations that expose data and trigger actions beyond what any owner approved"2
.The financial impact of this AI-related security issue is already measurable. IBM's 2025 Cost of a Data Breach report, which studied 600 breached organizations across 17 industries, found that one in five had experienced a breach involving Shadow AI. Organizations with high levels of Shadow AI recorded data breach costs averaging $670,000 more than those with little or none
1
.
Source: TechRadar
Reco's research identified 637 AI agent-related vulnerabilities across analyzed systems
2
. The telemetry, gathered from 62 enterprise-scale businesses in financial services, healthcare, retail, and telecommunications between January 1 and August 1, 2026, reveals what Klein calls a "free-for-all attitude" toward AI adoption2
.Related Stories
An employee connects an agent for a three-month project, the project ends, and six months later that employee moves to another department. The agent, however, remains active. Klein says Reco commonly finds these "orphaned agents" when entering a customer environment for the first time. An agent may have arrived through someone's OAuth grant, API key, or service account, and its access can survive organizational changes
1
.This represents a broader identity management crisis. Okta's Businesses at Work 2026 report found that 78% of organizations see controlling access and permissions for non-human identities as a major concern, but only 10% have a strategy for governing them. This includes the service accounts and other machine identities AI agents increasingly use to access company systems and data
1
.Security teams face a fundamental problem: someone needs to know why an agent exists, what it can access, and whether it still needs to run. When nobody does, an agent set up for a three-month project can quietly become a permanent fixture
1
. Klein emphasizes that "AI agents have moved from experimentation into daily business workflows," but with only 20% of AI tools in enterprise ecosystems currently governed by IT oversight, organizations remain exposed to a new class of operational risks2
.The challenge lies in balancing security with productivity. Shutting down all unsanctioned AI tools could disrupt useful work. Some tools may already prepare account updates for salespeople, summarize support tickets, or assist developers connected to code repositories
1
. Instead of treating every unknown AI tool equally, security teams must prioritize based on what each agent can actually reach. An assistant connected only to public information presents a vastly different problem from an agent accessing customer records, financial systems, or production code1
.Summarized by
Navi
30 Jun 2026•Business and Economy

12 Feb 2026•Technology

21 Apr 2026•Technology

1
Technology

2
Policy and Regulation

3
Technology
