[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5pmtCyhh3b4iLDOSr9b0i_6D1gEYXnamzIuMgzbOiRM":3},{"article":4,"iocs":45},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"4e90f327-3088-4529-806b-1f6939c7dcd1","The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn't","the-third-party-agent-problem-why-security-built-for-ai-you-chose-misses-the-age-6966a6","In environments studied for the 2026 State of Agent Security Report, roughly 1,280 third-party products now embed AI. About 282 of them sit behind single sign-on. The other thousand are invisible to identity infrastructure by default, not because anyone hid them, but because an identity stack can only govern what authenticates through it, and most agents never do. That gap is the clearest","A new report highlights that a significant number of third-party AI agents embedded in enterprise software are not visible to existing identity and security infrastructure. These 'inherited' agents, often bundled within existing applications, bypass traditional security review processes, creating a blind spot for organizations. The article emphasizes that security risks lie not in the AI models themselves, but in the scaffolding and ecosystem that grant these agents access and permissions.","Many third-party AI agents in enterprise software are invisible to security controls.","The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn't The Hacker NewsOct 10, 2026Artificial Intelligence \u002F Enterprise Security In environments studied for the 2026 State of Agent Security Report, roughly 1,280 third-party products now embed AI. About 282 of them sit behind single sign-on. The other thousand are invisible to identity infrastructure by default, not because anyone hid them, but because an identity stack can only govern what authenticates through it, and most agents never do. That gap is the clearest expression of a shift the security industry is only starting to name. For several years, \"AI security\" solved a first-party problem: the company decided to use AI, procured licenses, deployed a model behind a gateway, and security pointed controls at the thing the business had chosen. Agents do not arrive that way. They arrive inside software the enterprise already runs, and they arrive without a decision. Why the decision point mattered more than the controls Every control in the first-party toolkit assumes a moment exists: model scanning assumes a model was selected, prompt inspection assumes a gateway was deployed, an acceptable-use policy assumes there was an adoption to accept. That moment gave security a review, a surface to instrument, and an owner to name. Agents skip the moment. Salesforce's Slack Code, launched in August 2026, lets a user tag a coding agent into any conversation; the agent reads the shared context, writes the code, and opens the pull request. The announcement promises agents \"inherit Slack's built-in security model, permissions, and admin controls from day one, without any additional IT lift.\" Read by a security team, that sentence describes an autonomous actor with reach into GitHub and production infrastructure whose governance is a chat tool's channel membership. There was nothing to instrument, because nothing was adopted. Three launch vectors, one destination Security leaders tend to sort agents into two buckets: bought and built. There is a third, and it is the largest. Inherited agents ship inside existing platforms via product updates. Configured agents are an enterprise's own prompts and logic running on someone else's runtime, model, and connectors. Built agents are open frameworks on infrastructure the enterprise owns end to end. The first two account for the overwhelming majority of adoption and are growing exponentially as every major application becomes an agent platform. The third is the smallest and slowest growing, and it is the only one with a repo to scan and a build to gate. The destination is the same regardless of origin. An agent born in a CRM ends up reading a data warehouse and writing to a ticketing system. An agent assembled on a cloud platform ends up holding tokens into Salesforce, Slack, and Drive. The enterprise application layer is where they all execute, and it has no fixed edges. Four questions that work on any agent Every agent has two parts: the model that reasons and the scaffolding around it that turns a model into an actor, deciding what it is wired to, what it may call, and when it acts. Almost none of the risk lives in the model. It lives in the scaffolding and the ecosystem the scaffolding sits inside. Four questions cover it, and none of them ask what the model would do on its own. Area to review What it looks like in practice Identity Is the agent registered anywhere? Does a named human raise a hand when asked \"whose is this?\" Or does it silently run as whoever built it? Permissions What is it allowed to do, and is that more than it needs? Whose OAuth scopes and roles did it inherit at creation, and did anyone decide that on purpose? Connectivity What can it reach, directly and transitively, through the products, grants, data stores, and other agents it touches? This is the blast-radius question, and it is rarely answerable from the agent's own configuration screen. Activity What is it actually doing, and is that normal for what it is? Judged by behavior, not by the description in its prompt. The Connectivity row is where agent security separates from everything the market already sells. A vendor questionnaire, a prompt filter, and a model scanner all evaluate an agent in isolation. Reach is a property of the environment. The buyers with the most influence have already moved Patrick Opet, global CISO of JPMorgan Chase, told the software industry in 2025 that the third-party supply chain had become a systemic risk, citing incidents serious enough that the bank had to isolate compromised suppliers in an open letter to the industry. He has since applied the same scrutiny to agents: ideally, an agent gets an identity but no entitlements by default, and IT confirms who it acts on behalf of before it touches anything outside that boundary. When a buyer of that size names agents as a supply-chain risk, the question shows up in everyone else's security questionnaires within a few quarters. Regulators are moving on the same assumption. The EU AI Act's obligations phasing in through 2026 presume an enterprise can inventory its AI systems, name their owners, and evidence oversight. An organization that cannot enumerate its agents cannot comply. What a standing capability looks like The approach that keeps up with fifty agents through spreadsheets and quarterly reviews collapses at five hundred, and five hundred is one product update away from five thousand. What replaces it is a live answer, continuously refreshed, to what is operating, what each agent inherited, what it can reach directly and through chains, what it is doing, and how all of that changed since yesterday. Some platforms are now built around exactly that map. One leading example is Reco, whose Reco Graph connects every human and non-human identity, application, permission, and agent action into a single live view so that reach, not configuration, is the unit of analysis. The industry spent a decade building security for the AI enterprises decided to use. The agents they did not decide on are now the larger population. The six-chapter series this analysis draws on, Into the Expanse, covers where they come from, how to govern them, how attackers use them, where runtime belongs, and what to fund first. Learn more about Reco's agent discovery at reco.ai\u002Fplatform. \u003Cimg alt=\"\" height=\"1\" src=\"https:\u002F\u002Fpx.ads.linkedin.com\u002Fcollect\u002F?pid=4587841&amp;fmt=gif\" style=\"display:none;\" width=\"1\" \u002F> Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, enterprise security, Identity Security, SaaS Security, Supply Chain ⚡ Top Stories This Week ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Apple CoreGrap","https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fthe-third-party-agent-problem-why.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEghemGbtxM2amUYAlxUPHPdMiyDMQJFWZeY-dDODRqCRD0phZXXQv0rrKHiOsLPW3t0Fq2XxvvFyCC-OmNs7TXhXXKSRVMPpC1GPKSUsyzN9t-W6L4jtiA2DUiTLgou4iyw0QXN-6Wfz0H2zWYGgC6-OxtlQrfb0PygOeBWwDnR11nl3Gl8W5pL07sExNc\u002Fs1600\u002Freco.gif","2026-10-10T11:00:00+00:00","2026-10-10T12:00:17.833435+00:00",7,[18,21,24],{"name":19,"type":20},"Slack Code","product",{"name":22,"type":23},"Salesforce","vendor",{"name":25,"type":26},"AI","technology","839da5c1-3c34-47e2-9499-f7201640e3ac",{"id":27,"icon":29,"name":30,"slug":31},null,"AI Security","ai-security",[33,38,43],{"category":34},{"id":35,"icon":29,"name":36,"slug":37},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":39},{"id":40,"icon":29,"name":41,"slug":42},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":44},{"id":27,"icon":29,"name":30,"slug":31},[]]