Skip to main content

Reco releases State of Agent Security 2026 findings on agent oversight

Reco released “The State of Agent Security 2026,” a report that reviewed how AI agents and related tooling are adopted and governed. The findings focus on where governance gaps appear and how agent capabilities intersect with disclosure activity, using analysis of published servers and vulnerability records.

According to the report’s Reco telemetry, four in five AI tools operated without IT oversight. Reco said it observed those tools in use without IT or security approval, and it also analyzed how agent tooling can access local data while maintaining outbound network connectivity.

Reco’s review of 500 published Model Context Protocol servers found that 62% combined local file-read access with outbound network connectivity. Reco also tracked 637 vulnerabilities across agent and LLM tooling, and said 525 were disclosed in the past 18 months, describing this as more than a sixfold increase in the average monthly disclosure rate compared with 2023 and 2024.

“AI agents have moved from experimentation into daily business workflows, but our findings show only 20% of AI tools in enterprise ecosystems are currently governed by IT oversight,” said Ofer Klein, CEO of Reco. “That leaves organizations exposed to a new class of operational risk. Agents embedded in applications can operate through existing permissions, OAuth grants and workflow access, creating toxic combinations that expose data and trigger actions beyond what any owner approved.”

Reco said the report incorporated anonymized platform telemetry from 62 large enterprises collected between Jan. 1, 2026 and Aug. 1, 2026, and that it also reviewed vulnerability disclosures from the National Vulnerability Database published from January 2025 through June 2026.

Provided by Globe Newswire on behalf of Recorded Future. Read the original.

Graph Connections

4thThis is Recorded Future's 4th mention on Decision Insights this quarter, following coverage of its Reco to Present Sessions on AI Agent Security Exposure at Black Hat USA and DEF CON 34 in August.