Your Biggest AI Risk May Be the Agents Nobody Approved
Most organizations can tell you which AI tools they chose to buy. Far fewer can tell you which AI agents are already running inside the software they use every day. A new vendor-led analysis argues that this second group is now the larger one, and that most security programs still cannot see it.
What was reported
The figures come from Reco's 2026 State of Agent Security Report, covered in a sponsored analysis on The Hacker News. In the environments Reco studied, about 1,280 third-party products now include AI features. Only around 282 of those sit behind single sign-on. The rest are outside the view of identity tooling. Nobody hid them. Identity systems can only govern what logs in through them, and most embedded agents never do.
Treat the numbers as one vendor's view of its own customer base, not as an industry-wide census. The pattern they point to still matches what we see in practice.
Why the old playbook falls short
Today's "AI security" tooling assumes there was a moment of decision. Someone picked a model, set up a gateway, signed a license, wrote a policy. That moment gave security something to review, something to instrument and someone to hold accountable.
Agents often skip that moment. They arrive through a routine product update, already connected to data. The analysis gives one example: a chat-based coding agent that can be tagged into a conversation, read the context, write code and open a pull request. In practice, its governance amounts to whoever is in the channel.
The piece sorts agents into three groups:
- Inherited. Shipped inside platforms you already use.
- Configured. Your prompts and logic running on someone else's runtime, model and connectors.
- Built. Frameworks you host end to end.
Only the last group has a repository to scan and a pipeline to gate. The first two make up most adoption and are growing fastest.
Why it matters
Wherever they come from, agents end up in the same place: the enterprise application layer. An agent that starts in a CRM can end up reading a data warehouse. A low-code agent can hold tokens for email, file storage and chat. Reach, meaning everything an agent can touch directly or through other systems, is a property of your environment. A vendor questionnaire or a prompt filter that looks at the agent alone will miss it.
Pressure is also coming from outside:
- Large buyers. JPMorgan Chase's CISO publicly called third-party software a systemic supply-chain risk in 2025 and has since applied that thinking to agents. His position is that agents should get an identity with no default entitlements. Expect the same questions in your customers' security questionnaires.
- Regulators. EU AI Act obligations phasing in through 2026 assume you can list your AI systems, name an owner for each and show oversight. If you can't count your agents, you will struggle to comply.
What to do
- Inventory beyond SSO. Use OAuth grant reviews, SaaS admin consoles and API-token audits to find agents and AI features that never authenticate through your identity provider.
- Ask four questions about every agent:
- Identity: Is it registered, and does a named person own it?
- Permissions: What scopes and roles did it inherit, and did anyone approve them on purpose?
- Connectivity: What can it reach, directly and through other apps, data stores and agents? This is its blast radius.
- Activity: Is what it actually does normal for its role? Judge it by behavior, not by its description.
- Default to least privilege. Give new agents an identity but no standing entitlements. Make access a deliberate decision.
- Watch vendor release notes. Treat "now with AI agents" in a SaaS update as a change request that needs a security review.
- Make discovery continuous. Spreadsheets and quarterly reviews work for a few dozen agents. They do not work for hundreds. Monitor grants and behavior on an ongoing basis.
- Get ready for the questions. Prepare an agent inventory and ownership record now, for customer due diligence and for EU AI Act evidence.
Credit: based on reporting by The Hacker News (sponsored content by Reco, drawing on Reco's 2026 State of Agent Security Report). Analysis and recommendations are 4Tify's own.
