Almost all AI tools are now running with no oversight from IT — putting companies in the firing line
- Report claims an incredible 80% of AI tools are running in organizations without IT oversight
- Browser agents and integration tools are escaping the attention of security and IT engineers
- Reco’s State of Agent Security 2026 report also tracked 637 vulnerabilities across agents and LLMs
Unmonitored deployment of AI tools is a risk to security, and puts data at risk, a new study has claimed.
The report from Reco, which draws its information from disclosed vulnerabilities, analysis of 500 Model Context Protocol servers, and Reco’s own platform telemetry, found four in five AI tools (80%) are running without oversight from IT departments.
Of particular concern is the scale of AI applications in use. Smaller companies use 414 AI tools per 1,000 employees without IT approval, apparently a combination of browser extensions and workflows beyond the usual review and approval process.
Latest Videos FromTechRadar
Data risks from unmonitored AI
Giving AI tools to employees might unlock productivity boosts, but their use has to be approved. That’s the key takeaway from the report, which highlights some concerning cybersecurity figures. For example, it assessed 500 agent tools and found “62% can both read local data and reach the internet.” This represents an opportunity for data exfiltration.
Elsewhere, 637 AI agent related vulnerabilities were identified in the report.
The adoption of AI is wider than specific use of a SaaS application or visiting ChatGPT. Reco found that AI agents are running within other tools, and inheriting user permissions. The implications of this are clear.
Operational risk
Analysis of the telemetry (gathered from 62 enterprise-scale businesses in financial services, healthcare, retail, and telecommunications between January 1 and August 1 2026) reveals a free-for-all attitude towards AI adoption. While businesses may have policies and procedures in place and processes to assess, evaluate, review, and finally approve new AI-based tools, these are being circumvented for low-level applications.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The rules work for SaaS procurement oversight, but not for browser extensions, and the result is “operational risk.”
“AI agents have moved from experimentation into daily business workflows, but our findings show only 20% of AI tools in enterprise ecosystems are currently governed by IT oversight,” Reco CEO Ofer Klein noted.
“That leaves organizations exposed to a new class of operational risk. Agents embedded in applications can operate through existing permissions, OAuth grants and workflow access, creating toxic combinations that expose data and trigger actions beyond what any owner approved.”
Organizations will need to give IT teams the resources they need to manage and restrict unauthorized AI use, as the alternative means leaving the gates open to the possibility of data exfiltration.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Source
Report claims an incredible 80% of AI tools are running in organizations without IT oversight Browser agents and integration tools are escaping the attention of security and IT engineers Reco’s State of Agent Security 2026 report also tracked 637 vulnerabilities across agents and LLMs Unmonitored deployment of AI tools is…
Recent Posts
- First Xiaomi, then the world: why Arm might give phone gaming a huge graphics boost
- Almost all AI tools are now running with no oversight from IT — putting companies in the firing line
- The wait for The Wolf Among Us 2 has been a long one — but its Gamescom 2026 preview has me more hyped than ever
- How To Reset The Camera Settings On Your iPhone
- Cathay Pacific tests Google AI that dramatically cuts airplane contrails — tiny altitude shifts slash environmental impact by 40% in early trials
Archives
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023