Almost all AI tools are now running with no oversight from IT — putting companies in the firing line
Someone hasn’t locked the door
by https://www.techradar.com/author/christian-cawley · TechRadarNews By Christian Cawley Published 8 September 2026
Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter
- Report claims an incredible 80% of AI tools are running in organizations without IT oversight
- Browser agents and integration tools are escaping the attention of security and IT engineers
- Reco’s State of Agent Security 2026 report also tracked 637 vulnerabilities across agents and LLMs
Unmonitored deployment of AI tools is a risk to security, and puts data at risk, a new study has claimed.
The report from Reco, which draws its information from disclosed vulnerabilities, analysis of 500 Model Context Protocol servers, and Reco’s own platform telemetry, found four in five AI tools (80%) are running without oversight from IT departments.
Of particular concern is the scale of AI applications in use. Smaller companies use 414 AI tools per 1,000 employees without IT approval, apparently a combination of browser extensions and workflows beyond the usual review and approval process.
Latest Videos FromTechRadarWatch full video here:
Data risks from unmonitored AI
Giving AI tools to employees might unlock productivity boosts, but their use has to be approved. That’s the key takeaway from the report, which highlights some concerning cybersecurity figures. For example, it assessed 500 agent tools and found “62% can both read local data and reach the internet.” This represents an opportunity for data exfiltration.
Elsewhere, 637 AI agent related vulnerabilities were identified in the report.
The adoption of AI is wider than specific use of a SaaS application or visiting ChatGPT. Reco found that AI agents are running within other tools, and inheriting user permissions. The implications of this are clear.
Operational risk
Analysis of the telemetry (gathered from 62 enterprise-scale businesses in financial services, healthcare, retail, and telecommunications between January 1 and August 1 2026) reveals a free-for-all attitude towards AI adoption. While businesses may have policies and procedures in place and processes to assess, evaluate, review, and finally approve new AI-based tools, these are being circumvented for low-level applications.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors