AI governance has a discovery problem and a capability problem. Unsanctioned AI can enter an enterprise through browser extensions, delegated access, and employee-built workflows. Agents inside approved applications can also operate through identities, permissions, and integrations the organisation already uses. Security leaders need visibility into both the AI tools present and the access available to them.
Product approval creates a governance checkpoint. It shows that a tool has passed an organisational process. But an agent’s effective reach can change later as it acts through existing user permissions, service accounts, APIs, and integrations. Discovery is the starting point for governance rather than its endpoint.
The first gap is shadow AI
Reco’s State of Agent Security 2026 report found that 20% of AI tools observed across anonymised platform telemetry from 62 large enterprises had IT or security approval. Reco also said 79% of third-party applications were authorised. Its telemetry covered large enterprises in financial services, healthcare, retail and consumer sectors, and telecommunications. Reco sells security technology in this area, so these figures should be read as the company’s findings.
Several routes can bring AI into business systems without a conventional software purchase. Browser extensions can add AI functions inside an employee’s working environment. OAuth, an authorization protocol that lets one service receive delegated access to another, can connect AI tools to existing services. Employee-built workflows can also connect AI to company data and business processes outside the procurement route for centrally purchased SaaS.
Niche automation frameworks, browser-based agents, and integration tools create a related visibility problem. Connections can rely on permissions that persist beyond initial setup, including OAuth grants and other credentials. An inventory focused on centrally purchased assistants and copilots can miss AI connected through these other paths. Reco’s approval figures make discovery a material governance concern within its dataset.
Discovery also determines whether security teams can examine an AI tool’s access. A tool missing from the inventory cannot undergo an inventory-based review of its permissions and integrations. Reco’s data indicates that formal approval processes capture a minority of the AI tools it observed. Once a tool is found, the next question is what authority it can exercise.
Approval establishes only the starting state
AI agents can operate inside mainstream workplace software instead of appearing as separate applications. An agent may use access that already exists through user permissions, OAuth grants, service accounts, or APIs. These mechanisms can give people and software legitimate access to files, services, and business processes. An agent’s effective capability depends on the actions those access paths permit together.
Reco’s analysis of 500 published Model Context Protocol servers provides one example. Model Context Protocol, or MCP, gives AI applications a standardized way to connect with tools and data sources. Reco selected publicly available servers from the npm registry using the keyword “mcp”, then filtered out frameworks, gateways, and clients to focus on software confirmed to start a server. As with Reco’s telemetry, this analysis comes from a security vendor that benefits commercially from greater demand for AI-security controls.
Reco found that 62% of the MCP servers in its sample combined local file-read capability with outbound network connectivity. A server with both capabilities has a technical path to read local information and transmit information over a network, a combination that could support data exfiltration. The figure measures the presence of capabilities. It does not show that those servers exfiltrated data, were exploited, or caused incidents.
One tool may read files, another may communicate externally, and another may trigger workflows. An agent able to coordinate those functions through existing permissions and integrations can perform a wider range of actions than any single permission describes. The MCP result provides a concrete instance: local file access and an outbound communication path coexist in Reco’s sample. Governance therefore has to examine combinations as well as individual grants.
Ofer Klein, Chief Executive Officer at Reco, describes these combinations as a source of operational risk. He argues that agents embedded in applications can use existing permissions, OAuth grants, and workflow access to expose data or trigger actions beyond what an individual owner approved. Reco benefits commercially when enterprises perceive a need for additional AI-security controls, so Klein’s characterization is a vendor assessment. Reco’s telemetry and MCP analysis provide the quantitative evidence presented for that assessment.
An application inventory can record that software is sanctioned and identify its administrative status. Assessing effective capability requires more information about the agents operating through an application, the credentials available to them, and the integrations connecting them to other systems. Persistent access matters because an authorization can remain available after its initial grant. Continuing governance must therefore be able to reassess the state established at approval.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
Vulnerability disclosures change the post-approval picture
Permissions are one reason an initial review can become outdated. Reco tracked 637 vulnerabilities across agent and large language model tooling. It reported that 525 were disclosed in the previous 18 months, including at least 111 ranked critical with Common Vulnerability Scoring System, or CVSS, scores of 9.0 or higher. CVSS is a standard scale for rating the severity of software vulnerabilities.
Reco also reported fewer than five vulnerabilities per month on average during 2023 and 2024 and about 29 per month since January 2025. These numbers measure disclosures rather than successful exploitation. Within Reco’s dataset, new security information about agent tooling has been appearing substantially faster since January 2025. Reco’s commercial stake in AI security also applies to its interpretation of this vulnerability data.
A tool can pass an initial review and later become associated with newly disclosed vulnerabilities. OAuth grants, service accounts, APIs, and integrations can remain active while the known security characteristics of connected software change.
The supported implication is narrower. A one-time security review records conditions at a point in time, while later vulnerability disclosures can change what is known about the software. Continuing visibility lets security teams reassess connected tools as that information changes. This adds a time dimension to the earlier problem of discovering tools and understanding their effective access.
Governance has to follow capabilities after approval
For CIOs and security executives, a useful inventory has two dimensions. Teams need visibility into AI entering through browsers, OAuth connections, employee workflows, and other routes. They also need to map how discovered agents interact with identities and technical permissions after connection. Reco’s findings support treating discovery and access mapping as related governance tasks.
That operational view includes identities, OAuth grants, service accounts, APIs, persistent permissions, and agent integrations. These elements determine which resources and actions an agent can reach through connected systems. Mapping them lets a security team evaluate effective reach even when the host application has already passed an approval process. It also exposes permission combinations for review.
Combinations deserve particular attention because individual access records describe individual grants. File access enables one set of actions, an external connection another, and workflow execution another. When an agent can coordinate those paths, security teams need to evaluate the resulting set of possible actions. Data access and outbound connectivity within the same connected tool show why that combined view matters.
Governance also has to persist over time. Initial security review remains an important control point, especially given the low approval share in Reco’s observed AI tools. Existing grants can persist, integrations can connect separate capabilities, and later vulnerability disclosures can change what is known about previously accepted software. For security leaders, the durable control objective is visibility into which identities and services give an agent authority and what that authority permits in combination.
Key executive takeaways
- Shadow AI creates a discovery gap: Reco found that only 20% of observed AI tools had IT or security approval. Leaders should extend discovery beyond centrally purchased software to browser extensions, OAuth connections, employee-built workflows, and other routes into enterprise systems.
- Approval does not define effective access: AI agents can operate through existing user permissions, service accounts, APIs, and integrations, combining capabilities in ways individual grants do not show. Security teams should map what agents can access and do after approval.
- New vulnerabilities can change approved tools’ risk: Reco reported a sharp increase in vulnerability disclosures across agent and LLM tooling since January 2025. Continuing visibility allows security teams to reassess connected tools as new security information emerges.
- Governance must follow capabilities over time: Effective AI governance requires continuous discovery alongside access mapping across identities, permissions, credentials, and integrations. Leaders should evaluate these capabilities in combination and revisit them as permissions, connections, and known vulnerabilities change.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


