Shadow AI is already inside your company. Here’s how to get control of it
September 7, 2026 – 2:22 pm
Abstract: Close up of Mainboard Electronic computer background. (artificial intelligence, ai)
In a nutshell: Reco’s State of Agent Security 2026 report reveals that 80% of AI tools operate without IT oversight, with SMBs averaging 414 unsanctioned AI tools per 1,000 employees. IBM research indicates that shadow AI adds $670K to breach costs. This article offers guidance on triaging the situation: map access permissions, identify ownership, watch for orphaned agents, and prioritize agents handling customer data, code, and production systems.*
Companies are discovering AI agents integrated into software without IT oversight. But finding them is just the beginning.
For a decade, IT teams could track the full list of software within an organization. Today, AI makes this challenging. A marketing manager might activate an AI feature in existing software; a developer can connect an assistant to an internal knowledge base; or someone could install an AI meeting tool with a simple "Allow" click.
"The first scan often reveals AI hidden in places the organization didn’t consider part of its AI program," says Ofer Klein, co-founder and CEO of Reco, a company specializing in enterprise agent security. This includes browser extensions, meeting tools, productivity suites, CRM workflows, support tools, developer environments, and app-to-app integrations.
Reco’s State of Agent Security 2026 report highlights the extent of the issue:
- Four in five AI tools observed lacked IT oversight.
- SMBs averaged 414 unsanctioned AI tools per 1,000 employees.
While discovering these tools is crucial, it also raises a new challenge: managing 400 previously unknown AI tools.
The first step should be to assess each agent’s actual access:
Instead of immediately shutting down every tool, consider its functionality within the business. Some might perform essential tasks; others might be redundant or risky.
Klein notes that a seemingly harmless assistant could have permissions to:
- Read emails
- Summarize files
- Access customer records
- Interact with ticketing systems
- Connect to source code repositories
IBM’s 2025 Cost of a Data Breach report, which analyzed 600 breaches across 17 industries, found that one in five involved shadow AI. Organizations with significant shadow AI faced average breach costs $670,000 higher than those with minimal or none.