Reco
9 stats1 reports
All Statistics
Small and midsize companies carry 414 unsanctioned AI tools per 1,000 employees.
AI AdoptionThird-Party RiskAI ToolsAI Risk
80% of AI tools operate without IT oversight.
Agent SecurityAI SecurityIT Governance
More than 80% of analyzed agent tools can read or write local files.
Data AccessAgent Security
79% of third-party applications are authorized.
Third-Party RiskSaaS Governance
62% of agent tools combine local file-read access with outbound network connectivity.
Agent SecurityNetwork Security
525 of 637 tracked agent and LLM-tooling vulnerabilities were disclosed in the past 18 months.
VulnerabilitiesLLM SecurityAgent Security
The average monthly disclosure rate for agent and LLM-tooling vulnerabilities increased from fewer than 5 during 2023–2024 to approximately 29 since January 2025.
VulnerabilitiesPatch ManagementAgent Security
At least 111 agent and LLM-tooling vulnerabilities are rated critical with CVSS scores of 9.0 or higher.
Critical VulnerabilitiesVulnerabilitiesAgent Security
50% of analyzed agent tools can execute shell commands.
Agent SecurityCommand Execution