As enterprises rapidly adopt artificial intelligence, a profound shift is quietly taking place beneath the surface of corporate IT infrastructure—one that is fundamentally altering how organizations must approach cybersecurity and governance. According to findings highlighted in the 2026 State of Agent Security Report, roughly 1,280 third-party products now embed autonomous AI capabilities across studied corporate environments. Out of that total, approximately 282 sit comfortably behind traditional single sign-on (SSO) gateways, allowing IT and security teams to monitor, manage, and govern them through established identity frameworks.

However, the remaining thousand products operate entirely invisible to traditional identity infrastructure. This invisibility is rarely the result of malicious concealment or shadow IT circumvention by rogue employees. Instead, it occurs because standard enterprise identity stacks can only govern and authenticate what explicitly routes through them. Because most modern autonomous agents operate natively within existing applications without ever triggering a standard login or authentication handshake through corporate identity providers, they evade detection entirely.

This glaring operational gap highlights a massive evolution in the cybersecurity landscape—a shift that the security industry is only beginning to understand and categorize. For several years, enterprise "AI security" largely revolved around a controlled, first-party paradigm. In that older model, a company made a deliberate, top-down decision to leverage artificial intelligence. Leadership procured enterprise licenses, deployed a centralized model behind a secure API gateway, and security teams implemented strict controls around a tool that the business had explicitly chosen to adopt.

Autonomous agents, by contrast, do not arrive through a traditional procurement and deployment pipeline. They arrive embedded seamlessly inside software platforms the enterprise already runs, often materializing via routine product updates without requiring any explicit business decision or administrative sign-off.

Why the Decision Point Mattered More Than the Controls

Traditional enterprise security toolkits have long relied on a singular, foundational moment: the explicit adoption decision. Every classic control mechanism assumes this moment exists. Model scanning assumes a specific model was intentionally selected and evaluated. Prompt inspection assumes a dedicated gateway was deployed to intercept communications. Acceptable-use policies assume there was a formal adoption milestone to regulate. Historically, that precise moment provided security teams with a critical window for review, a tangible surface area to instrument, and a clearly defined human owner to hold accountable.

Autonomous agents systematically bypass this crucial moment of evaluation. A prime example of this dynamic can be seen in platform integrations such as Salesforce’s Slack Code, which allows any standard user to tag an autonomous coding agent directly into an active conversation thread. Upon activation, the agent immediately reads the shared contextual history, writes the necessary code, and opens a formal pull request.

On the surface, marketing materials and vendor announcements emphasize that these native tools inherit the host platform’s built-in security model, user permissions, and existing administrator controls right out of the box, requiring zero additional IT lift. However, when read from the perspective of an enterprise security team, that exact description reveals an autonomous software actor equipped with direct, high-level access to GitHub repositories and production infrastructure, governed solely by the fluid membership of a chat channel. Because the tool was quietly shipped as a feature update rather than intentionally deployed, there was nothing for security teams to instrument, review, or authorize because no formal adoption process ever took place.

Three Launch Vectors, One Destination

When evaluating modern artificial intelligence risks, security leaders have traditionally sorted deployments into two distinct categories: software that is purchased off-the-shelf and software that is engineered internally. However, industry analysis points to a third category that has quietly become the largest and most pervasive: inherited agents.

Inherited agents are those that ship directly inside existing enterprise platforms via standard product updates and feature rollouts. Configured agents, meanwhile, represent an enterprise’s custom prompts and specialized logic running on top of an external third-party runtime, foundational model, and connector infrastructure. Finally, built agents consist of open-source frameworks operating on infrastructure that the enterprise owns and maintains end-to-end.

The first two categories—inherited and configured agents—account for the overwhelming majority of current adoption and are expanding at an exponential rate as every major software application rapidly transforms into an agentic platform. The third category, built agents, represents the smallest and slowest-growing segment, yet it is ironically the only one that features a traditional code repository to scan and a formal build pipeline to gate.

Despite their vastly different origins, nearly all of these agents share a remarkably similar trajectory. An autonomous agent born natively inside a customer relationship management system inevitably expands its reach to read sensitive data from a corporate data warehouse and write automated updates to an external ticketing system. Similarly, an agent assembled on a cloud development platform ultimately ends up holding critical authentication tokens that grant access to enterprise systems like Salesforce, Slack, and cloud file storage. The modern enterprise application layer serves as the universal execution environment for these tools, and it possesses virtually no fixed edges or perimeters.

Four Core Questions for Evaluating Any Agent

To effectively govern this sprawling ecosystem, security teams must recognize that every autonomous agent is comprised of two distinct components: the foundational model that handles complex reasoning, and the surrounding scaffolding that transforms a static model into an active agent by determining what it connects to, what application programming interfaces it may call, and when it is permitted to take action. Industry experts point out that almost none of the actual cybersecurity risk resides within the model itself; instead, the real vulnerabilities live within the surrounding scaffolding and the intricate ecosystem in which that scaffolding operates.

The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn't

Assessing this risk effectively requires moving away from traditional questions about what a model might do in isolation and focusing instead on four critical areas: identity, permissions, connectivity, and activity.

Regarding identity, security teams must determine whether an agent is properly registered anywhere within the organization. When asked who owns a specific tool, organizations need to know if a named human operator steps forward, or if the agent silently executes permissions under the identity of whoever originally built or triggered it.

On the permissions front, administrators must evaluate what the agent is authorized to do and whether those privileges exceed its operational necessities. It is vital to discover whose specific OAuth scopes and administrative roles the agent inherited at creation, and whether any human intentionally approved those grants.

Connectivity represents the most complex dimension, addressing what an agent can reach both directly and transitively through the various products, authorization grants, data repositories, and secondary agents it interacts with. This is fundamentally a blast-radius question, and it is rarely answerable by simply reviewing an agent’s individual configuration screen.

Finally, activity monitoring requires security teams to continuously analyze what the agent is actually doing in practice and whether those actions align with normal operational patterns for its intended purpose, judged strictly by observed behavior rather than the descriptive text written in its system prompt.

The connectivity dimension is precisely where modern agent security diverges entirely from legacy software solutions. Traditional vendor security questionnaires, basic prompt filtering tools, and standard model scanners all evaluate an agent in complete isolation. In contrast, reach and blast radius are dynamic properties of the broader enterprise environment itself.

The Shift in Enterprise Buying Influence and Regulatory Pressure

Enterprise buyers with significant market influence have already begun adapting their strategies to address these evolving supply chain realities. Corporate leaders, such as JPMorgan Chase Global CISO Patrick Opet, have increasingly warned the broader software industry that third-party digital supply chains represent a systemic organizational risk. Major financial institutions have faced incidents severe enough to necessitate the immediate isolation of compromised suppliers, prompting a push for tighter vendor scrutiny.

Under this rigorous approach, an ideal enterprise agent should be granted a distinct identity but zero default entitlements, requiring explicit IT confirmation of the human it acts on behalf of before it is permitted to touch any resource outside a strictly defined boundary. When a security buyer of that magnitude publicly classifies autonomous agents as a primary supply-chain risk, those stringent requirements rapidly filter into security questionnaires across virtually every industry sector within a matter of quarters.

Regulatory bodies are simultaneously operating under similar assumptions. The compliance obligations of the European Union Artificial Intelligence Act, which phase in progressively, explicitly presume that an enterprise can comprehensively inventory its artificial intelligence systems, clearly designate their internal owners, and provide verifiable evidence of ongoing human oversight. An organization that lacks the capability to fully enumerate and track its active agents will find itself unable to meet these emerging regulatory mandates.

Moving Toward Continuous Visibility and Governance

The traditional approach of managing artificial intelligence adoption through static spreadsheets and periodic quarterly reviews inevitably collapses once an organization scales from fifty agents to five hundred—and in today’s software environment, reaching five hundred agents is often just one major product update away from reaching five thousand.

What must replace manual tracking is a live, continuously refreshed capability that instantly answers critical operational questions: what tools are currently running, what permissions each agent inherited, what systems it can reach directly or through complex authorization chains, what actions it is performing in real time, and how all of those parameters have shifted since yesterday.

To address this challenge, specialized cybersecurity platforms are emerging to map these complex relationships. Leading solutions, such as the Reco platform powered by the Reco Graph, are specifically designed to connect every human and non-human identity, underlying application, permission grant, and agent action into a single unified live view. By shifting the unit of analysis from static configuration settings to dynamic environmental reach, these platforms enable modern enterprises to secure their expanding digital ecosystems against the invisible wave of autonomous agents.

Leave a Reply

Your email address will not be published. Required fields are marked *