“AI agents have moved from experimentation into daily business workflows, but our findings show only 20% of AI tools in enterprise ecosystems are currently governed by IT oversight,” said Ofer Klein, CEO of Reco.
Reco’s dataset and headline finding: four in five tools run without IT oversight
Reco, an AI security vendor, compiled The State of Agent Security 2026 from three inputs: anonymized platform telemetry from large enterprises, publicly available Model Context Protocol (MCP) servers, and vulnerability disclosures listed in the National Vulnerability Database. From that combined dataset the firm reports a stark imbalance: 80% of AI tools in enterprise environments operate with no IT oversight. In smaller organizations, Reco estimates the problem is even more diffuse — about 414 unsanctioned tools per 1,000 employees in SMBs.
MCP servers: direct shell access, file I/O and outbound network calls
Reco examined roughly 500 MCP servers — the connectors that allow agents to reach data and take actions — and found capabilities that raise immediate operational concerns. “Exactly half can execute shell commands directly,” the report observed, turning a successful prompt-injection into potential operating-system access. More than eight in ten MCP servers can read or write local files, and roughly three-quarters can make outbound network calls. Reco flagged that “these are the tools agents are built to load, by the thousands, often through a marketplace with no review step.”
The report also notes that many MCPs are exposed in ways that increase attack surface: just over a quarter expose a network endpoint rather than running locally, and half of those exposed endpoints “ship no authentication at all,” a description Reco summarized as “a remotely reachable tool with host-level reach and no lock on the door.”

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildCompound risk: 62% of agents bundle command, file and network capabilities
Reco found nearly two-thirds — 62% — of agents combine command execution, file access, and network egress in a single package. The report frames that configuration as an end-to-end toolkit capable of “find[ing] data, act[ing] on it, and move[ing] it off the machine.” In Reco’s view, the combination of functionality plus weak or absent oversight creates what Ofer Klein described as “a new class of operational risk,” where agents can inherit existing permissions, OAuth grants, and workflow access and thus trigger actions “beyond what any owner approved.”
Vulnerability disclosures are accelerating and outpacing patching
Reco tracked 637 vulnerabilities across agents and large-language-model tools. Of those, 525 were disclosed in the past 18 months; at least 111 were rated critical with CVSS scores of 9.0 or higher. The pace of disclosure has increased sharply: the report says the average monthly disclosure rate rose from less than five during 2023 and 2024 to around 29 per month since January 2025. Reco warned that vulnerabilities are being published faster than patching programs can absorb.
What this means for technologists, procurement leaders, and SMB decision-makers
- Technologists and security teams will be watching MCP exposure and combined-capability agents closely: Reco’s counts of shell execution, file I/O and network egress point to specific connector behaviors to inventory and harden.
- Procurement and platform teams should note the report’s marketplace observation — thousands of tools loaded with little or no review — and re-evaluate approval and integration controls for third-party MCPs and agent extensions.
- SMB leaders face scale and visibility problems: Reco’s estimate of roughly 414 unsanctioned tools per 1,000 employees signals a governance gap that can multiply operational and data-exfiltration risk unless addressed.
Reco’s report lays out a simple, uncomfortable proposition: agents that act and move data are proliferating faster than organizations are governing them, and vulnerabilities are being disclosed at a pace patching regimes may struggle to match. The practical test now is whether oversight, authentication on exposed endpoints, and inventory discipline can be applied quickly enough to prevent the theoretical risks the report documents from becoming practical losses.
https://www.infosecurity-magazine.com/news/four-in-five-ai-tools-no-it/




