# Reco Report Exposes 80% of Enterprise AI Tools Without IT Oversight

> The State of Agent Security 2026 study draws on telemetry from 62 enterprises and analysis of 500 Model Context Protocol servers to document how most AI agents bypass governance and accelerate vulnerability growth.

*Published 2026-08-26 · Updated 2026-09-02 · By Diane Okafor*

Shadow AI agents are autonomous AI tools deployed in enterprise settings that evade standard IT oversight and governance processes.

The State of Agent Security 2026 report released by Reco on August 26, 2026, draws on platform telemetry from 62 large enterprises, an analysis of 500 Model Context Protocol servers, and records from the National Vulnerability Database. This combination of data sources provides a detailed view of how AI agents integrate into business operations while remaining outside traditional controls.

Enterprises face mounting pressure to adopt AI for efficiency gains, yet the report underscores that rapid integration often occurs without corresponding security reviews. Decision makers must weigh productivity benefits against the operational exposures created when agents inherit broad permissions from underlying applications.

## What Scale of AI Tools Operate Outside IT Control?

According to the report, four in five AI tools operate without IT oversight. This figure comes from Reco's analysis of enterprise environments where agents are embedded in applications and use existing permissions to function. Organizations that assume all deployed tools receive formal review may underestimate the volume of shadow deployments that accumulate through departmental initiatives.

The absence of oversight allows these tools to execute actions that extend beyond initial approvals, increasing the chance of unintended data access or workflow modifications. Business leaders evaluating AI strategies should first establish inventories that capture both sanctioned and unsanctioned instances to quantify their exposure accurately.

## How Do Agent Capabilities Contribute to Risks?

Of the 500 published agent tools examined, 62% can both read local data and reach the internet. This combination allows for potential data exfiltration or interaction with external systems in ways that could compromise security. Enterprises relying on these tools for routine tasks may inadvertently grant pathways for sensitive information to leave controlled environments.

Further details show that half of these tools can execute shell commands, more than eight in ten can read or write local files, and roughly three-quarters can make outbound network calls. Such capabilities, when combined without monitoring, create conditions where minor configuration errors can lead to broader system impacts.

Agent Tool Capabilities from Reco AnalysisCapabilityPercentage of ToolsPotential RiskRead local data and internet access62%Data exfiltrationExecute shell commands50%System controlRead or write local filesOver 80%File manipulationOutbound network callsRoughly 75%External communication

## What Trends Emerge in Vulnerability Disclosures?

The report notes that 525 of 637 tracked agent and LLM-tooling vulnerabilities were disclosed in the past 18 months. The average monthly disclosure rate has risen more than sixfold to approximately 29 since January 2025, compared to the 2023-2024 period. This acceleration signals that the attack surface is expanding faster than defensive measures can adapt in many organizations.

## How Do Company Sizes Factor Into the Problem?

While 79% of third-party applications are authorized, small and midsize companies average 414 unsanctioned AI tools per 1,000 employees. Larger enterprises may maintain tighter procurement processes, but the pattern in smaller firms indicates that resource constraints often delay the implementation of comprehensive monitoring programs.

This disparity suggests that AI adoption strategies must account for organizational scale when allocating security resources. Midsize firms in particular may benefit from prioritizing automated discovery tools that surface unsanctioned agents before they accumulate in significant numbers.

## What Do Industry Experts Say About These Findings?

> AI agents have moved from experimentation into daily business workflows, but our findings show only 20% of AI tools in enterprise ecosystems are currently governed by IT oversight. That leaves organizations exposed to a new class of operational risk. Agents embedded in applications can operate through existing permissions, OAuth grants and workflow access, creating toxic combinations that expose data and trigger actions beyond what any owner approved.Ofer Klein, CEO of Reco

## What Framework Does the Report Suggest for Mitigation?

The report provides a five-step framework for closing the oversight gap, with the full document available via download at reco.ai. Organizations seeking to reduce exposure can begin by mapping all active AI tools against current access policies to identify gaps.

- 80% of AI tools lack oversight.
- 62% have combined file and network access.
- Vulnerability rate increased sixfold.
- Half can execute shell commands.
- Over 80% can read or write files.

## What Are the Market Implications for AI Adoption?

The findings indicate that enterprises accelerating AI deployment without parallel governance investments face rising operational risks that could slow future adoption rates. Procurement teams evaluating new agent-based solutions should require vendors to demonstrate how tools will integrate with existing oversight mechanisms before purchase decisions are finalized.

Stakeholders across IT, security, and business units must align on shared visibility standards to prevent the proliferation of tools that bypass controls. Without such alignment, the cumulative effect of unsanctioned agents may offset productivity gains through increased incident response costs and compliance challenges.

## How Can Enterprises Respond to the Vulnerability Surge?

The sixfold increase in monthly vulnerability disclosures requires proactive monitoring that extends beyond traditional endpoint protection. Security teams should incorporate continuous scanning of Model Context Protocol servers and related tooling into routine assessments to detect emerging issues before exploitation occurs.

Decision makers evaluating long-term AI strategies will need to balance the speed of deployment against the documented growth in exposures. Establishing clear escalation paths for unsanctioned tool discovery can help contain risks while still enabling innovation within approved boundaries.

## Sources

1. [80% of AI tools operate without IT oversight and the Ofer Klein quotation on governance gaps.](https://markets.businessinsider.com/news/stocks/reco-finds-four-in-five-ai-tools-operate-without-it-oversight-in-state-of-agent-security-2026-report-1036493914)
2. [Vulnerability disclosures accelerated more than sixfold with 525 of 637 in past 18 months.](https://www.infosecurity-magazine.com/news/four-in-five-ai-tools-no-it/)
3. [The report measures the gap using platform telemetry from 62 enterprises, analysis of 500 published agent tools, and public vulnerability records from the National Vulnerability Database.](https://www.reco.ai/state-of-agent-security-2026-form)

---
Source: https://aiintelreport.com/enterprise-ai/enterprise-ai
Index: https://aiintelreport.com/llms.txt · Full text: https://aiintelreport.com/llms-full.txt
