Businesses are increasingly deploying AI tools and agents without the oversight of IT teams, raising the risk of data exposure and unsafe behaviour as autonomous systems gain access to corporate networks and information.
Research from AI and SaaS specialist Reco found that 80% of AI tools operating within organisations are running without IT oversight. The problem is particularly pronounced among smaller companies, where 414 AI tools are reportedly being used for every 1,000 employees without approval from IT departments.
The growing use of AI agents could introduce a more serious security risk. An assessment of 500 AI agent tools found that 62% could both read local data and access the internet, creating potential routes for sensitive information to leave an organisation.
The research also identified 637 vulnerabilities associated with AI agents, highlighting the security challenges created as autonomous systems become embedded in day-to-day business operations.
The findings point to the growing problem of “shadow AI”, where employees and teams adopt AI applications independently of established IT and security processes.
For organisations deploying connected devices and industrial systems, the issue extends beyond the governance of conventional workplace software. AI agents that can interact with local data, applications and networks could potentially become another route into wider connected environments if their permissions and activity are not properly controlled.
Richard Bovey, Chief Data Officer at AND Digital, said the rapid adoption of agentic AI was making strong data governance increasingly important.
“AI investment is accelerating fast, especially with the rise of agentic AI platforms,” he said. “However, without strong data governance, business leaders are effectively flying blind and risk losing oversight of critical value streams.”
Bovey added that 58% of organisations describe their data as “chaos”, arguing that reliable data foundations would be essential as AI systems take on more autonomous tasks.
Stuart Harvey, Chief Executive of Datactics, warned that human oversight alone would not necessarily prevent AI systems from behaving unpredictably.
“Advanced models have been seen to go rogue and producing their own attacks, and without oversight of models, this will become the new normal,” he said.
Harvey argued that organisations need people with sufficient technical expertise to understand both AI models and the data on which they operate, rather than relying on human intervention as a safeguard.
