التكنولوجيا

Invisible AI Agents Creating New Enterprise Security Risks

Invisible AI Agents Creating New Enterprise Security Risks

AAdmin
٢٦ أغسطس ٢٠٢٦
3 دقيقة قراءة
Invisible AI Agents Creating New Enterprise Security Risks

Lurking in many business environments are AI agents that pose serious security risks but, for the most part, remain out of sight of security teams, according to a report released Wednesday by a global agent security company.

AI agents now read inboxes, file tickets, write code, and move records between applications under standing OAuth grants, the report by Reco noted, and most arrived the way unsanctioned AI always has: one consent screen at a time, with no security review.

The 16-page report, based on Reco telemetry on AI tool use in the enterprise, an analysis of 500 Model Context Protocol (MCP) servers, and public vulnerability records, pointed out that an attacker who gets into a chatbot sees whatever employees pasted into it, while one who gets into an agent inherits everything it was permitted to reach, at machine speed, under a non-human identity an organization created but never personally meets.

While acknowledging that most SaaS applications are authorized in businesses, the report found that small and mid-size companies carry 414 unsanctioned AI tools per 1,000 employees.

"Employees use unsanctioned agents because they solve immediate work problems, like summarizing an inbox or connecting a workflow to a CRM," explained Reco CEO Ofer Klein.

"The employee may see that as a productivity gain, not as introducing a security risk into the company's environment," he told TechNewsWorld.

He added that "shadow AI" tools often enter the business without a security review, but still gain access to sensitive company data and systems, often through a browser extension or OAuth consent screen, outside the normal procurement and review process.

"At smaller companies, the volume is especially concerning because these tools may be able to reach the same payroll, customer and source-code systems they would at a much larger enterprise, but with fewer people watching," he said.

Dave Hayes, vice president of product at FusionAuth , a maker of customer identity and access management software in Broomfield, Colo., noted that unsanctioned apps used to be a data problem, but AI agents are far more dangerous, even when they're not rogue.

"Agents connect to multiple systems and attempt to achieve their goal regardless of human rules, whereas a user-installed app would connect to a single system and break if it couldn't do its job," he told TechNewsWorld.

Reco also reported that four out of five AI tools run without IT oversight.

"A tool with no IT oversight is a tool with no policy attached to it — no record of what data it can touch, no way to revoke its access when a project ends and no audit trail if something goes wrong," explained Ron Longo, CEO of TrustLogix , a data security and access governance company in Mountain View, Calif.

"At scale, that adds up to a large, invisible footprint of standing access across the business that nobody is actively managing," he told TechNewsWorld.

Jacob Krell, senior director for secure AI solutions and cybersecurity at Suzu Labs , a provider of AI-powered cybersecurity services in Las Vegas, pointed out that the ungoverned share is exactly where autonomous agents operate.

"An employee can configure an AI agent inside a platform such as Salesforce or Microsoft 365 without creating the procurement trail associated with a new application," he told TechNewsWorld. "Depending on how the integration is set up, that agent may inherit the platform's existing access permissions and continue operating autonom…