
AI agents are already operating inside your environment. They log in, make changes, and act with the permissions of whoever deployed them, under standing OAuth grants that arrived one consent screen at a time, with no security review. While security teams debate frameworks, agents have quietly accumulated reach across your most sensitive systems. Our research shows this isn't a future risk. It's running at machine speed right now, creating exposure such as:
• A governance blind spot: 79% of SaaS is authorized, yet unsanctioned AI tools run at 414 per 1,000 employees at small and mid-size firms, close to one for every two or three people on staff
• An oversight failure: four in five AI tools operate with no IT oversight, and that ungoverned share is where agents live
• Host-level access by default: half of 500 published agent tools can execute shell commands directly on the machine running them
• A toxic combination: 62% of these tools can read your data and reach the internet in a single package, an exfiltration bridge nobody approved as a pair
• Unvetted, viral adoption: one open-source agent framework passed 135,000 GitHub stars in weeks, then had its control interface hijacked from a single malicious webpage, with its skill marketplace running 12% malicious
• A vulnerability flood: 525 vulnerabilities disclosed across agent and LLM tooling in eighteen months, at least 111 of them critical, landing faster than any patch cycle absorbs them
The challenge for security leaders isn't stopping agent adoption. It's gaining visibility and control over the agents already acting inside your environment, before an incident forces the issue.
This report measures that gap using Reco platform telemetry, an independent analysis of 500 published agent tools, and the public vulnerability record, and lays out a five-step framework for closing it.
Download today and see where your own environment stands.