Almost all AI tools are now running with no oversight from IT — putting companies in the firing line
Organizations are employing AI tools as a “fire-and-forget” solution, overlooking the importance of AI oversight and leaving security teams with the problem of seeking out avoidable vulnerabilities.
A staggering 80% of AI tools are now being used without IT oversight, according to a new study, leaving companies vulnerable to security risks. The study, conducted by Reco, examined 500 Model Context Protocol servers and found that 80% of AI tools are operating without the necessary approval, primarily through browser extensions and workflows that bypass the standard review process.
This lack of oversight is particularly concerning given the scale of AI applications in use, with small companies utilizing an average of 414 AI tools per 1,000 employees without IT approval. The report highlights the potential for data risks from unmonitored AI, as 62% of assessed agent tools can both read local data and access the internet, increasing the likelihood of data exfiltration.
Additionally, the study identified 637 AI-related vulnerabilities, as AI agents are being integrated into various tools and inheriting user permissions. This trend has led to a "free-for-all" approach to AI adoption, where businesses have policies in place but circumvent them for low-level applications, resulting in operational risk.
According to Reco CEO Ofer Klein, only 20% of AI tools in enterprise ecosystems are currently governed by IT oversight, leaving organizations exposed to new forms of operational risk. As AI agents can operate through existing permissions, OAuth grants, and workflow access, there is a risk of toxic combinations that expose data and trigger actions beyond what any owner approved.
To mitigate these risks, organizations must provide IT teams with the necessary resources to manage and restrict unauthorized AI use, as failing to do so could leave the gates open to data exfiltration.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.