Security experts warn of risks from third-party AI agents embedded in enterprise software

Published:

Security experts are raising alarms about the risks associated with third-party AI agents embedded in enterprise software, as highlighted in the 2026 State of Agent Security Report. The report reveals that approximately 1,280 third-party products now incorporate AI, with around 282 of these operating behind single sign-on systems. However, the majority remain invisible to identity infrastructure, posing significant security challenges as organizations often lack visibility and control over these agents.

The Shift in AI Security Paradigms

Traditionally, “AI security” focused on first-party solutions where organizations actively selected and deployed AI models. In contrast, third-party agents often integrate into existing software without explicit user decisions, complicating security oversight. For instance, Salesforce’s Slack Code allows users to introduce coding agents into conversations, which can autonomously interact with production environments without prior approval from security teams. This lack of a defined adoption moment creates vulnerabilities that security controls are ill-equipped to address.

Understanding Agent Risks

Experts categorize agents into three main types: bought, built, and inherited. The latter, which includes agents that come embedded within existing platforms, represents the largest and fastest-growing segment. These agents can access sensitive data and systems, raising concerns about their permissions and connectivity. Security leaders are urged to ask critical questions regarding the identity of these agents, their permissions, connectivity, and actual activities to assess their risk effectively.

Regulatory Implications and Industry Response

As the risks associated with third-party agents become more apparent, regulatory bodies are beginning to take action. The EU AI Act, set to phase in through 2026, requires organizations to inventory their AI systems and demonstrate oversight. This regulatory pressure is prompting companies to scrutinize their use of agents more closely, particularly as high-profile organizations like JPMorgan Chase have identified third-party agents as systemic risks in their supply chains.

Moving Towards Proactive Security Measures

To manage the growing complexity of agent security, organizations are encouraged to adopt continuous monitoring solutions that provide real-time insights into agent activities and their permissions. Platforms like Reco are emerging to offer comprehensive visibility into the interactions between human and non-human identities, applications, and permissions, enabling organizations to better understand and mitigate risks associated with third-party AI agents.

As the landscape of enterprise software evolves, the need for robust security measures that account for both chosen and inherited AI agents is becoming increasingly critical. The industry must adapt to these changes to safeguard sensitive data and maintain compliance with emerging regulations. For further insights, refer to The Hacker News.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

CrowdStrike partners with Anthropic to enhance AI-driven defenses for critical infrastructure security

In a significant move to bolster defenses for critical infrastructure, CrowdStrike has partnered with Anthropic to enhance AI-driven security measures. This collaboration aims to...

FBI arrests Edward Dubrovsky, co-founder of ransomware negotiation firm, amid ShinyHunters investigation

On October 8, the FBI arrested Edward Dubrovsky, co-founder of the Canadian cybersecurity firm CyberSteward, in Pennsylvania amid an investigation into the ShinyHunters hacking...

Prasan Nepal, leader of child sextortion group 764, pleads guilty to exploitation charges

A 21-year-old from North Carolina, Prasan Nepal, has pleaded guilty to conspiracy to commit sexual exploitation of a child, marking a significant development in...

Coast Guard orders four MQ-9B SeaGuardian drones for $248 million to enhance maritime surveillance capabilities

In a significant move to enhance its maritime surveillance capabilities, the U.S. Coast Guard has placed an order for four MQ-9B SeaGuardian drones, valued...