Reco

9 stats1 reports

All Statistics

Small and midsize companies carry 414 unsanctioned AI tools per 1,000 employees.

AI AdoptionThird-Party RiskAI ToolsAI Risk

80% of AI tools operate without IT oversight.

Agent SecurityAI SecurityIT Governance

More than 80% of analyzed agent tools can read or write local files.

Data AccessAgent Security

79% of third-party applications are authorized.

Third-Party RiskSaaS Governance

62% of agent tools combine local file-read access with outbound network connectivity.

Agent SecurityNetwork Security

525 of 637 tracked agent and LLM-tooling vulnerabilities were disclosed in the past 18 months.

VulnerabilitiesLLM SecurityAgent Security

The average monthly disclosure rate for agent and LLM-tooling vulnerabilities increased from fewer than 5 during 2023–2024 to approximately 29 since January 2025.

VulnerabilitiesPatch ManagementAgent Security

At least 111 agent and LLM-tooling vulnerabilities are rated critical with CVSS scores of 9.0 or higher.

Critical VulnerabilitiesVulnerabilitiesAgent Security

50% of analyzed agent tools can execute shell commands.

Agent SecurityCommand Execution