As artificial intelligence rapidly transitions from passive chat interfaces to autonomous actors capable of executing complex workflows, corporate security teams are facing an unprecedented blind spot. According to new data detailed in the 2026 State of Agent Security Report, roughly 1,280 third-party products now embed autonomous AI capabilities within the enterprise environments analyzed by researchers.
Out of that total, only about 282 sit securely behind single sign-on (SSO) infrastructure. The remaining thousand operate entirely invisible to traditional identity and access management (IAM) stacks by default. This invisibility is rarely the result of malicious intent or clandestine deployments by rogue employees; rather, it stems from a fundamental structural limitation. Standard enterprise identity stacks are engineered to govern only what explicitly authenticates through them. Because the vast majority of modern autonomous agents bypass this gateway, existing infrastructure remains blind to their presence.
This growing governance gap highlights a profound shift in the cybersecurity landscape—one that the industry is only beginning to understand and categorize. For several years, enterprise "AI security" largely addressed a first-party problem. Organizations made intentional decisions to deploy AI, procured corporate licenses, routed traffic through managed gateways, and directed standard security controls toward technologies explicitly chosen by the business.
Autonomous agents, however, arrive differently. They do not wait for a formal procurement cycle or an IT review board. Instead, they slip quietly into software suites that enterprises are already running, establishing a foothold without a formal corporate adoption decision.
Why the Decision Point Mattered More Than the Controls
Traditional enterprise security toolkits have long relied on a specific moment of adoption to anchor their defenses. Model scanning assumptions required a specific model to be actively selected by the organization; prompt inspection assumed a managed gateway had been deliberately deployed; acceptable-use policies presupposed an official rollout process that leadership could authorize and monitor. That initial decision point provided security teams with a vital opportunity: a formal review window, a defined surface area to instrument, and a designated internal owner to hold accountable.
Autonomous agents systematically bypass this critical moment. A prime example of this phenomenon is Salesforce’s Slack Code, which allows any standard user to tag a coding agent directly into an ongoing enterprise conversation. The agent immediately reads the shared contextual history, writes the necessary code, and automatically opens a pull request in the organization’s repositories.
From a product announcement perspective, such features promise seamless integration, noting that agents inherit the host platform’s built-in security model, user permissions, and administrator controls from day one without requiring additional IT lift. However, when viewed through the analytical lens of a corporate security team, that exact description reveals an entirely different reality: an autonomous software actor equipped with direct, operational reach into core code repositories like GitHub and underlying production infrastructure, governed by nothing more robust than a standard chat tool’s channel membership. Because the tool arrived via an automated platform update rather than a formal procurement project, there was nothing for security teams to instrument or review, simply because no official adoption event ever took place.
Three Launch Vectors, One Destination
Historically, enterprise security leaders have attempted to categorize AI adoption into two distinct buckets: software that is purchased off-the-shelf and software that is built in-house. However, a third and vastly larger category has emerged to dominate modern corporate environments.
Security analysts now recognize three primary launch vectors for enterprise AI. The first is inherited agents, which ship directly inside existing third-party software platforms via routine product updates and feature rollouts. The second is configured agents, representing an enterprise’s custom prompts and internal logic operating on top of a third-party runtime environment, foundation model, and external connectors. The third category comprises built agents, which are developed using open frameworks deployed entirely on enterprise-owned infrastructure.
Market realities indicate that the first two categories—inherited and configured agents—account for the overwhelming majority of actual enterprise adoption. They are expanding at an exponential rate as every major enterprise application evolves into an autonomous agent platform. Conversely, built agents represent the smallest and slowest-growing segment, yet they remain the only variety equipped with a dedicated code repository to scan and a formal build pipeline to gate.
Regardless of their origin point, these agents ultimately converge on the same operational destination. An agent that originates inside a customer relationship management (CRM) platform inevitably ends up querying a corporate data warehouse and writing automated records to an enterprise ticketing system. Similarly, an agent assembled on a cloud development platform frequently ends up holding elevated authentication tokens granting access to Salesforce, Slack, and cloud storage directories simultaneously. The modern enterprise application layer acts as the shared execution environment for all of these systems, and it possesses no fixed or reliable perimeter edges.
Four Questions That Work on Any Agent
At its architectural core, every modern autonomous agent consists of two distinct components: the underlying foundation model that handles reasoning and decision-making, and the surrounding software scaffolding that transforms a static model into an active participant. This scaffolding dictates what data sources the model is wired into, what external Application Programming Interfaces (APIs) it is permitted to call, and precisely when it is authorized to take autonomous action.

Industry analysis reveals that almost none of the actual cybersecurity risk resides within the model itself. Instead, vulnerabilities and dangerous over-privileging are concentrated within the scaffolding and the complex digital ecosystem in which that scaffolding operates. To properly assess this risk, security professionals rely on four critical areas of review, none of which depend on analyzing what a base model might do in isolation.
The first area of review is identity. Security teams must determine whether an autonomous agent is formally registered within organizational inventories, and whether a named human stakeholder can be identified when asking who owns the asset. In many cases, unmanaged agents silently execute with the administrative privileges of whichever developer or user initially triggered them.
The second area focuses on permissions. Analysts must evaluate what operations the agent is legally and technically allowed to perform, and whether those capabilities far exceed its operational necessity. This requires auditing the OAuth scopes and user roles the agent inherited at the moment of its creation, and verifying whether those privilege levels were intentionally assigned.
The third and most critical area involves connectivity. Security leaders must evaluate what resources the agent can reach—both directly and transitively—through the diverse products, API grants, internal data stores, and secondary agents it touches. This represents the ultimate blast-radius question, and it is a metric that can almost never be answered simply by looking at the agent’s individual configuration screen.
The fourth area is active behavior. Teams must continuously monitor what the agent is actually doing in production, determining whether those actions align with expected operational norms. This must be judged strictly by empirical behavioral telemetry rather than the idealistic descriptions written into its system prompts.
It is within the connectivity dimension that agent security diverges fundamentally from traditional cybersecurity tools. Standard vendor risk questionnaires, input prompt filters, and model vulnerability scanners all evaluate an agent in isolation. True reach, however, is an emergent property of the entire enterprise environment.
The Influence of Enterprise Buyers and Regulatory Pressures
The urgency surrounding autonomous agent governance is already reshaping priorities among major enterprise buyers. Patrick Opet, the global Chief Information Officer and Chief Information Security Officer of JPMorgan Chase, issued a stark warning to the software industry regarding third-party supply chain risks. Citing severe incidents that forced the financial institution to actively isolate compromised suppliers, Opet highlighted the systemic danger posed by unvetted third-party integrations.
That rigorous level of security scrutiny has increasingly been applied directly to autonomous AI agents. The ideal security posture dictates that an agent should be provisioned with a clear digital identity but zero inherent entitlements by default. IT infrastructure must verify the human authorization behind an agent before it is permitted to interact with any resource outside a strictly controlled boundary. When a financial institution of that scale publicly designates autonomous agents as a primary supply-chain vulnerability, similar demands rapidly filter down into standard enterprise security questionnaires across global markets.
Regulatory bodies are rapidly converging on the same foundational assumptions. The European Union AI Act, with obligations phasing in throughout 2026, explicitly mandates that enterprises maintain the capability to inventory their artificial intelligence systems, designate accountable internal owners, and provide verifiable evidence of ongoing oversight. Organizations that lack the technical capability to discover and enumerate their operational agents will find themselves unable to achieve regulatory compliance.
Maintaining Continuous Visibility
The manual approaches that allowed security teams to track fifty software agents through static spreadsheets and periodic quarterly reviews inevitably collapse once an organization scales to five hundred. In modern enterprises, reaching five hundred agents is often just one routine product update away from expanding to five thousand.
To cope with this velocity, organizations are moving toward continuous visibility solutions that provide real-time answers regarding what software is operating, what permissions each agent has inherited, what resources it can reach across complex chains, and how its operational behavior has shifted over time. Platforms like the Reco Graph are emerging to address this challenge by mapping human and non-human identities, software applications, permission grants, and agent actions into a single live operational view, allowing security teams to treat environmental reach as the primary unit of analysis.
Having spent the past decade developing defenses for the intentional AI implementations chosen directly by business leadership, the cybersecurity industry now faces a much larger population of agents that arrived without explicit approval. Comprehensive analysis, such as the six-chapter research series Into the Expanse, continues to explore the origins of these autonomous systems, effective governance frameworks, emerging threat actor tactics, and strategic budgeting priorities for enterprise security leaders navigating the expansion of the agentic web.
