Report Reveals 80% of AI Tools Lack IT Oversight, Heightening Security Risks
September 8, 2026
A new Reco report finds that 80% of AI tools used in organizations operate without IT oversight, creating significant security and data risk.
Among 500 analyzed agent tools, 62% can both read local data and access the internet, opening potential data exfiltration pathways.
Telemetry from 62 large organizations across finance, healthcare, retail, and telecom in early 2026 shows a permissive AI adoption pattern, with policies frequently bypassed for low‑level tools.
The report notes that AI agents are embedded within other tools and inherit user permissions, amplifying risk beyond standalone apps.
While enabling employee use of AI can boost productivity, it must be governed by approval processes to mitigate data and security risks.
Reco identified 637 vulnerabilities related to AI agents, underscoring substantial security exposure across AI tooling and large language models.
Smaller companies are deploying AI tools at a rate of 414 tools per 1,000 employees without IT approval, often via browser extensions and unreviewed workflows.
Summary based on 1 source
