AI News Feed
Market watch
Products & Applications

80% of AI tools run without IT oversight, Reco report finds

A Reco report covered by TechRadar claims 80% of AI tools in enterprises run without IT oversight, leaving companies exposed to data exfiltration and other security risks.

The report, Reco's State of Agent Security 2026, drew on disclosed vulnerabilities, analysis of 500 Model Context Protocol servers, and Reco's own platform telemetry. It found that smaller companies use 414 AI tools per 1,000 employees without IT approval, many of them browser extensions and automated workflows that circumvent standard review and approval procedures.

The study highlighted serious cybersecurity gaps. Reco assessed 500 agent tools and found that 62% can both read local data and reach the internet, creating an opportunity for data exfiltration. It also identified 637 vulnerabilities related to AI agents. The company said AI agents are now embedded within other tools and inherit user permissions, allowing them to operate beyond what any owner approved.

The telemetry behind the report was gathered from 62 enterprise-scale businesses in financial services, healthcare, retail, and telecommunications between January 1 and August 1, 2026. The analysis reveals that existing policies and processes for evaluating and approving AI tools are being circumvented for low-level applications, resulting in what Reco described as operational risk.

Reco CEO Ofer Klein said that AI agents have moved from experimentation into daily business workflows, but only 20% of AI tools in enterprise ecosystems are currently governed by IT oversight. He warned that agents embedded in applications can operate through existing permissions, OAuth grants, and workflow access, creating toxic combinations that expose data and trigger actions beyond what was approved. TechRadar reported that organizations will need to give IT teams the resources to manage and restrict unauthorized AI use, as the alternative leaves the door open to potential data exfiltration.