The 80% Problem: Shadow AI at Scale
Reco’s telemetry found that four in five AI tools in enterprise ecosystems run without IT or security approval. The sanctioned 20%—the visible chatbots, approved copilots, and vetted integrations—get the attention. The other 80% operate in the background.
This isn’t just about rogue employees downloading sketchy apps. It includes automation frameworks, browser-based agents, and integration tools that employees adopt through OAuth consent screens, browser extensions, and self-service workflows. None of these go through standard procurement. Many hold standing permissions and can act independently.
Small and midsize companies carry the heaviest load: 414 unsanctioned AI tools per 1,000 employees, according to the report. Even in organizations with mature SaaS review programs—where 79% of third-party apps are authorized—AI tools are slipping through a different door.
Why AI Agents Are a Different Kind of Risk
A forgotten SaaS subscription is a cost problem. An ungoverned AI agent with broad permissions is an operational security problem.
Agents don’t just sit there. They inherit user permissions, OAuth grants, service accounts, and API access. They act on behalf of users, often continuously, often across multiple systems. The risk isn’t any single tool doing something obviously wrong—it’s the combination of capabilities that no single application owner ever approved.
Reco’s CEO Ofer Klein put it directly: agents embedded in applications can operate through existing permissions and workflow access, creating what the report calls toxic combinations
that expose data and trigger actions beyond what any owner intended.
MCP Servers: Powerful by Default
Model Context Protocol servers are the connective tissue of modern AI agents—they link agents to data sources, APIs, and actions. Reco analyzed 500 publicly available MCP servers and found that the default capability set is significant.
Here’s what the analysis found:
- 50% can execute shell commands on the host machine
- 80%+ can read or write local files
- ~75% can make outbound network calls
- 62% combine local file-read access with outbound network connectivity in a single package
That last figure is the one that should concern security teams most. A tool that can read local files and reach the internet in one package creates a direct exfiltration path. It doesn’t require a sophisticated attacker—just a misconfigured agent with the wrong permissions.
Vulnerability Disclosures Are Accelerating Fast
The agent and LLM tooling ecosystem produced 637 tracked vulnerabilities. Of those, 525 were disclosed in just the past 18 months—including at least 111 rated critical, with CVSS scores of 9.0 or higher.
The pace shift is stark. The average monthly disclosure rate went from fewer than 5 per month during 2023 and 2024 to approximately 29 per month since January 2025. That’s a more than sixfold increase.
Normal patch and review cycles aren’t built for that velocity. Security teams that treat agent tooling like standard SaaS—quarterly reviews, annual audits—are already behind.
What This Means for Security Teams
The report’s findings point to a few concrete pressure points worth addressing now.
Visibility comes before governance
You can’t govern what you can’t see. The first step isn’t policy—it’s discovery. Understanding which AI tools are active, who owns them, and what permissions they hold is the baseline that most organizations are still missing.
Visibility comes before governance.
Default capabilities need explicit review
An MCP server that can run shell commands isn’t inherently malicious—but it shouldn’t be deployed without explicit review of what it can access and under what conditions. The combination of powerful defaults and weak oversight is where real exposure lives.
Patch velocity is now a security metric
With critical LLM and agent tooling vulnerabilities being disclosed at roughly 29 per month, the speed at which your team can identify, prioritize, and patch agent-related vulnerabilities is now a meaningful security metric—not just an operational one.
The Bottom Line
The State of Agent Security 2026 report makes one thing clear: the governance gap in enterprise AI isn’t a future problem. It’s a present one, already measured in hundreds of unsanctioned tools, millions of inherited permissions, and a vulnerability disclosure rate that’s accelerating faster than most security programs are designed to handle.
The organizations that get ahead of this won’t do it by slowing down AI adoption. They’ll do it by building visibility and governance into the adoption process itself—before the toxic combinations become incidents.
Comments (0) No comments yet
Want to join this discussion? Login or Register.
No comments yet. Be the first to share your thoughts!