Full Report
In environments studied for the 2026 State of Agent Security Report, roughly 1,280 third-party products now embed AI. About 282 of them sit behind single sign-on. The other thousand are invisible to identity infrastructure by default, not because anyone hid them, but because an identity stack can only govern what authenticates through it, and most agents never do. That gap is the clearest
Analysis Summary
# Industry News: The Rise of "Inherited" AI Agents and the Identity Governance Gap
## Summary
The **2026 State of Agent Security Report** reveals a massive visibility gap in enterprise AI, where over 1,000 third-party AI agents operate outside traditional identity infrastructure. These "inherited agents" ship within existing software updates (e.g., Salesforce’s Slack Code), bypassing the standard procurement and security review cycles typically applied to first-party AI models.
## Key Details
- **Date:** October 10, 2026
- **Companies Involved:** Salesforce (Slack), JPMorgan Chase (cited for supply chain stance), and various enterprise SaaS providers.
- **Category:** Industry Report / Market Analysis / Cybersecurity Trend
## The Story
The cybersecurity landscape has shifted from "built" AI (models developed in-house) to "inherited" agents—AI capabilities that arrive via product updates in platforms the enterprise already uses. Of the ~1,280 third-party AI products studied, roughly 80% (1,000 products) are invisible to identity stacks because they do not require a separate authentication event.
A primary example is **Slack Code**, which allows users to tag agents into conversations to write code and open pull requests. While Salesforce markets this as inheriting existing permissions, security analysts warn this creates autonomous actors with access to critical infrastructure (like GitHub) governed only by channel membership, rather than rigorous identity controls. The report highlights that the risk is not in the AI model itself, but in the "scaffolding"—the connections and permissions that allow the agent to act across different software ecosystems.
## Business Impact
### For the Companies Involved
- **SaaS Vendors (Salesforce, etc.):** Facing pressure to balance "frictionless" AI deployment with the need for granular administrative controls.
- **JPMorgan Chase & Large Enterprises:** Leading the charge in treating third-party agents as systemic supply-chain risks, potentially leading to stricter vendor requirements.
### For Competitors
- **Security Vendors:** A new market is emerging for "Agent Security" tools that can discover and map transitive connectivity, as traditional CASB and SSO solutions are proving insufficient.
### For Customers
- **Enterprises:** Increased risk of "shadow AI" where employees use powerful autonomous tools without IT's knowledge, potentially leading to unauthorized data exfiltration or privilege escalation.
### For the Market
- **Standardization:** The industry is moving toward a four-pillar review framework for agents: Identity, Permissions, Connectivity, and Activity.
## Technical Implications
The core technical challenge is **transitive connectivity**. An agent born in one application (CRM) can inherit OAuth scopes that allow it to read from data warehouses and write to ticketing systems. Traditional security gates (model scanning, prompt filtering) fail because they evaluate the agent in isolation rather than as an actor within a connected environment.
## Strategic Analysis
- **Market Positioning:** Organizations like JPMorgan Chase are positioning themselves as "security-first" by treating AI agents as potential insider threats.
- **Competitive Advantage:** SaaS providers who offer transparent "agent governance" dashboards will likely win over highly regulated enterprise customers.
- **Challenges:** The "identity dark matter" crisis—where agents run as the user who built them or as silent system processes—makes it nearly impossible to maintain a "least privilege" architecture.
## Industry Reactions
- **Patrick Opet (CISO, JPMorgan Chase):** Has signaled that the third-party supply chain, now complicated by agents, is a systemic risk requiring isolation of compromised suppliers.
- **Security Analysts:** Note that the "decision point" for security (the moment of procurement) has vanished, leaving security teams to react to features they didn't know were deployed.
## Future Outlook
- **Predictions:** By late 2026/2027, expect a surge in "Agent Governance" platforms that focus specifically on the "scaffolding" and blast-radius of autonomous AI.
- **Watch For:** Regulations or industry standards (like an updated SOC2) that specifically address autonomous agent permissions and audit logs.
## For Security Professionals
Practitioners must move beyond filtering prompts and start auditing the **reach** of agents. Key action items include:
1. Identifying which existing SaaS tools have recently toggled on "autonomous" features.
2. Mapping the OAuth scopes held by agents to ensure they don't have write-access to production environments via chat tools.
3. Transitioning from "Model Security" to "Agent Scaffolding Security."