The rapid proliferation of artificial intelligence has moved beyond the era of centralized, IT-approved model deployment. We have entered the age of the "Shadow Agent"—autonomous software entities that arrive not through procurement portals or security reviews, but via quiet updates to the SaaS platforms already woven into the fabric of the modern enterprise. According to findings from the 2026 State of Agent Security Report, this shift has created a massive blind spot: out of roughly 1,280 AI-embedded products identified in enterprise environments, nearly 80% operate entirely outside the visibility of standard identity infrastructure.
This is not a failure of oversight; it is a fundamental shift in how software is architected. Traditional security controls were built on the assumption that a company "decides" to use AI. Today, the agent decides to use the enterprise.
The Evolution of the "Decision Point" Problem
For years, the cybersecurity industry operated under a clear, linear model. Whether a company was deploying a custom large language model (LLM) or subscribing to an enterprise AI gateway, there was a defined "decision point." This moment allowed security teams to perform model scanning, implement prompt inspection, and mandate acceptable-use policies. It was a tangible surface area that could be instrumented and governed.
That era has effectively ended. The current generation of AI agents—integrated directly into ubiquitous tools like Slack, Salesforce, and enterprise ERP systems—bypasses the procurement process entirely. When a platform like Salesforce launches a feature like "Slack Code," it arrives as a native update. It inherits the host application’s permissions, channel memberships, and data access by default.
From a security perspective, this is a radical departure from traditional governance. There is no software to install, no vendor to vet, and no IT ticket to process. The agent is simply "turned on" by the platform provider. Consequently, security teams are tasked with managing autonomous actors that have read/write access to production environments, yet lack a formal audit trail or a designated owner within the organization.
Chronology of the Agent Proliferation
The trajectory of AI adoption has undergone three distinct phases, each moving further away from centralized control:
- The First-Party Era (2022–2023): Organizations manually deployed AI models behind gateways. Security teams focused on data leakage prevention (DLP) and model-level security, treating AI as a distinct, contained application.
- The "Configured Agent" Era (2024–2025): Enterprises began using low-code frameworks to connect their own internal logic and data to third-party APIs. While still largely internal, these agents introduced complexity regarding how data was being passed between systems.
- The "Inherited Agent" Era (2026–Present): We are currently witnessing the mass-market rollout of AI agents embedded directly into the "plumbing" of the enterprise. These agents are not built or bought; they are inherited. They are activated with a single click in existing software, meaning the growth of these entities is now tethered to the update cycles of major SaaS vendors, leading to exponential, unmanaged growth.
Supporting Data: The Anatomy of Risk
The 2026 State of Agent Security Report highlights a chilling statistic: of the 1,280 third-party products using AI, only 282 are governed by single sign-on (SSO). The remaining thousand exist in a "ghost state," where they interact with data stores, write to code repositories, and execute API calls without ever authenticating through the identity stack.
The Four Pillars of Agent Governance
Because the risk associated with agents resides primarily in the "scaffolding"—the connectors, roles, and permissions—rather than the LLM itself, security teams must pivot their evaluation criteria. The following four questions have become the gold standard for auditing an agent’s footprint:
- Identity: Is there a named human responsible for this agent, or is it running as a service account with broad, forgotten privileges?
- Permissions: Does the agent possess "permission bloat"? Are its OAuth scopes and roles tailored to its specific function, or has it inherited the maximum permissions of the user who enabled it?
- Connectivity: What is the "blast radius"? This requires mapping the agent’s reach across transitive connections—what it can touch, which other agents it can trigger, and what data it can export.
- Activity: Is the agent’s behavior anomalous? By comparing live activity against expected use-cases, teams can identify malicious behavior that prompt-based filters would completely miss.
The Industry Response: Moving Toward the "Graph"
Prominent security leaders, including JPMorgan Chase’s CISO Patrick Opet, have signaled that the third-party AI supply chain is now a systemic risk. The strategy is moving away from static questionnaires toward dynamic, real-time observability.

The limitation of traditional security products is their tendency to view an agent in isolation. A vendor questionnaire or a prompt scanner looks at what an agent says it will do. However, in a complex enterprise, an agent’s risk is defined by its environment—its connectivity. This has led to the rise of platforms like Reco, which utilize "graph-based" analysis. By mapping every human and non-human identity, along with every permission and action, these platforms create a living, breathing model of the enterprise ecosystem.
This shift is crucial because spreadsheets and quarterly reviews are mathematically incapable of keeping pace with the velocity of modern agent deployment. When an organization can go from 50 agents to 5,000 in a single product update, the only viable defense is a system that understands the context of connectivity, not just the configuration of the model.
Implications: A New Regulatory Reality
The regulatory landscape is rapidly catching up to this technological reality. The EU AI Act, with its phased implementation through 2026, places the burden of proof squarely on the enterprise. Companies are now legally obligated to maintain an inventory of their AI systems, name their owners, and provide evidence of ongoing oversight.
For the modern enterprise, this means "Shadow AI" is no longer just a technical debt issue—it is a compliance liability. Organizations that cannot enumerate their agents, or map their access to critical data stores, will find themselves in direct violation of evolving standards.
The Path Forward: Governing the Expanse
As we look toward the future, the security industry must accept that the perimeter has dissolved. The agents an enterprise did not "choose" are now the dominant population in its ecosystem.
Governing these agents requires a fundamental re-evaluation of what constitutes a security boundary. It is no longer enough to guard the front door with SSO and model scanning. Security teams must now implement "standing capabilities"—continuous, automated monitoring that tracks the entire life cycle of an agent: its origin, its entitlements, its connectivity, and its daily behavior.
The "Expanse"—the sprawling, interconnected web of SaaS-integrated agents—is where the next generation of security challenges will be fought. For those who cling to the legacy model of static reviews and procurement-based gatekeeping, the scale of this new environment will be overwhelming. For those who invest in dynamic, identity-centric, and graph-based visibility, the agent revolution represents an opportunity to secure the enterprise not by stopping innovation, but by mapping and governing the very fabric upon which it runs.
The era of manual governance is over. The era of the live, persistent, and autonomous security graph has begun. Organizations that fail to make this transition are not just leaving a door open; they are inviting a silent, intelligent actor into the heart of their production infrastructure.








