AI Agents Operating in the Shadows Create New Risks for Enterprises
A new report from security firm Reco warns that automated software agents, now reading inboxes, filing tickets, writing code and moving data between business applications, are quietly slipping past the security teams meant to be watching them.
Most of these tools entered company networks the way unsanctioned software always has: one consent screen at a time, without any formal security review. The report, based on telemetry from enterprise environments, an analysis of 500 Model Context Protocol servers and public vulnerability records, found that small and mid-size companies now carry an average of 414 unapproved automation tools for every 1,000 employees.
Reco CEO Ofer Klein said employees typically adopt these tools because they solve an immediate problem, like summarizing an inbox or linking a workflow to a customer database, without realizing they’re introducing risk into the company’s systems. He noted that smaller companies face outsized exposure, since these tools can reach the same payroll, customer and source-code systems found at much larger firms, but with far fewer people watching.
The danger goes beyond a typical unauthorized app. Dave Hayes of FusionAuth explained that unlike a single-purpose tool that simply breaks if it can’t complete a task, these agents connect across multiple systems and keep pursuing their goal regardless of the rules a human might expect them to follow.
According to Reco, four out of five of these tools operate with no oversight from IT at all, meaning there’s no record of what data they can access, no way to revoke that access once a project ends, and no trail to follow if something goes wrong. Jacob Krell of Suzu Labs pointed out that an employee can set one up inside platforms like Salesforce or Microsoft 365 without triggering any of the usual procurement steps, and the resulting access can quietly persist long after that employee has left the company.
Perhaps the most alarming finding involves infrastructure access directly: researchers found that half of the 500 published integration servers they examined could run shell commands on the host machine, effectively enabling remote code execution. Jeff Collins of WanAware warned that a manipulated document summarized by an AI tool could trick it into executing malicious commands, instantly giving an attacker a foothold to move through the network, install ransomware or steal data.
Arti Raman of Portal26 said this should serve as a wake-up call for anyone treating these integrations as a lightweight convenience rather than one of the highest-value targets in the enterprise, particularly since most organizations still lack the visibility to treat it that way.
The report also logged 525 vulnerabilities disclosed in agent and language-model tooling over the past 18 months, including at least 111 rated critical. Researchers found that 62 percent of the tools examined can both read local data and transmit it over the internet within a single package, a combination Mind co-founder Itai Schwartz said collapses the gap between access and loss, since a tool doesn’t need to be hacked, just nudged by the wrong prompt, to expose sensitive files nobody ever properly classified.
The consensus among the experts cited in the report is that security teams need to shift their focus from controlling what these tools produce to controlling what they’re allowed to do, following their actions all the way to the systems they touch, and doing so at a pace that matches how quickly the tools themselves operate.
Also Read:
The Story of Geoffrey Hinton, the Godfather of Deep Learning
How Entrepreneurs Build Successful Businesses From the Ground Up
