Report by Reco
The State of Agent Security 2026
Key Findings
Small and midsize companies carry 414 unsanctioned AI tools per 1,000 employees.
80% of AI tools operate without IT oversight.
More than 80% of analyzed agent tools can read or write local files.
79% of third-party applications are authorized.
62% of agent tools combine local file-read access with outbound network connectivity.
525 of 637 tracked agent and LLM-tooling vulnerabilities were disclosed in the past 18 months.
The average monthly disclosure rate for agent and LLM-tooling vulnerabilities increased from fewer than 5 during 2023–2024 to approximately 29 since January 2025.
At least 111 agent and LLM-tooling vulnerabilities are rated critical with CVSS scores of 9.0 or higher.
50% of analyzed agent tools can execute shell commands.