Shadow AI now averages 414 unsanctioned tools per 1,000 employees
New research shows most AI agents operate without IT oversight, adding $670K to breach costs when security fails.
Shadow AI now averages 414 unsanctioned tools per 1,000 employees
Companies scanning their networks for AI tools are discovering hundreds of agents connected to email systems, customer databases, and code repositories—most operating entirely outside IT oversight.
Reco's State of Agent Security 2026 report found that 80% of AI tools in its telemetry operated without IT knowledge or approval. At small and midsize businesses, the average reached 414 unsanctioned AI tools for every 1,000 employees.
The proliferation happens quietly. A marketing manager activates an AI feature in existing software. A developer connects an assistant to an internal knowledge base. Someone adds a meeting transcription tool and clicks "Allow" when prompted for calendar access. No procurement process, no security review—just an OAuth consent screen.
Why it matters
Shadow AI isn't just an inventory problem. IBM's 2025 Cost of a Data Breach report studied 600 breached organizations and found that one in five had experienced a breach involving shadow AI. Organizations with high levels of shadow AI recorded breach costs averaging $670,000 more than those with minimal shadow AI presence. As employees gain the ability to activate AI capabilities inside existing tools or connect agents directly to company systems, traditional software governance approaches no longer capture what's actually running.
Map access before counting tools
Ofer Klein, cofounder and CEO of Reco, says the first surprise for security teams often isn't the number of AI tools employees have introduced, but how deeply some connect to business systems.
"A tool that looks like a harmless assistant may have permission to read email, summarize files, access customer records, connect to ticketing systems or interact with source-code repositories," Klein said in an interview.
This makes simple headcounts misleading. An assistant connected only to public information presents a fundamentally different risk than an agent accessing customer records, financial systems, or production code. Effective triage starts by understanding what each agent can actually reach.
The orphaned agent problem
Many discovered agents have outlived their creators. An employee connects an agent for a three-month project, the project ends, and six months later that employee moves to another department. The agent keeps running.
Klein says Reco commonly finds these "orphaned agents" when scanning customer environments. An agent may have arrived through someone's OAuth grant, API key, or service account, and its access survives long after that person's role changes.
Okta's Businesses at Work 2026 report found that 78% of organizations see controlling access for non-human identities as a major concern, but only 10% have a strategy for governing them. This includes the service accounts and machine identities AI agents increasingly use.
Triage by system criticality
Klein says companies stall after discovery for three reasons: nobody knows who owns certain agents, security can see a tool exists without understanding everything it accesses, and the available response feels binary—leave it alone or shut it down.
A more practical approach prioritizes by system sensitivity. Agents touching customer information, source code, financial workflows, production systems, or external communications go to the front of the queue. From there, teams identify an owner, examine permissions, remove unnecessary access, and establish review schedules.
Trying to catalogue every approved AI application won't reveal what's actually happening when employees can activate new capabilities inside existing software or connect agents to company systems themselves. The job isn't finding a giant off switch—it's determining which agents have the keys to critical systems.
These details were first reported by The Next Web.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
