Quick Facts

  • Reco’s State of Agent Security 2026 report found only 20% of AI tools in enterprise ecosystems operate under IT oversight.
  • 62% of analyzed MCP servers can both read local data and reach the internet, creating direct data exfiltration paths.
  • IBM’s 2026 Cost of a Data Breach report links unauthorized AI tools to 43% of breaches, with shadow AI correlating to $670,000 higher average breach costs.

Eight out of ten AI tools running inside large enterprises operate with no IT oversight. That is the central finding of Reco’s State of Agent Security 2026 report, published August 26. Security teams at most companies have no clear view of which AI tools are active, who owns them, or what data they can access.

Reco drew on anonymized telemetry from 62 large enterprises across financial services, healthcare, retail, and telecommunications between January and August 2026. The firm also analyzed 500 published Model Context Protocol servers and tracked disclosed vulnerability records.

The Scale of the Problem

Smaller companies now run 414 AI tools per 1,000 employees without IT approval. Most are browser extensions and embedded workflows that bypass standard procurement review. Traditional SaaS approval processes were not built for this category of tool.

Reco CEO Ofer Klein put it directly: “AI agents have moved from experimentation into daily business workflows, but our findings show only 20% of AI tools in enterprise ecosystems are currently governed by IT oversight.”

Lenovo Digital Workplace Solutions VP Rakshit Ghura described the gap as structural: “Usage is growing faster than organizations can control or secure it.”

Agent Tools Carry Serious Technical Risk

Reco’s analysis of 500 published agent tools found 62% can read local data and reach the internet simultaneously. Half can execute shell commands, turning a prompt-injection attack into operating system access. More than 80% can read or write local files, and roughly three-quarters can make outbound network calls.

Vulnerability disclosures are accelerating. Of the 637 agent and LLM-tooling vulnerabilities tracked in the report, 525 were disclosed in the past 18 months. That represents a sixfold increase in the average monthly disclosure rate compared to 2023 and 2024. At least 111 carried CVSS scores of 9.0 or higher.

Breaches Are Already Happening

IBM’s 2026 Cost of a Data Breach report found unauthorized tools contributed to 43% of breaches over the past year. One in five organizations has already experienced a breach tied to shadow AI, and only 37% had policies in place to manage or detect it. Organizations with high shadow AI usage faced average breach costs $670,000 higher than peers.

LayerX’s 2025 Enterprise AI and SaaS Data Security report found 77% of workers paste sensitive data into generative AI tools. Of those pastes, 82% came from personal accounts outside company visibility.

Darren Williams, founder and CEO of BlackFog, said the compliance gap most businesses have not addressed “isn’t the AI tools they’ve approved and deployed, but the ones their employees are already using without anyone’s knowledge.”

Regulatory Exposure Is Growing

The EU AI Act’s obligations for general deployers took effect August 2, 2026, covering inventory requirements, data governance, audit logging, and transparency. Controls on high-risk AI use cases take effect December 2, 2027. Fines can reach 35 million euros or 7% of global annual turnover.

IDC found 57% of European enterprises discovered at least one instance of shadow AI in the past 12 months. Fewer than 18% report full visibility into AI tools used across their SaaS environments.

Business Implications

Salesforce’s 2026 Workforce AI Survey found 67% of employees now use AI tools at work, but only 18% of organizations have formal AI security policies. Deloitte’s 2026 State of AI in the Enterprise report found employee AI access grew 50% in 2025, yet only one in five companies has a mature governance model for autonomous agents.

The ROI impact is also measurable. Only 4% of organizations have realized desirable returns on AI investment, compared to 26% that have developed innovative AI solutions, with shadow AI cited as a key factor distracting companies from security and compliance obligations.

Read more: Almost all AI tools are now running with no oversight from IT — putting companies in the firing line

This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.