Four in Five AI Tools Operate Without IT Oversight 

The State of Agent Security 2026 Report issued today by Reco finds that four in five AI tools operate without it oversight, leaving security teams without a clear view of which ones are active, who owns them or what they can access. The analysis of 500 published agent tools based on Reco telemetry found that 62% can both read local data and reach the internet, creating a direct path for data exfiltration. 

AI agents aren’t just another third-party applications, they’re increasingly embedded inside the ecosystem of tools employees use everyday, where they can inherit user permissions, OAuth grants, service accounts and API access. The risk comes from intended combinations: one tool can read files, another can reach the internet, another can trigger a workflow, and together they grant agents the ability to move through the enterprise in ways no single application owner intended.

Liquibase VP Ryan McCurdy Had This To Say:

  “Most employees aren’t trying to bypass security, they’re just trying to get their work done. If the approved AI tool is harder to use, less capable, or doesn’t fit how people actually work, they’ll find another way, and risks grow as AI moves from accessing information to taking action. An unsanctioned chatbot creates one level of risk, but an AI agent with credentials and access to code, infrastructure, or production databases creates another entirely. And at that point, the organization may not even know the agent exists, much less what it can access or change.

  “With four in five AI tools running with no IT oversight, the biggest problem is losing visibility and control over what AI can actually do. An agent can make a bad decision, misunderstand an instruction, or be manipulated. That shouldn’t automatically become a production problem. Enterprises need to know what an agent can access, what it can change, and what policies have to be met before it can act. The answer isn’t to stop people from using AI. It’s to make the governed path the easiest path.

  “The broader challenge in agentic AI security is that organizations are moving beyond governing what AI can generate, and need to govern what AI can actually do. As agents get access to more tools, credentials, and production systems, security can’t stop at the model. Governance has to follow the action all the way to the system being changed. And it has to operate at the speed of AI. Adding more tickets and manual approvals every time an agent wants to do something defeats the reason enterprises are adopting agents in the first place.

  “Shadow AI becomes even more serious whenever agents move into software delivery, data workflows, and production systems. An agent that writes code or generates a database change is not just producing content. It is proposing change to the business. That change needs governance, traceability, and proof of control.

    “To manage Shadow AI risks, organizations should start with policy and visibility. IT teams need to know which AI tools are being used, what data they can access, and what actions they can take. Then make the governed path the easiest path. Give employees a way to use AI without adding more tickets, manual reviews, and bottlenecks. And when AI reaches critical systems, put governance around the change itself so policy doesn’t depend on which AI tool created it.”

“The fix isn’t to slow AI down, it’s to design the work before it’s automated.”

This might sound familiar. AI that runs itself is dangerous. It needs guardrails and safety before you turn it loose. Otherwise bad things are going to happen.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading