Shadow AI Is Already Inside Your Company. Here's How to Get Control of It
The Next Web, Monday, September 7th, 2026
Reco data shows 80% of AI tools run without IT oversight; the fix starts with mapping what each agent can reach and who owns it.
Reco's State of Agent Security 2026 report found four in five AI tools in its telemetry operated without IT oversight, with SMBs averaging 414 unsanctioned AI tools per 1,000 employees.
IBM's 2025 Cost of a Data Breach report found one in five breached organizations had a shadow AI incident, adding about $670,000 to breach costs.
Reco CEO Ofer Klein says AI hides in browser extensions, meeting tools, CRM workflows and developer environments, often added via a simple OAuth consent.
Rather than shutting everything down, companies should map each agent's access, identify owners, watch for orphaned agents, and prioritize those touching customer data, code and production systems.