In environments studied for the 2026 State of Agent Security Report, approximately 1,280 third-party products now incorporate AI. Among them, about 282 are accessible through single sign-on, while the remaining thousand remain unseen by identity infrastructure by default. This is not due to intentional concealment, but rather because an identity stack can only govern what authenticates through it, and most agents do not.
This gap signifies a notable shift in the security industry that is just beginning to be acknowledged. For years, “AI security” primarily addressed first-party issues: a company choosing to use AI, obtaining licenses, deploying a model behind a gateway, and implementing security controls around the selected technology. However, agents do not follow this same pattern. They are integrated into existing enterprise software without a deliberate decision-making process.
Why the decision point mattered more than the controls
Every security control in the first-party context relies on the existence of a specific moment: model scanning assumes a model was chosen, prompt inspection assumes a gateway was installed, and an acceptable-use policy assumes there was an intentional adoption. Agents bypass this moment. For example, Salesforce’s Slack Code allows a user to introduce a coding agent into any conversation, enabling the agent to read context, write code, and submit a pull request. This autonomy raises governance concerns as the agent operates within existing platforms without explicit adoption measures.
Three launch vectors, one destination
Security experts often categorize agents as bought, built, or inherited. Inherited agents, shipped within existing platforms through product updates, constitute the largest category. Configured agents involve an enterprise’s logic running on external infrastructure, while built agents operate on an internally owned framework. Despite their origins, all agents ultimately converge in the enterprise application layer, which lacks distinct boundaries.
Four questions that work on any agent
Every agent comprises a reasoning model and surrounding infrastructure that dictate its actions. The risk primarily resides in the scaffolding and ecosystem supporting the model. Four key questions address these risks, focusing on identity, permissions, connectivity, and activity. Notably, evaluating an agent’s connectivity reveals security gaps that conventional assessments may overlook.
The buyers with the most influence have already moved
Global CISO Patrick Opet of JPMorgan Chase highlighted the systemic risks associated with third-party supply chains in 2025 and has since extended this scrutiny to agents. His approach emphasizes granting agents identities without entitlements by default, ensuring IT oversight of their actions. Regulatory bodies are also aligning with this perspective, as demonstrated by the EU AI Act’s requirements for comprehensive AI system inventories and oversight.
What a standing capability looks like
Managing a growing number of agents necessitates a dynamic approach that goes beyond periodic reviews. Platforms like Reco offer a comprehensive view of all agents and their interactions, emphasizing reach as a critical security metric. As the prevalence of agents increases, the industry must adapt security measures to address these evolving challenges.
For more insights on agent discovery and security, visit reco.ai/platform.




