Lurking in many business environments are AI agents that pose serious security risks but, for the most part, remain out of sight of security teams, according to a report released Wednesday by a global SaaS security company.

AI agents now read inboxes, file tickets, write code, and move records between applications under standing OAuth grants, the report by Reco noted, and most arrived the way unsanctioned AI always has: one consent screen at a time, with no security review.

The 16-page report, based on Reco telemetry on AI tool use in the enterprise, an analysis of 500 Model Context Protocol (MCP) servers, and public vulnerability records, pointed out that an attacker who gets into a chatbot sees whatever employees pasted into it, while one who gets into an agent inherits everything it was permitted to reach, at machine speed, under a non-human identity an organization created but never personally meets.

While acknowledging that most SaaS applications are authorized in businesses, the report found that small and mid-size companies carry 414 unsanctioned AI tools per 1,000 employees.

Shadow AI Spreads Outside IT Oversight