AI agents at work: What Acronis endpoint data reveals about MSP and SMB usage

AI agents at work: What Acronis endpoint data reveals about MSP and SMB usage
About 9.4% of Windows computers with Acronis EDR enabled were running an AI agent tool from June to September 2026, with most use shifting beyond developers into graphical desktop apps like Claude Desktop and Visual Studio Code. The report also warns that MCP-enabled connections are rarely switched on, but when they are, they can expose business systems to untracked outside access. #AcronisEDR #ClaudeDesktop #VisualStudioCode #MCP

Keypoints

  • About 9.4% of Windows endpoints with Acronis EDR had some kind of AI agent tool installed and active during the June to September 2026 observation window.
  • Usage has moved beyond terminal-based developer tools; roughly 72.7% of observed agent-tool machines were running graphical applications.
  • Two vendors dominate the market: Anthropic and Microsoft together accounted for 80.2% of all observed agent tool instances.
  • The most-used tool was Claude Desktop, followed by Visual Studio Code, Claude Code, and OpenAI’s Codex tools.
  • Only 4.9% of machines with MCP-capable tools had an MCP connection actually configured or in use, despite near-universal capability.
  • Adoption is led by smaller businesses and confirmed MSP-managed customers, with MSPs making up 78.2% of adopters and showing the highest adoption rate among partner-managed channels.
  • Personal autonomous AI agents were rare, appearing on about 0.018% of protected business endpoints, with Hermes and OpenClaw accounting for nearly all detections.

MITRE Techniques

  • [T1059 ] Command and Scripting Interpreter – The article describes command-line AI assistants that can run commands and act on systems directly (‘command-line assistants’, ‘run a command’).
  • [T1218 ] System Binary Proxy Execution – Agentic tools embedded in existing software such as Visual Studio Code and Visual Studio gained acting capability through updates (‘software that organizations had already deployed’, ‘quietly gained the ability to act’).
  • [T1105 ] Ingress Tool Transfer – MCP lets tools connect to external systems and data sources such as databases or company services (‘a database, a company system, another website’, ‘universal plug’).
  • [T1071 ] Application Layer Protocol – The report notes tools reaching outside themselves through a shared standard and remote server connections (‘shared standard called MCP’, ‘whether it runs locally or reaches a remote server’).
  • [T1562 ] Impair Defenses – The visibility gap and lack of governance/access controls are presented as a security weakness that can let risky AI activity proceed undetected (‘no AI governance policy’, ‘97% lacked proper access controls’).
  • [T1087 ] Account Discovery – The report emphasizes the need to know which endpoints and connections exist across users and partners (‘which endpoints are using generative AI tools’, ‘which connections exist and when those connections change’).

Indicators of Compromise

  • [Tool names ] Observed AI agent applications on endpoints – Claude Desktop, Visual Studio Code
  • [Tool names ] Command-line and IDE assistants observed in use – Claude Code, Codex CLI, Codex
  • [Tool names ] Other named tools and autonomous agents mentioned in the report – Hermes, OpenClaw
  • [Operating systems ] Personal AI agent activity was mostly on Windows endpoints, with small shares on other platforms – Windows, macOS
  • [Statistics/coverage ] Endpoint prevalence and adoption metrics used as detection context – 9.4% of Windows computers, 0.018% of endpoints, 4.9% MCP connections enabled


Read more: https://www.acronis.com/en/tru/posts/ai-agents-at-work-what-acronis-endpoint-data-reveals-about-msp-and-smb-usage/