Skip to main content
Cybersecurity

Agents Expose Blind Spots in AI Security Controls

Rows of equipment racks and devices in a network operations center or server room.

In environments studied for the 2026 State of Agent Security Report, roughly 1,280 third‑party products now embed AI — about 282 of them sit behind single sign‑on, and the other thousand are invisible to identity infrastructure by default.

A thousand agents the identity stack doesn't see

The report's central data point is stark: an identity stack can only govern what authenticates through it, and most agents never do. That gap is not the result of deliberate evasion; it is a structural mismatch. Many agents arrive inside software the enterprise already runs, not as a separately procured model behind a gateway, and therefore are not present at the point where identity and entitlement controls normally attach.

Why the decision point mattered more than the controls

For several years, "AI security" solved a first‑party problem: a company decided to use AI, bought licenses, deployed a model behind a gateway, and security pointed controls at that chosen thing. That workflow depends on a moment — a decision point — when reviewers, owners, and instrumenting controls exist. The State of Agent Security Report argues agents skip that moment.

Salesforce's Slack Code, launched in August 2026, illustrates the danger. The announcement promises agents "inherit Slack's built‑in security model, permissions, and admin controls from day one, without any additional IT lift." Read in security terms, the sentence describes an autonomous actor with reach into GitHub and production infrastructure whose governance is a chat tool's channel membership — and nothing in that lifecycle created a distinct surface for security to review or gate.

Three launch vectors, one destination

The report sorts agents into three concrete launch vectors: bought and built were familiar buckets, but a third — inherited — is the largest. Inherited agents ship inside existing platforms via product updates. Configured agents are enterprise prompts and logic running on someone else's runtime, model, and connectors. Built agents are the smallest group and the only one with a repo to scan and a build to gate.

Wherever they come from, agents converge on the same enterprise targets: "An agent born in a CRM ends up reading a data warehouse and writing to a ticketing system. An agent assembled on a cloud platform ends up holding tokens into Salesforce, Slack, and Drive." The enterprise application layer is the execution plane, and the report emphasizes it has no fixed edges.

Four questions, and why reach replaces isolation

The analysis frames every agent as two parts: the model that reasons and the scaffolding that turns a model into an actor — deciding what it is wired to, what it may call, and when it acts. "Almost none of the risk lives in the model. It lives in the scaffolding and the ecosystem the scaffolding sits inside." The report warns that vendor questionnaires, prompt filters, and model scanners evaluate an agent in isolation; reach is a property of the environment.

It highlights the "Connectivity" row as where agent security departs from existing products: reach through chains and connectors, not the standalone model, becomes the unit of risk analysis.

How buyers like JPMorgan Chase, regulators, and security teams are responding

  • Buyers — Patrick Opet, global CISO of JPMorgan Chase, told the software industry in 2025 that the third‑party supply chain had become a systemic risk, citing incidents serious enough that the bank had to isolate compromised suppliers in an open letter. He has since applied the same scrutiny to agents: ideally, an agent gets an identity but no entitlements by default, and IT confirms who it acts on behalf of before it touches anything outside that boundary. When a buyer of that size names agents as a supply‑chain risk, those expectations quickly surface in questionnaires.
  • Regulators — the report points to the EU AI Act's obligations phasing in through 2026, which presume an enterprise can inventory its AI systems, name their owners, and evidence oversight. An organization that cannot enumerate its agents cannot comply with those assumptions.
  • Security teams — the authors argue manual tracking collapses at scale: "The approach that keeps up with fifty agents through spreadsheets and quarterly reviews collapses at five hundred, and five hundred is one product update away from five thousand." Teams are being pushed toward a continuously refreshed, live map of what is operating and what each agent can reach.

Standing capability and the Reco Graph example

Some platforms are built around that live map. The report cites Reco and its Reco Graph, which "connects every human and non‑human identity, application, permission, and agent action into a single live view so that reach, not configuration, is the unit of analysis." That model treats reach as the thing to measure and monitor continuously, rather than relying on point‑in‑time scans of models or prompts.

The industry spent a decade building security for the AI enterprises decided to use. According to the State of Agent Security Report, the agents enterprises did not decide on are now the larger population. That shift forces a simple operational test: can an organization answer, in near real time, what code or actor is operating inside its apps, what access it inherited, and what it can touch downstream?

https://thehackernews.com/2026/10/the-third-party-agent-problem-why.html