Third-party AI agents expose a growing identity governance gap

Enterprise security teams face a growing governance gap as third-party software adds AI agents without a distinct adoption decision. The 2026 State of Agent Security Report examined environments containing roughly 1,280 third-party products with embedded AI, yet only about 282 were behind single sign-on. The remaining products are typically outside identity infrastructure because they do not authenticate through it.
The issue changes the assumptions behind conventional AI security programmes. Those programmes generally begin when an organisation selects a model, buys licences, deploys a gateway or formally approves a tool. That decision point gives security teams an owner, a review process and a surface on which to apply controls. Agents embedded in existing enterprise applications can bypass that sequence.
Agents can arrive through existing software
The article identifies three routes by which agents enter an organisation. Inherited agents are introduced in updates to platforms already in use. Configured agents use an enterprise's prompts and logic while running on a provider's runtime, models and connectors. Built agents use open frameworks on infrastructure owned end to end by the enterprise.
Inherited and configured agents account for most adoption, while built agents are the smallest and slowest-growing category. They can nevertheless converge on the same application layer. An agent originating in a CRM may read a data warehouse and write to a ticketing system, while an agent assembled on a cloud platform may hold tokens for Salesforce, Slack and Drive.
Salesforce's Slack Code, launched in August 2026, illustrates the change. Users can tag a coding agent into a conversation, where it reads the shared context, writes code and opens a pull request. Salesforce says the agents inherit Slack's built-in security model, permissions and administrative controls without additional IT work. The governance boundary therefore depends on a chat platform's memberships even when the agent can interact with GitHub and production infrastructure.
Review the actor and its reach
The report argues that the model itself is only one part of an agent. The surrounding scaffolding determines what an agent is connected to, which tools it may call and when it can act. It recommends assessing four areas: identity, permissions, connectivity and activity.
- Identity: establish whether the agent is registered and whether a named person owns it.
- Permissions: determine which roles and OAuth scopes it inherited and whether they exceed what it requires.
- Connectivity: map what it can reach directly and through connected applications, grants, data stores and other agents.
- Activity: evaluate observed behaviour rather than relying on the description in a prompt.
Connectivity is particularly difficult to establish from an agent's own configuration page. Vendor questionnaires, prompt filters and model scanners evaluate an agent in isolation, whereas reach is a property of the wider environment. The article describes this as the agent's blast-radius question.
Inventory and oversight become operational requirements
Patrick Opet, global CISO of JPMorgan Chase, has described third-party supply chains as a systemic risk and has extended that scrutiny to agents. His preferred model is for an agent to receive an identity but no entitlements by default, with IT confirming whom it represents before it accesses anything beyond that boundary.
The EU AI Act's obligations phasing in through 2026 also assume that enterprises can inventory AI systems, identify owners and demonstrate oversight. A spreadsheet review conducted quarterly cannot provide a continuously current account as agent numbers rise through software updates.
For businesses, the practical implication is to operate an ongoing inventory that records each agent, its owner, inherited permissions, direct and transitive connections, activity and changes over time. That approach shifts assessment from isolated configurations to the access an agent can exercise across the enterprise.

