A striking visual representation of human-robot interaction showcasing a warning symbol

Four in Five Enterprise AI Tools Lack IT Oversight

Unsanctioned AI agents create data exfiltration risks as security leaders urge governance that tracks automated actions without slowing workflows.

Enterprise security teams face a growing visibility gap as four in five artificial intelligence tools operate without central oversight, according to The State of Agent Security 2026 Report published by security firm Reco.

The analysis examined 500 published agent tools and revealed that 62% possess the combined ability to read local internal files and connect directly to the internet. Security experts note that this dual access path creates a direct mechanism for unintended data exfiltration across organizational boundaries.

Unlike traditional third-party applications, modern AI agents embed themselves directly within corporate ecosystems. By inheriting user permissions, OAuth grants and API access, these tools aggregate individual capabilities into unexpected risk factors. While one tool may read files and another triggers automated workflows, their combined capabilities allow autonomous agents to traverse enterprise networks in ways IT administrators never designed or intended.

Industry specialists warn that the transition from static conversational bots to active operational agents multiplies the danger. Unsanctioned chatbots introduce data privacy concerns, but autonomous agents equipped with active credentials can modify source code, alter production databases and interact directly with critical cloud infrastructure.

To mitigate these risks, governance experts recommend focusing on visibility and action-level policy controls rather than attempting to outright block AI usage. By embedding automated security policies directly into data workflows, enterprises can ensure that autonomous actions meet strict regulatory controls without forcing employees to navigate cumbersome manual approval chains.

About the Author

Jesse Jacobs is assistant editor of SecurityToday.com.

Featured

New Products

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction.

  • NAPCO product image

    StarLink Fire Max2 Dual Cell/IP Communicator

    Streamline commercial fire compliance with dual-carrier cellular connectivity, a dedicated FACP data path, and dual-layer electronic inspection verification.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities