80% of Enterprise AI Tools Operate Outside IT Oversight, New Research Finds

80% of Enterprise AI Tools Operate Outside IT Oversight, New Security Report Finds
A new industry report reveals that most AI tools deployed inside enterprise environments are running without any IT governance — creating what researchers call "toxic permission combinations" that can expose sensitive data and trigger unauthorized actions.
Reco, an AI security platform, published The State of Agent Security 2026, drawing on its own platform telemetry, an analysis of 500 published Model Context Protocol (MCP) servers, and disclosed vulnerability records. The findings paint a clear picture of a fast-moving adoption wave outpacing security infrastructure.
Key Takeaways
- 80% of AI tools in enterprise ecosystems operate without IT oversight. The managed risk is visible — approved chatbots and copilots inside licensed software suites — but the larger exposure sits in automation frameworks, browser agents, and integration tools operating outside any review process.
- 62% of AI tools can read local data and reach the internet simultaneously, creating a direct path for data exfiltration. Among 500 agent tools analyzed, half can execute shell commands, more than 80% can read or write local files, and roughly 75% can make outbound network calls.
- AI security vulnerabilities are accelerating. 525 of 637 tracked agent and LLM-tooling vulnerabilities were disclosed in the past 18 months — more than a sixfold increase in the average monthly disclosure rate compared to 2023–2024.
- Unsanctioned AI adoption is highest at smaller organizations. Small and mid-sized companies carry an estimated 414 unsanctioned AI tools per 1,000 employees, often spreading through browser extensions.
"AI agents have moved from experimentation into daily business workflows, but our findings show only 20% of AI tools in enterprise ecosystems are currently governed by IT oversight," said Ofer Klein, CEO of Reco. "That leaves organisations exposed to a new class of operational risk."
For teams scaling AI systems inside their organizations, this report is a direct signal that governance infrastructure needs to keep pace with adoption — not trail it.
Read the full article on DIGIT.FYI
Stay in Rhythm
Subscribe for insights that resonate • from strategic leadership to AI-fueled growth. The kind of content that makes your work thrum.
More from Thrum
Additional pieces exploring adjacent ideas
