Reco Finds Shadow AI Running Past Governance

Reco’s State of Agent Security 2026 found that 80% of AI tools in enterprise ecosystems run without IT oversight, and SMBs average 414 unsanctioned tools per 1,000 employees. The same report counted 637 agent and LLM vulnerabilities, including 111 critical disclosures. The problem is the permission stack, not the chatbot brand. Reco says agents can act through existing OAuth grants and workflow access, and many Model Context Protocol servers can run shell commands, read or write files, or make outbound network calls, so a prompt-injection trick can turn into file access, command execution, and data exfiltration. For organizations that let assistants touch mail, files, or SaaS records, the durable exposure sits in the standing app grants and unreviewed agent infrastructure. The disclosure pace is also rising fast, which means the governance gap is getting more dangerous even before any single tool is named or patched.

Part of the PlainSec briefing for 2026-08-26

Every edition of this story: Reco Finds Shadow AI Running Past Governance

Sources