TL;DRReco’s State of Agent Security 2026 report found that 80% of AI tools in its telemetry operated without IT oversight, with SMBs averaging 414 unsanctioned AI tools per 1,000 employees. IBM found shadow AI added $670K to breach costs. The article explains how companies should triage: map what each agent can reach, find who still owns it, watch for orphaned agents that outlive their creators, and prioritize agents touching customer data, code, and production systems.
Companies are discovering AI agents connected to email, customer data, and code without IT oversight. Finding them is only the beginning.
For most of the past decade, the list of software a company ran was, at least in theory, one that somebody in IT could find. Today, however, AI is making that increasingly difficult.
A marketing manager can switch on an AI feature inside software the company already pays for. A developer can connect an assistant to an internal knowledge base. Someone else can add an AI meeting tool or browser extension and click “Allow” when it asks for access to their files or calendar.
Nobody necessarily thinks they are introducing a new piece of enterprise software. There is no procurement meeting or lengthy security review. Sometimes all it takes is an OAuth consent screen. Then the security team goes looking.







