As artificial intelligence shifts from a tool that humans actively direct to an autonomous actor embedded deep within enterprise software, corporate security teams are facing an unprecedented blind spot. According to findings highlighted in the 2026 State of Agent Security Report, roughly 1,280 third-party products now embed artificial intelligence across the studied corporate environments. Out of that total, approximately 282 sit comfortably behind traditional single sign-on (SSO) gateways.
However, the remaining thousand products operate entirely invisibly to standard identity infrastructure by default. This obscurity is rarely the result of intentional concealment; rather, it stems from a fundamental structural limitation. An enterprise identity stack can only govern what explicitly authenticates through it, and the vast majority of modern AI agents never interact with those core verification gates.
This widening visibility gap highlights a profound structural shift in cybersecurity—one that the industry is only beginning to conceptualize and name. For several years, the paradigm of "AI security" addressed a straightforward, first-party challenge. An enterprise would consciously decide to adopt artificial intelligence, procure the necessary software licenses, deploy a centralized model behind a secured gateway, and direct security controls toward the specific asset the business had deliberately chosen to acquire.
Autonomous agents, by contrast, do not arrive through traditional procurement pathways. They emerge silently inside software applications the enterprise is already running, integrated via routine product updates, and deployed without a centralized, top-down business decision.
Why the Decision Point Mattered More Than the Controls
Historically, every single control within the conventional first-party security toolkit relied on a distinct, identifiable moment of adoption. Model scanning presumed that a specific foundational model had been consciously selected by engineering teams. Prompt inspection assumed that a dedicated enterprise gateway had been formally deployed. Acceptable-use policies assumed there was a clear, deliberate adoption milestone for the organization to review and govern.
That critical moment of introduction provided security professionals with a formal review process, a physical surface area to instrument, and an accountable asset owner to name. Autonomous agents bypass that vital moment entirely.
Consider the operational reality introduced by platforms like Salesforce’s Slack Code, which allows any standard user to tag a coding agent into an active, ongoing workspace conversation. The agent immediately reads the shared contextual history, writes the underlying code, and initiates a pull request. Official product announcements typically market these capabilities with reassuring phrasing, noting that agents inherit the host platform’s built-in security model, user permissions, and administrator controls from day one, requiring no additional IT configuration or overhead.
Read from the perspective of an enterprise security team, however, that exact capability describes an autonomous software actor equipped with direct, programmatic reach into GitHub repositories and core production infrastructure whose ultimate governance relies entirely on a chat tool’s channel membership. Because the agent was embedded seamlessly via a platform update, there was nothing for security teams to instrument, review, or intercept, simply because there was no formal adoption cycle to monitor.
Three Launch Vectors, One Destination
Security leaders have traditionally attempted to categorize artificial intelligence initiatives into two neat buckets: solutions they buy or solutions they build internally. Yet, a third category exists, and it has rapidly expanded to become the largest vector of enterprise AI adoption.
Inherited agents ship directly inside existing, trusted enterprise platforms via routine product updates and feature rollouts. Configured agents represent an enterprise’s custom prompts and internal logic operating on top of external runtimes, foundational models, and third-party data connectors. Built agents, meanwhile, consist of open frameworks deployed on infrastructure that the enterprise owns and controls from end to end.
The first two categories account for the overwhelming majority of real-world AI adoption, growing exponentially as every major enterprise application evolves into an agentic platform. The third category, built agents, remains the smallest and slowest-growing segment, yet it happens to be the only one equipped with a traditional code repository to scan and a formal build pipeline to gate.

Despite their diverse origins, these agents all converge on the same operational destination. An artificial intelligence agent born inside a customer relationship management platform inevitably ends up reading enterprise data warehouses and writing updates to ticketing systems. Similarly, an agent assembled on a cloud development platform frequently winds up holding active authentication tokens for disparate tools like Salesforce, Slack, and cloud storage drives. The modern enterprise application layer serves as the common execution environment for all of these systems, and it currently possesses no fixed, enforceable perimeter.
Evaluating Agents Beyond the Model
Every functional agent consists of two primary components: the foundational model that performs the core reasoning, and the surrounding technical scaffolding that transforms a static model into an active agent, dictating what systems it can connect to, what Application Programming Interfaces it may call, and when it is permitted to take action.
Practically speaking, almost none of the genuine security risk resides within the model itself. The vulnerability lives within the scaffolding and the complex digital ecosystem in which that scaffolding operates. Evaluating an agent effectively requires moving past traditional questions about what a model might do in a vacuum and focusing instead on four core operational areas: identity, permissions, connectivity, and activity.
In terms of identity, security teams must determine whether an agent is properly registered anywhere within the organization, and whether a named human owner steps forward when questioned about its origins, or if it simply operates silently under the credentials of whoever originally deployed it. Permissions analysis requires uncovering what the agent is explicitly allowed to do, and whether those granted privileges exceed its operational necessity, including whose inherited OAuth scopes and roles it leverages.
Connectivity addresses the broader blast-radius question by examining what resources the agent can reach, both directly and transitively, through the applications, security grants, and data stores it touches—a property that is rarely discoverable from the agent’s native configuration screen. Finally, activity monitoring evaluates what the agent is actually executing in real time, assessing its behavior against operational norms rather than relying on the idealized descriptions outlined in its configuration prompts.
This focus on connectivity and reach is precisely what separates modern agent security from conventional software tools. Traditional vendor questionnaires, prompt filters, and model scanners evaluate individual agents in isolation, failing to account for the interconnected web of enterprise permissions.
Regulatory Pressures and Enterprise Leadership
Industry leaders are already adapting to these emerging realities at the highest levels. Patrick Opet, global Chief Information Security Officer of JPMorgan Chase, issued a public warning to the software industry regarding third-party supply chains becoming a systemic risk, citing serious incidents that forced the bank to forcefully isolate compromised suppliers. Opet has since applied that exact rigor to autonomous AI agents, advocating for a security posture where agents ideally receive an explicit identity but zero broad entitlements by default, requiring IT verification before interacting with any resources outside a tightly defined boundary. When a financial institution of that magnitude designates autonomous agents as a severe supply-chain risk, that standard quickly cascades into enterprise security questionnaires industry-wide.
Regulatory bodies are rapidly aligning with these expectations. The implementation milestones of the European Union Artificial Intelligence Act place direct compliance obligations on organizations, presuming that any modern enterprise can accurately inventory its artificial intelligence systems, designate clear ownership, and evidence continuous oversight. Any organization unable to comprehensively enumerate its active agents will find compliance nearly impossible to achieve.
Moving Toward Continuous Visibility
The traditional security approach of managing dozens of systems through static spreadsheets and periodic quarterly reviews collapses entirely when faced with hundreds of deployments, a figure that can easily multiply following a single software product update.
To maintain effective governance, organizations are transitioning toward live, continuously refreshed operational visibility. This capability provides real-time answers regarding what software is operating, what permissions each agent has inherited, what systems it can reach directly or transitively, what tasks it is actively executing, and how those parameters have shifted over time. Platforms like Reco have emerged to address this exact challenge, utilizing interconnected data models like the Reco Graph to unify human and non-human identities, software applications, permissions, and agent actions into a single, cohesive view where operational reach serves as the primary unit of analysis.
For over a decade, the cybersecurity industry focused its efforts on securing the specific artificial intelligence deployments that businesses consciously chose to procure and implement. Today, the unmanaged agents operating invisibly across enterprise software stacks represent a vastly larger and more complex population, demanding an entirely new approach to digital governance.
