The State of Agent Security 2026

Download to discover:
✔️
Why 79% of SaaS being "authorized" still leaves small and mid-size firms carrying 414 unsanctioned AI tools per 1,000 employees
✔️
Which four in five AI tools in your environment answer to nobody, and why that's exactly where agents operate
✔️
What half of 500 published agent tools can do to the machine they run on the moment they're installed
✔️
The permission pairing that turns a normal agent into a complete data-exfiltration pipeline, no malware required
✔️
How one open-source agent framework hit 135,000 GitHub stars, then got hijacked from a single malicious webpage
✔️
Why 525 vulnerabilities landed across agent and LLM tooling in eighteen months, and what that means for your next patch cycle
Most security programs are measuring the application layer while the risk has already moved to the identity layer. This report shows exactly how far that gap has opened, and what to do about it.

Sign up to get your copy today

AI agents are already operating inside your environment. They log in, make changes, and act with the permissions of whoever deployed them, under standing OAuth grants that arrived one consent screen at a time, with no security review. While security teams debate frameworks, agents have quietly accumulated reach across your most sensitive systems. Our research shows this isn't a future risk. It's running at machine speed right now, creating exposure such as:

A governance blind spot: 79% of SaaS is authorized, yet unsanctioned AI tools run at 414 per 1,000 employees at small and mid-size firms, close to one for every two or three people on staff

An oversight failure: four in five AI tools operate with no IT oversight, and that ungoverned share is where agents live

Host-level access by default: half of 500 published agent tools can execute shell commands directly on the machine running them

A toxic combination: 62% of these tools can read your data and reach the internet in a single package, an exfiltration bridge nobody approved as a pair

Unvetted, viral adoption: one open-source agent framework passed 135,000 GitHub stars in weeks, then had its control interface hijacked from a single malicious webpage, with its skill marketplace running 12% malicious

A vulnerability flood: 525 vulnerabilities disclosed across agent and LLM tooling in eighteen months, at least 111 of them critical, landing faster than any patch cycle absorbs them

The challenge for security leaders isn't stopping agent adoption. It's gaining visibility and control over the agents already acting inside your environment, before an incident forces the issue.

This report measures that gap using Reco platform telemetry, an independent analysis of 500 published agent tools, and the public vulnerability record, and lays out a five-step framework for closing it.

Download today and see where your own environment stands.