A new study has revealed that 80% of AI tools used in organizations are not monitored by IT departments, raising concerns about data security and operational risks. The report, published by Reco, analyzed 500 Model Context Protocol servers, disclosed vulnerabilities, and data from Reco’s own platform. It highlights how AI tools are being widely used without going through formal approval processes, often outside the awareness of IT teams.
Smaller companies, in particular, are using an average of 414 AI tools per 1,000 employees without IT oversight. These tools are frequently accessed through browser extensions and workflows that bypass standard approval procedures. The study identified 637 vulnerabilities in AI agents and large language models (LLMs), with 62% of the 500 assessed tools able to access both local data and the internet. This capability could allow for data exfiltration, or the unauthorized transfer of data out of an organization.
AI agents are increasingly integrated into other tools, which can inherit user permissions and create new security risks. While some companies have policies in place to review and approve AI tools, these policies are often ignored for simpler applications. The study notes that AI tools have moved from being experimental to being used daily in business operations, but only 20% of these tools are currently under IT oversight.
Reco CEO Ofer Klein pointed out that AI agents are now deeply embedded in enterprise workflows, operating through existing permissions and access controls. This means they can perform actions or expose data without explicit approval from users or IT teams. The report stresses the need for IT departments to be equipped with the resources to monitor and manage AI usage, ensuring unauthorized tools do not pose risks such as data leaks or unintended actions.
Majority of AI Tools Deployed Without IT Oversight, Study Finds
AI-rewritten from original reportingHow it works
ai-securitydata-exfiltrationit-oversightai-toolsenterprise-riskllm-vulnerabilities



