IT Brief Canada - Technology news for CIOs & IT decision-makers
Canada
Four in five AI tools lack IT oversight, Reco finds

Four in five AI tools lack IT oversight, Reco finds

Thu, 27th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Reco has released its State of Agent Security 2026 report, which says four in five AI tools in enterprise environments operate without IT oversight.

The findings are based on anonymised telemetry from 62 large enterprises, an analysis of 500 published Model Context Protocol servers, and a review of disclosed vulnerabilities tied to agent and large language model tooling.

The report highlights a gap between the spread of AI agents in day-to-day work and the controls many companies apply to them. It found that only 20% of AI tools observed in enterprise ecosystems had IT or security approval, leaving teams without a clear record of which tools were active, who owned them, or what permissions they held.

This matters because AI agents increasingly sit inside mainstream workplace software rather than existing as separate applications. In that setting, they can inherit user permissions, OAuth grants, service accounts, and API access, allowing them to act through systems that already have standing approval.

Permission risks

Reco's analysis of 500 published Model Context Protocol servers found that 62% combined local file-read access with outbound network connectivity. That pairing creates a direct route for data exfiltration because the same tool may be able to read local data and send it outside the organisation.

The report also found that half of the sampled agent tools could execute shell commands, more than eight in ten could read or write local files, and roughly three-quarters could make outbound network calls. Those functions may be legitimate in isolation, but become more concerning when organisations do not know which tools are in use or how permissions overlap.

The report argues that risk does not always come from a single rogue tool. It can arise when several authorised or semi-visible tools combine their access in unintended ways, such as one reading files, another reaching the internet, and another triggering workflows.

"AI agents have moved from experimentation into daily business workflows, but our findings show only 20% of AI tools in enterprise ecosystems are currently governed by IT oversight," said Ofer Klein, Chief Executive Officer at Reco.

"That leaves organizations exposed to a new class of operational risk. Agents embedded in applications can operate through existing permissions, OAuth grants and workflow access, creating toxic combinations that expose data and trigger actions beyond what any owner approved," Klein said.

Vulnerability growth

The report tracked 637 vulnerabilities across agent and LLM tooling. Of those, 525 were disclosed in the past 18 months, including at least 111 ranked critical with CVSS scores of 9.0 or higher.

According to Reco, the average monthly disclosure rate rose from fewer than five during 2023 and 2024 to about 29 since January 2025. That pace can exceed the speed at which many organisations review tools, test updates, and apply patches.

The figures add to broader concern in the security market about AI software entering companies through routes that bypass formal procurement. Browser extensions, OAuth consent prompts, and employee-built workflows can all introduce software with access to business data without going through the same checks as conventional SaaS tools.

Adoption patterns

Reco said its data showed 79% of third-party applications are authorised, suggesting many organisations have relatively established SaaS governance programmes. The issue, the report says, is the separate growth of AI-specific tools, which spread more quickly and informally.

Among small and midsize companies, Reco found 414 unsanctioned AI tools per 1,000 employees. That suggests AI adoption can scale well beyond the set of large, approved assistants and copilots that security teams tend to track most closely.

The report argues that sanctioned AI products are often the easiest for IT departments to see because they sit inside approved software suites or are bought centrally. Less visible are niche automation frameworks, browser-based agents, and integration tools that may hold persistent permissions and act independently once connected.

Methodologically, Reco analysed anonymised platform telemetry from large enterprises in financial services, healthcare, retail and consumer sectors, and telecommunications. For the tool review, it selected publicly available Model Context Protocol servers from the npm registry using the keyword "mcp", then filtered out frameworks, gateways, and clients to focus on software confirmed to start a server.

The findings arrive as businesses test where AI agents can take on repetitive tasks across customer service, software development, and office workflows. The report suggests that while adoption has moved quickly, oversight has not kept pace, especially when AI functions are embedded in existing business systems rather than introduced as standalone products.