Four out of five artificial intelligence (AI) tools operate without IT oversight. At small and medium-sized companies (SMEs), unsanctioned AI tools run at 414 per 1,000 employees — close to one for every two or three people on staff. According to a new report from AI agent security platform Reco, The State of Agent Security 2026, this shadow AI epidemic has created a vast and very vulnerable attack surface for hackers and cybercriminals.

What is unsanctioned AI — and why does it matter?

Unsanctioned AI, sometimes called shadow AI, refers to tools adopted by employees without formal approval or monitoring from IT or security teams. Unlike traditional shadow IT — rogue apps or personal cloud storage — AI tools are different in kind, not just degree. They act autonomously, hold standing permissions, and operate on their own schedules long after the employee who installed them has moved on.

"The long tail is where [AI] agents live: automation frameworks, browser agents, and integration tools that hold standing permissions rather than waiting for prompts. Picture what hides there: a browser agent that summarizes the inbox, a workflow tool wired into the CRM, a coding assistant with repository access. Each is invisible to a program that counts sanctioned applications, and each acts on its own schedule, with its own credentials, long after the employee has moved teams or left," says Reco.

"No lock on the door"

Reco's findings expose just how exposed most AI agents are by design. Exactly half of AI agents can execute shell commands directly — turning a prompt-injection trick into operating system access. More than eight in ten can read or write local files, and roughly three-quarters can make outbound network calls. These capabilities are the tools agents are built to load, by the thousands, often through a marketplace with no review step.

The exposure doesn't stop there. Just over a quarter of agents expose a network endpoint rather than running locally — and half of those ship with no authentication at all. Reco identifies this as "a remotely reachable tool with host-level reach and no lock on the door."

A complete attack toolkit in a single package

Two in five of the AI tools examined combine command execution, file access, and network egress in a single package. This effectively creates a complete toolkit to find data, act on it, and move it off the machine — all without any malware landing or any password being stolen.

A prompt-injection payload can exploit these three privileges to execute a complete attack chain. The agent reads a poisoned document — such as a weaponized spreadsheet — runs a command it was never meant to run, and ships the result outbound, all under credentials inadvertently issued by the target organization itself.

Why SMEs are especially at risk

The concentration of unsanctioned AI at SMEs — 414 tools per 1,000 employees — is particularly alarming. Smaller organizations typically have fewer dedicated security personnel, less mature vendor-vetting processes, and greater reliance on lightweight, off-the-shelf automation tools. Each unsanctioned agent represents a potential pivot point for attackers who have identified that human employees are no longer the only targets worth compromising.

As Reco's research makes clear, the security conversation can no longer focus solely on people and endpoints. Every AI agent with credentials, file access, and a network connection is effectively a new employee — one that never clocks out, rarely authenticates, and was never properly onboarded by IT.