Skip to content
Menu
Menu

Reco Finds Four In Five AI Tools Run Without IT Oversight

Most are not chatbots but software that logs into company systems and works on its own, using access an employee granted once by clicking “allow.”

 

Key Takeaways

  • Four in five of the AI tools running inside the companies Reco monitors have no IT approval and nobody watching them.
  • At small and mid-size companies, Reco found about 41 unapproved AI tools for every 100 employees.
  • Of 500 published add-ons that AI tools use, 62% can both read a computer’s files and send data to the internet.
  • Nobody reviews that combination of permissions, because no purchasing step ever sees these add-ons.

Reco, an AI security company, in its The State of Agent Security 2026 report, looked inside its customers’ systems and found that four in five of the AI tools running there have no IT approval and nobody monitoring them.

 

These tools are not chatbots, and they do not wait to be asked

The AI tools that companies do watch are the visible kind: the well-known chatbots and the assistants built into office software they already pay for. The unwatched tools are the ones that act on their own.

Those unwatched tools log into email, customer records, and code repositories and do work on their own schedule. Reco identifies three types of these tools: browser assistants that read an employee’s inbox, automation tools connected to a company’s customer database, and coding assistants with access to company code. Each runs on access an employee granted once, and that access stays live after the employee changes jobs or leaves.

 

Nobody approved them because nobody bought them

Reco says 79% of the software applications it sees were reviewed and approved. That works for software a company buys, because purchasing is where the review happens.

AI tools do not arrive that way. They arrive as a browser extension, or as one click on a permission screen that gives an application access to a mailbox or a shared drive. At small and mid-size companies, Reco found about 41 AI tools with no approval for every 100 employees.

 

The add-ons these tools use arrive with permissions already attached

AI tools reach files and other software through small add-ons that anyone can publish, and anyone can install with a single command. Reco examined 500 of them:

  • Half can run commands on the computer they are installed on.
  • 82% can read or write that computer’s files.
  • 73% can send data out to the internet.
  • 62% can do both of the last two.

Each ability looks reasonable on its own: a document tool needs to read files, an integration needs to reach the internet. Nobody asks what one add-on can do with both abilities, and both are what let data leave. That matters because when data leaves a company this way, it leaves through software the company installed on purpose, using credentials the company issued. Nothing is broken into, and no password is stolen, so the security tools most companies run do not flag the transfer.

 

The NSA says current defenses do not cover this

Reco counted 525 security holes disclosed in the software that runs AI agents and connects them to other systems. At least 111 of them are serious enough to demand immediate patching. 

In May, the National Security Agency (NSA) published guidance for companies that connect AI tools to their systems through these add-ons. It tells them to proceed with caution and says the cyber defenses most companies already run do not adequately cover the risk.

 

Methodology

The approval and oversight numbers come from Reco’s own software running inside its customers’ systems. Reco’s press release says that covers 62 large enterprises, and Reco’s report attributes the 41-per-100 figure to small and mid-size companies. The add-on numbers come from Reco’s review of 500 add-ons published to a public software library. The 525 security holes come from the US government’s public record of disclosed software flaws, the National Vulnerability Database, counting entries logged since January 2025 that name AI agents or the software built around them.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!