VYPR
researchPublished Oct 10, 2026· 1 source

Third-Party AI Agents Pose Unseen Security Risks Beyond Traditional Controls

A new report reveals that over a thousand third-party AI agents embedded in enterprise software operate outside standard security and identity management, creating significant blind spots.

A recent analysis, detailed in the 2026 State of Agent Security Report, has identified a substantial security challenge emerging from the proliferation of third-party AI agents. The study found approximately 1,280 products that embed AI agents, with a striking majority of over a thousand operating without the benefit of traditional identity and access management (IAM) controls. This lack of visibility stems from the agents' independent authentication methods, which bypass existing identity infrastructure, leaving organizations vulnerable to unseen risks.

The security industry has largely focused on "first-party" AI problems, where organizations intentionally select, deploy, and secure AI models within their own controlled environments. However, the rise of third-party agents represents a fundamental shift. These agents are often integrated into existing software through product updates or are configured by enterprises using external platforms, meaning they arrive without a deliberate procurement or security review process. This bypasses critical security checkpoints like model scanning, prompt inspection, and the establishment of acceptable-use policies, as there is no clear adoption moment for security teams to intervene.

Agents can enter an enterprise through three primary vectors: inherited, configured, and built. Inherited agents are the most prevalent, arriving as part of software updates from vendors. Configured agents are custom prompts and logic run on third-party infrastructure. Built agents, the least common, are developed on infrastructure fully owned by the enterprise. The first two categories, which are growing rapidly as major applications become agent platforms, bypass traditional security measures like code scanning and build gating, as the agent's core components are managed externally.

Regardless of their origin, these agents converge on the enterprise application layer, where they can access and manipulate data across various systems. An agent embedded in a CRM might end up reading a data warehouse and writing to a ticketing system, while an agent assembled on a cloud platform could gain access to sensitive data in Salesforce, Slack, and Google Drive. This broad reach within the interconnected enterprise application layer creates complex security challenges with no fixed boundaries.

To address these risks, security leaders are advised to ask four critical questions about any agent: its identity (is it registered and attributable?), its permissions (are its inherited scopes and roles appropriate?), its connectivity (what systems can it reach directly and transitively?), and its activity (is its behavior consistent with its intended function?). The report emphasizes that the most significant risks often lie not in the AI model itself, but in the scaffolding that enables it to act as an autonomous entity and the ecosystem it interacts with.

Connectivity, in particular, is highlighted as a key differentiator from traditional security assessments. While vendor questionnaires, prompt filters, and model scanners evaluate agents in isolation, their true reach and potential blast radius are properties of the environment in which they operate. Understanding this environmental context is crucial for effective risk management.

Major organizations and regulators are already recognizing these threats. JPMorgan Chase's CISO has identified third-party agents as a systemic supply chain risk, advocating for agents to have identities but no default entitlements. Similarly, the EU AI Act's upcoming obligations presume enterprises can inventory and oversee their AI systems, making agent enumeration a compliance necessity. The report suggests that a robust security capability for AI agents requires continuous, live monitoring of their operations, inherited access, reach, and behavioral changes, moving beyond static assessments.

The current market is beginning to respond with solutions designed for this new landscape. Platforms are emerging that provide a continuously refreshed map of AI agent activity, including their inherited access, direct and transitive reach, and operational changes. This proactive and dynamic approach is essential to manage the evolving threat posed by third-party AI agents and ensure they do not become a significant blind spot in enterprise security strategies.

Synthesized by Vypr AI