The 2026 State of Agent Security Report found that roughly 1,280 third-party products now embed AI, yet only about 282 of them sit behind single sign-on. The rest are invisible to identity infrastructure not because they are hidden, but because identity stacks can only govern what authenticates through them—and most agents never do. Traditional AI security assumed a company deliberately chose a model, deployed a gateway, and could point controls at that decision. Agents skip that moment: they arrive inside software the enterprise already runs, without a review, a surface to instrument, or an owner to name.
Security leaders tend to sort agents into bought and built, but the largest category is inherited—agents shipped inside existing platforms via product updates. Configured agents, built on someone else's runtime and connectors, are also widespread. Only built agents, on enterprise-owned infrastructure, have a repo to scan and a build to gate. Regardless of origin, all agents end up executing in the enterprise application layer, reading data warehouses, writing to ticketing systems, and holding tokens across SaaS tools—a layer with no fixed edges.
The article proposes four questions that work on any agent: identity (is it registered and owned by a named human?), permissions (what did it inherit, and was that deliberate?), connectivity (what can it reach directly and transitively?), and activity (is its behavior normal?). Connectivity is where agent security diverges from existing tools: a vendor questionnaire, prompt filter, or model scanner evaluates an agent in isolation, but reach is a property of the environment. Pressure is building from buyers like JPMorgan Chase's global CISO, who has called agents a supply-chain risk, and from the EU AI Act, which presumes enterprises can inventory their AI systems and name their owners.
Spreadsheets and quarterly reviews collapse at scale, so the article argues for a live, continuously refreshed map of what each agent is operating, what it inherited, what it can reach, and how that changed since yesterday. Platforms like Reco's Reco Graph aim to provide exactly that, connecting human and non-human identities, applications, permissions, and agent actions into a single view where reach—not configuration—is the unit of analysis.