Security experts are raising alarms about the risks associated with third-party AI agents embedded in enterprise software, as highlighted in the 2026 State of Agent Security Report. The report reveals that approximately 1,280 third-party products now incorporate AI, with around 282 of these operating behind single sign-on systems. However, the majority remain invisible to identity infrastructure, posing significant security challenges as organizations often lack visibility and control over these agents.
The Shift in AI Security Paradigms
Traditionally, “AI security” focused on first-party solutions where organizations actively selected and deployed AI models. In contrast, third-party agents often integrate into existing software without explicit user decisions, complicating security oversight. For instance, Salesforce’s Slack Code allows users to introduce coding agents into conversations, which can autonomously interact with production environments without prior approval from security teams. This lack of a defined adoption moment creates vulnerabilities that security controls are ill-equipped to address.
Understanding Agent Risks
Experts categorize agents into three main types: bought, built, and inherited. The latter, which includes agents that come embedded within existing platforms, represents the largest and fastest-growing segment. These agents can access sensitive data and systems, raising concerns about their permissions and connectivity. Security leaders are urged to ask critical questions regarding the identity of these agents, their permissions, connectivity, and actual activities to assess their risk effectively.
Regulatory Implications and Industry Response
As the risks associated with third-party agents become more apparent, regulatory bodies are beginning to take action. The EU AI Act, set to phase in through 2026, requires organizations to inventory their AI systems and demonstrate oversight. This regulatory pressure is prompting companies to scrutinize their use of agents more closely, particularly as high-profile organizations like JPMorgan Chase have identified third-party agents as systemic risks in their supply chains.
Moving Towards Proactive Security Measures
To manage the growing complexity of agent security, organizations are encouraged to adopt continuous monitoring solutions that provide real-time insights into agent activities and their permissions. Platforms like Reco are emerging to offer comprehensive visibility into the interactions between human and non-human identities, applications, and permissions, enabling organizations to better understand and mitigate risks associated with third-party AI agents.
As the landscape of enterprise software evolves, the need for robust security measures that account for both chosen and inherited AI agents is becoming increasingly critical. The industry must adapt to these changes to safeguard sensitive data and maintain compliance with emerging regulations. For further insights, refer to The Hacker News.


