The rapid proliferation of enterprise artificial intelligence has introduced a profound paradigm shift that the cybersecurity industry is only beginning to comprehend and categorize. For years, the prevailing framework for "AI security" addressed a fundamentally first-party problem: a corporation would deliberately choose to adopt artificial intelligence, officially procure software licenses, deploy a sophisticated language model securely behind a specialized API gateway, and task the internal security organization with pointing controls directly at the specific asset the business had intentionally chosen to deploy.
However, the modern enterprise landscape is no longer shaped exclusively by deliberate, top-down purchasing decisions. Autonomous AI agents—software entities capable of reasoning, planning, and executing complex multi-step workflows—do not arrive through traditional procurement channels. Instead, they arrive silently inside software applications the enterprise is already running, embedded via routine product updates and ecosystem integrations, and they frequently do so entirely without the explicit knowledge, review, or authorization of corporate IT and security teams.
Recent data compiled for the 2026 State of Agent Security Report illustrates the staggering scale of this invisible workforce. Within the enterprise environments analyzed for the report, roughly 1,280 third-party products now natively embed artificial intelligence capabilities. Of that total, approximately 282 sit securely behind centralized single sign-on infrastructure, giving security teams at least baseline visibility into their usage. The remaining one thousand products, however, remain entirely invisible to standard identity and access management infrastructure by default.
This invisibility is not the result of malicious obfuscation by vendors; rather, it is a structural limitation of modern identity stacks. Traditional identity infrastructure can only govern and monitor what explicitly authenticates through it, and the vast majority of modern AI agents never interact with single sign-on mechanisms or enterprise identity providers during their deployment.
Why the Decision Point Mattered More Than the Controls
To understand why this architectural gap poses such a significant challenge, one must examine how legacy security toolkits operate. Every traditional control assumes a distinct moment of adoption existed in time. Model scanning tools assume an organization deliberately selected a specific model to deploy; prompt inspection utilities assume an enterprise engineered and deployed a dedicated gateway; acceptable-use policies assume there was a formal corporate adoption process to regulate. Historically, that critical moment of decision-making provided security teams with a vital opportunity for formal review, a tangible attack surface to instrument, and a clearly defined human owner to hold accountable.
Autonomous agents systematically bypass this crucial moment of evaluation. A prominent example of this operational shift can be observed in tools like Salesforce’s Slack Code, which allows any enterprise user to dynamically tag a coding agent into an ongoing chat conversation. The agent immediately reads the shared conversational context, writes functional code, and autonomously opens a pull request in external repositories. Official product announcements frequently market these capabilities by promising that agents inherit the host platform’s built-in security models, user permissions, and administrator controls from day one, requiring zero additional IT lift.
When a cybersecurity professional reads that promise, however, it translates into something entirely different: an autonomous, highly capable software actor with direct, unmonitored reach into source code repositories like GitHub and sensitive production infrastructure, governed solely by the fluid membership boundaries of a routine chat channel. Because the feature was enabled automatically through a platform update rather than a deliberate corporate procurement cycle, there was nothing for security teams to instrument, review, or authorize, because no formal adoption decision ever took place.
Three Launch Vectors and One Shared Destination
Enterprise security leaders have traditionally attempted to categorize artificial intelligence integration into two distinct buckets: software that is purchased off-the-shelf and software that is engineered internally. Yet, a third and far larger category has come to dominate the landscape: inherited agents. These autonomous entities ship directly inside existing enterprise platforms via routine product updates and feature expansions.
Alongside inherited agents are configured agents, which consist of an enterprise’s proprietary prompts and custom logic operating on top of a third-party runtime environment, foundation model, and external connectors. Finally, built agents represent custom solutions developed on open frameworks hosted on infrastructure owned and managed end-to-end by the enterprise.
While inherited and configured agents account for an overwhelming majority of total enterprise adoption and are growing exponentially as virtually every major software application transforms into an agent platform, built agents represent the smallest and slowest-growing category. Ironically, built agents are also the only category that traditional security tools are actually equipped to handle, as they typically feature a dedicated code repository to scan and a formal build pipeline to gate.
Regardless of their origin, virtually all autonomous agents share a common destination within the corporate network architecture. An agent initially born inside a customer relationship management platform inevitably expands its operational scope, reading data from a centralized data warehouse and executing write operations directly into an enterprise ticketing system. Similarly, an agent assembled on a cloud platform frequently ends up holding persistent OAuth tokens and API keys granting access to disparate services like Salesforce, Slack, and cloud storage drives. The modern enterprise application layer serves as the universal execution environment for these tools, and it possesses no fixed or easily defensible perimeter.

Evaluating Agents Beyond the Model Itself
Every autonomous agent fundamentally consists of two primary components: the underlying foundation model that handles reasoning and inference, and the surrounding technical scaffolding that transforms a static model into an active software participant, determining what systems it is wired to, what APIs it may call, and when it is permitted to take action. Industry analysis reveals that almost none of the actual security risk resides within the foundation model itself. Instead, the overwhelming majority of risk is concentrated within the scaffolding and the complex digital ecosystem in which that scaffolding operates.
Assessing the security posture of an agent requires a fundamental shift away from evaluating isolated model behaviors and toward a comprehensive review of four critical operational areas. The first area is identity, which examines whether an agent is properly registered anywhere within corporate inventories, whether a named human owner can be identified when questioning whose asset it is, or whether it silently executes under the elevated privileges of the developer who originally built it.
The second area focuses on permissions, analyzing what actions the agent is authorized to perform and whether those capabilities exceed its operational necessity, including a review of which specific OAuth scopes and administrative roles it inherited at creation and whether those grants were intentionally approved.
The third and most critical area is connectivity, which evaluates what external systems the agent can reach, both directly and transitively, through the products, data grants, underlying data stores, and other interacting agents it touches. This addresses the core blast-radius question, which is rarely answerable by looking solely at an agent’s individual configuration screen because reach is an inherent property of the interconnected enterprise environment rather than a static configuration setting.
The final area monitors activity, continuously observing what the agent is actually executing in practice and determining whether those runtime behaviors align with normal operational parameters for its intended purpose, judged strictly by observed actions rather than the descriptive text contained within its system prompt. This emphasis on connectivity and transitive reach separates modern agent security from traditional software evaluation tools, as vendor questionnaires, prompt filters, and model scanners evaluate agents in isolated environments, failing to capture the systemic risk posed by enterprise-wide integrations.
The Broader Industry Response and Regulatory Pressure
Enterprise buyers wielding significant market influence have already begun adapting their governance strategies to address this evolving risk landscape. In a notable industry development, Patrick Opet, global chief information security officer at JPMorgan Chase, cautioned the broader software industry regarding the systemic risks posed by vulnerable third-party supply chains, detailing serious incidents that required the financial institution to actively isolate compromised suppliers. Opet and other senior security leaders have since applied this rigorous level of scrutiny directly to artificial intelligence agents.
Under an ideal enterprise governance model, an agent should be provisioned with a distinct digital identity but zero entitlements by default, requiring IT verification of the human it acts on behalf of before any permissions are granted outside a strictly defined boundary. When organizations of this financial scale designate autonomous agents as a critical supply-chain vulnerability, those compliance and security expectations inevitably propagate across the broader market via security questionnaires within a matter of quarters.
Regulatory bodies are simultaneously operating on very similar assumptions regarding institutional accountability. The compliance obligations of regulatory frameworks such as the European Union Artificial Intelligence Act explicitly require organizations to maintain comprehensive inventories of their deployed artificial intelligence systems, formally designate internal operational owners, and provide verifiable evidence of continuous oversight. Enterprises that lack the technical capability to accurately discover and enumerate their active AI agents will find themselves fundamentally unable to meet these regulatory mandates.
Moving Toward Continuous Visibility and Environmental Mapping
The traditional security approach of managing software deployments through static spreadsheets and periodic quarterly reviews collapses entirely when an organization scales from fifty agents to five hundred—and given the speed of automated platform updates, an enterprise managing five hundred agents is often only a single product update away from operating five thousand. Replacing manual oversight requires a live, continuously refreshed operational capability that can instantly answer fundamental questions regarding what software is currently running, what permissions each agent has inherited, what systems it can reach directly or through multi-hop chains, what actions it is actively performing, and how those security parameters have shifted over time.
To address these visibility gaps, specialized security platforms have emerged to construct comprehensive operational maps that connect every human and non-human identity, software application, permission grant, and agent action into a single unified view. By treating reach and transitive environmental access as the primary units of analysis rather than relying solely on static configuration reviews, modern security architectures aim to bring order to an enterprise application layer that continues to expand without fixed edges, forcing organizations to rethink how they govern an invisible workforce that arrived without an invitation.
