Companies are discovering AI agents connected to email, customer data, and code without IT oversight. Finding them is only the beginning. For most of the past decade, the list of software a company ran was, at least in theory, one that somebody in IT could find. Today, however, AI is making that increasingly difficult.

A marketing manager can switch on an AI feature inside software the company already pays for. A developer can connect an assistant to an internal knowledge base. Someone else can add an AI meeting tool or browser extension and click “Allow” when it asks for access to their files or calendar.

Reco’s latest The State of Agent Security 2026 report gives some sense of the scale. Four in five AI tools observed in its telemetry operated without IT oversight. At small and midsize companies, it found an average of 414 unsanctioned AI tools for every 1,000 employees.

Ofer Klein, cofounder and CEO of Reco, says the first surprise for security teams is often not the number of AI tools employees have introduced, but how deeply some are connected to the business. “A tool that looks like a harmless assistant may have permission to read email, summarize files, access customer records, connect to ticketing systems or interact with source-code repositories,” he said.

IBM’s 2025 Cost of a Data Breach report found that one in five had experienced a breach involving shadow AI. Organizations with high levels of shadow AI also recorded breach costs averaging $670,000 more than those with little or none.

The Munich factory delay

So instead of treating every unknown AI tool equally, the first priority becomes understanding its reach. An assistant connected only to public information presents a very different problem from an agent that can access customer records, financial systems or production code.

Then find out who still owns it. Here is where things get particularly messy. An employee connects an agent for a three-month project, the project ends and six months later, the employee moves to another department. The loophole, however, is that the agent is still there.

Klein says Reco commonly finds these “orphaned agents” when entering a customer environment for the first time. An agent may have arrived through someone’s OAuth grant, API key or service account, and its access can survive changes elsewhere in the organization.

This leaves security teams with a fairly basic problem. Someone needs to know why an agent is there, what it can access and whether it still needs to be running.

A more practical triage starts with the systems a company would least like to lose control of. Agents touching customer information, source code, financial workflows, production systems or external communications go to the front of the queue.

This article was written with the assistance of AI.
News Factory APP - agentic news to boost your SEO & AEO.