Report: Organisation AI Tools now Run with Little to No Supervision

Reco is a cybersecurity company focused on securing the use of SaaS applications and AI inside organisations. It has increasingly positioned itself around AI-agent security and governance, helping IT and security teams answer questions such as:

  • What AI tools and agents are employees using?
  • Which ones have been approved by IT?
  • What data can they access?
  • What permissions do they have?
  • Who created or owns them?
  • Are they connecting to other applications?
  • Are they behaving in a way that creates a security risk?

Reco describes this as “Agentic Ecosystem Security”, securing everything around an AI agent, rather than just the AI model itself. Its platform maps agents, identities, permissions and connections, and provides threat detection and governance controls.

2026 State of Agent Security Report

A new report from Reco warns that most AI tools inside organisations are now operating with little to no oversight from IT teams, exposing companies to significant operational and security risks.

The analysis found that 4 in 5 AI tools (80%) are running without oversight from IT departments.

Smaller companies are particularly exposed, as the researchs as much as 414 AI tools are being used per 1,000 employees without IT approval, often a combination of browser extensions and workflows that fall outside the usual review and approval process. 414 AI tools sounds incredulous, but AI tools can include AI browser extensions, AI assistants and copilots, AI-powered SaaS features, automation tools, AI agents, MCP servers that connect AI to other systems, employee-created AI workflows, and tools connected to email, files, CRM systems and other such business applications.

Lack of Monitoring Increasing

The amount of unmonitored agent activity is also growing. Through the assessment of 500 AI agent tools, it was found that 62% can both read local data and read the internet, creating clear pathways for data exfiltration when used without approval.

The report also identified 637 AI-agent related vulnerabilities, highlighting how quickly risk is escalating as agents become embedded across daily operations.

This increase in adoption is driving a rise in shadow AI, with many teams deploying tools independently and outside established governance frameworks. This is only creating blind spots for IT leaders who are struggling to maintain secure data practices as adoption accelerates.

Industry Reaction

Richard Bovey, Chief for Data at AND Digital commented:

“AI investment is accelerating fast, especially with the rise of agentic AI platforms. However, without strong data governance, business leaders are effectively flying blind risk losing oversight of critical value streams. Currently, 58 per cent of organizations describe their data as ‘chaos’, which is more concerning as AI becomes increasingly autonomous.” He continued:

“The organizations leading in AI are the ones investing in high-quality data foundations. Without governance and reliable data platforms, AI workloads become brittle, costly, and difficult to audit. As agentic AI takes on more independent tasks, poor data becomes a systematic risk, making strong data governance more essential than ever to ensure AI operates reliably, safely and at scale.”

Stuart Harvey, CEO of Datactics comments:

“Advanced models have been seen to go rogue and producing their own attacks, and without oversight of models, this will become the new normal. It’s not enough to have human oversight, however as if the human doesn’t have the knowledge to understand an AI model or the data that feeds it, they’re not in the loop, they’re just there, and human intervention is just a comfort and not something to be relied on.”

He continues:

“The danger in this is false confidence, and businesses have an obligation to have an expert in the middle of an AI function who can genuinely see what good looks like, otherwise, they have no real authority to override the AI and no expertise to understand what they’re looking at.”

The report warns that organisations must urgently equip IT teams with the resources and authority to manage and restrict unauthorised AI used. Without stronger governance, businesses risks leaving the door open to unsafe agent behaviour and data exposure.

author avatar
Trish Stevens Head of Content
Trish is the Head of Content for In the Channel Media Group. [email protected]
Share by Email
Facebook
Twitter
Whatsapp
LinkedIn

Related Articles

Featured

Read our latest magazine