Almost all AI tools are now running with no oversight from IT putting companies in the firing line
Date:
Tue, 08 Sep 2026 01:40:00 +0000
Description:
Organizations are employing AI tools as a fire-and-forget solution, overlooking the importance of AI oversight and leaving security teams with
the problem of seeking out avoidable vulnerabilities.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Report claims an incredible 80% of AI tools are running in organizations without IT oversight Browser agents and integration tools are escaping the attention of security and IT engineers Recos State of Agent Security 2026 report also tracked 637 vulnerabilities across agents and LLMs Unmonitored deployment of AI tools is a risk to security, and puts data at risk, a new study has claimed.
The report from Reco, which draws its information from disclosed vulnerabilities, analysis of 500 Model Context Protocol servers, and Recos
own platform telemetry, found four in five AI tools (80%) are running without oversight from IT departments. Of particular concern is the scale of AI applications in use. Smaller companies use 414 AI tools per 1,000 employees without IT approval, apparently a combination of browser extensions and workflows beyond the usual review and approval process. Latest Videos From TechRadar Watch full video here: Data risks from unmonitored AI Giving AI tools to employees might unlock productivity boosts, but their use has to be approved. Thats the key takeaway from the report , which highlights some concerning cybersecurity figures. For example, it assessed 500 agent tools
and found 62% can both read local data and reach the internet. This
represents an opportunity for data exfiltration.
Elsewhere, 637 AI agent related vulnerabilities were identified in the
report. You may like Many companies deploying AI often end up with much
bigger security issues, report warns Phishing the agent: Why AI guardrails arent enough New study claims most of us are now using unauthorized AI tools at work
The adoption of AI is wider than specific use of a SaaS application or visiting ChatGPT. Reco found that AI agents are running within other tools, and inheriting user permissions. The implications of this are clear. Operational risk Analysis of the telemetry (gathered from 62 enterprise-scale businesses in financial services, healthcare, retail, and telecommunications between January 1 and August 1 2026) reveals a free-for-all attitude towards AI adoption. While businesses may have policies and procedures in place and processes to assess, evaluate, review, and finally approve new AI-based
tools, these are being circumvented for low-level applications. Are you a
pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting
your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
The rules work for SaaS procurement oversight, but not for browser
extensions, and the result is operational risk.
AI agents have moved from experimentation into daily business workflows, but our findings show only 20% of AI tools in enterprise ecosystems are currently governed by IT oversight," Reco CEO Ofer Klein noted.
That leaves organizations exposed to a new class of operational risk. Agents embedded in applications can operate through existing permissions, OAuth grants and workflow access, creating toxic combinations that expose data and trigger actions beyond what any owner approved.
Organizations will need to give IT teams the resources they need to manage
and restrict unauthorized AI use, as the alternative means leaving the gates open to the possibility of data exfiltration. Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/almost-all-ai-tools-are-now-running-with-no-over sight-from-it-putting-companies-in-the-firing-line
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)