AI/ML

Shadow AI surges as 80% of employee AI tools evade IT oversight

Four out of five AI tools used by employees run with no oversight from the IT department, as AI vulnerability volumes accelerate and Model Context Protocol (MCP) tools pair capability and access to compound risk, according to The State of Agent Security 2026 report published by Reco on Wednesday.

The report draws from Reco’s platform telemetry, an analysis of 500 MCP servers available on npm and a review of AI tool vulnerabilities from the National Vulnerability Database (NVD). While 79% of all software-as-a-service (SaaS) applications at organizations were authorized, 80% of AI tools — including browser extensions and MCP servers — were ungoverned, suggesting “shadow AI” may be outpacing general “shadow IT” at many organizations.

Additionally, small and mid-size companies were found to have an average of about 414 unsanctioned AI tools running per 1,000 employees, showing high shadow AI adoption at organizations with fewer resources to vet and monitor such tools.

Shadow AI has been a long-running concern for organizations, with a report by Cyberhaven in 2024 finding that employees were increasingly sending sensitive data to chatbots and that most were using large language models (LLMs) such as ChatGPT and Gemini on personal accounts.

However, the risk has now expanded beyond data copied and pasted into chatbot conversations to the use of MCP servers and AI agents with the ability to read and write files, connect to the internet and even execute shell commands, with many tools combining all three capabilities.

Reco’s analysis of 500 MCP servers found that 50% of these tools enable agents to execute shell commands, 82% enable local file reads and writes, and 73% support outbound network calls. While each of these capabilities have a limited risk in isolation, the report emphasized that “toxic combinations” can enable file exfiltration and further system compromise through prompt injection attacks.

In total, 40% of MCP servers allowed for a “full trifecta” of capabilities — shell command execution, local system access and network egress — while 62% combined file and network access, creating a potential path for data exfiltration.

Additionally, just over a quarter of MCP servers exposed a network endpoint and half of these endpoints required no authentication out-of-the-box, representing “a remotely reachable tool with host-level reach and no lock on the door” for about 1 in 8 of these tools, Reco stated.

In addition to threats such as indirect prompt injection affecting ungoverned AI tools, organizations also need to worry about a growing volume of security vulnerabilities affecting AI, with Reco identifying 637 such vulnerabilities in the NVD since 2023 — 525 of which were disclosed in the last 18 months. Of those 525, 111 had a critical CVSS score of 9 or more, averaging one critical AI vulnerability every few days, according to Reco.

In order to get a handle on unseen AI risks within organizations, Reco recommended first working to discover these tools and every identity and integration attached to them, prioritizing those with OAuth grants showing 60 or more days of activity.

Next, organizations should audit and map the capabilities, permissions and access scope of each tool, revoke excessive and unused scopes and vet tools and skills acquired from online marketplaces, with Reco highlighting that 12% of skills found in the OpenClaw marketplace ClawHub were previously found to be malicious.

Reco also recommended having a kill switch for each agentic tool discovered so access can be rapidly revoked during an incident. This loop of “discover, map, detect, revoke,” can give organizations the necessary visibility to monitor tools and address vulnerabilities while enabling the proper governance to tailor access based on each tool’s risk.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds