Product1 publisher3 min readPublished
Reco says four in five AI tools in its telemetry run outside IT oversight, averaging 414 per 1,000 staff at smaller companies, which turns the cleanup into a question of who now owns each agent's credentials.
The Product Desk · Product desk

Follow any of these and your For You feed starts watching them — no settings page required.
Compiled by The Product DeskSomething wrong?How this is made
An OAuth consent screen is a thin place for a procurement decision to land, and often it is the whole of the process: there is no meeting and no security review, just one click on Allow [10]. What comes out the other side looks like an assistant and may hold permission to read email, summarise files, reach customer records, open ticketing systems or interact with a source-code repository, in Klein's description [7].
Per-desk arithmetic makes the count easier to hold. An average of 414 unsanctioned tools per 1,000 employees is one for roughly every 2.4 people, so a 250-person company is carrying about 104 of them [2][1]. The 80 percent figure puts four unsanctioned tools beside every one IT has a record of [1][2]. Both numbers come from the telemetry of a company that sells agent security to enterprises, so the population being measured is organisations that already bought a scanner [13].
Teams often assume that disabling a leaver's account on their last day removes their access, but the OAuth grant they issued in March still resolves, and so does the service account they stood up for a three-month project. Klein says the departing-employee process can work exactly as designed while the integrations and delegated access that person created get far less attention [9], and that Reco routinely finds these orphaned agents on its first pass through a customer environment [8].
IBM's number is the one that will travel into budget decks, so read it the way the report states it. Across 600 breached organisations in 17 industries, one in five had a breach involving shadow AI, which is about 120 companies [3][3]. Organisations with high levels of shadow AI recorded breach costs averaging $670,000 more than those with little or none [4]. That figure is a gap between two groups of breached companies, not a price tag on any single unowned agent, though the article's own summary compresses it into "added" [5].
What the reporting does not give you is the split that would size the job: no share of those 414 tools that are orphaned, and no share that holds access to customer data, code or production [4]. That ranking has to come out of your own inventory.
Two questions produce a usable grid: whether the agent can reach customer data, code or production [12], and whether a named, currently employed person will answer a page about it. High reach with a live owner is paperwork, so move the credential onto a managed identity and put the owner's name on it. High reach with no owner is the cell to work first, because revoking there costs a workflow at worst and nobody is left to argue for it. Low reach with an owner can wait. Low reach with no owner is a cleanup queue for a quiet week.
The figure worth reporting upward is how many agents with reach into customer data, code or production have a human name against them, and whether that count improves month over month, rather than how many AI tools the scan found [12].
Ranked by verification strength, evidence, and original report placement.
The article's TL;DR summary states that IBM found shadow AI 'added $670K to breach costs', while the body describes it as organizations with high levels of shadow AI also recording breach costs averaging $670,000 more than those with little or none.
Klein said Reco commonly finds 'orphaned agents' when entering a customer environment for the first time; an agent may have arrived through an employee's OAuth grant, API key or service account, and its access can survive changes elsewhere in the organization.
Klein said a company's normal process for handling departing employees might work exactly as designed while integrations and delegated access created by that employee receive far less attention.
Reco's State of Agent Security 2026 report found that 80% (four in five) of AI tools observed in its telemetry operated without IT oversight.
Reco's report found an average of 414 unsanctioned AI tools for every 1,000 employees at small and midsize companies.
IBM's 2025 Cost of a Data Breach report studied 600 breached organizations across 17 industries and found one in five had experienced a breach involving shadow AI.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One interview, three reports, no methods
Every number that makes this story alarming comes from a document nobody in our coverage examined. Reco's telemetry is quoted without a sample size, a customer count or a definition of what counts as a tool; IBM's and Okta's findings are cited secondhand. The qualitative core, orphaned agents surviving their creators through OAuth grants and service accounts, rests entirely on Klein, who is the only person interviewed and works for the vendor that produced the telemetry. That mechanism is specific enough that it could be independently verified, but our coverage has not verified it.
Real deployments, self-reported counts
The behaviour described is clearly happening rather than being predicted: staff wiring assistants into email, CRM and repositories through consent screens, and agents that already prepare sales updates or summarize tickets. Two datasets from different companies point the same way, and IBM's one-in-five is measured on organizations that were actually breached rather than surveyed about plans. What holds the score down is comparability: 414 per 1,000 employees has no denominator a reader can apply to their own environment, and the orphaned-agent share, which is the part that matters for cleanup, is never quantified.
The cost line overstates the study
The overstatement is concentrated in one sentence. The summary says IBM found shadow AI 'added $670K to breach costs'; the body, correctly, reports an average gap between organizations with high and low shadow AI, which is an association and not a bill. The scale figures carry a similar tilt, since the company counting ungoverned agents sells governance for them. Against that, the piece runs cooler than its own numbers where it counts, declining to recommend mass shutdown and saying plainly that some of these tools are useful and that failures usually look boring rather than dramatic.
The count and the cleanup, one supplier
Reco produced the telemetry saying four in five agents are ungoverned, Reco's CEO explains why finding them is hard, and Reco sells the discovery and governance work that follows. The Okta figure quoted alongside it comes from another vendor with a product in the same aisle. IBM's breach study is the only number here that does not belong to a company being interviewed. Our coverage does state Reco's business in the sentence that introduces Klein, so this is a disclosed interest, stated plainly rather than left for a reader to uncover.
Provenance clear, verification absent
We can say with confidence who claims what: attribution is clean throughout, the arithmetic in the piece is internally consistent, and the offboarding gap it describes is a familiar failure that any security team can test against its own leaver records. What we cannot do is confirm a single quantity, because all three studies are quoted rather than examined and no second outlet has covered the same ground.
product
IT's AI shopping list is inverted: 46.5% want automation, 71% of their AI tools are invisible1 publisher
security
Reco puts 80% of employee AI tools outside IT oversight against 21% of SaaS2 publishers
build
Shadow AI now has an invoice: about $670K on top of the average breach1 publisher
leadership
CrowdStrike buys SGNL, and standing privilege becomes a line item you have to defend1 publisher
Publishers with included, body-backed reporting in this cluster.
1 article · September 7, 2026