A new industry analysis, the 2026 State of Agent Security Report, has quantified a problem security teams have long suspected but rarely measured: most AI agents running inside enterprise environments were never chosen, provisioned, or even seen by the identity infrastructure meant to govern them.

Across the environments studied, researchers identified roughly 1,280 third-party products that now embed AI capabilities. Of those, only about 282, roughly a fifth, sit behind single sign-on (SSO). The remaining approximately 1,000 products operate entirely outside identity visibility by default.

Not a Cover-Up, a Blind Spot

The report is careful to note that this gap isn’t the result of deliberate concealment. Identity and access management stacks can only govern what actually authenticates through them. Many AI agents embedded in third-party software never go through that authentication path at all, whether because they operate via API keys, service accounts, embedded credentials, or integrations that sidestep centralized login entirely.

The result is a structural blind spot: security programs built around vetting and monitoring the AI tools an organization deliberately adopts are missing the much larger population of AI agents that arrive bundled inside other software, unmonitored and ungoverned.

Why This Matters for Defenders

For security teams, the implications are significant. Traditional AI governance programs tend to focus on sanctioned tools, chatbots, copilots, and platforms that IT explicitly rolled out. But this data suggests that approach only covers a small fraction of the actual AI footprint inside most organizations.

Agents operating outside SSO can still read data, call internal APIs, and make decisions, often with privileges inherited from whatever service account or embedded credential they use. Without visibility into these agents, security teams cannot assess what data they touch, what actions they can take, or whether they’ve been compromised.

The Takeaway

The report’s core finding reframes AI risk management as fundamentally an identity and asset discovery problem, not just a policy problem. Organizations that assume their AI governance covers their actual AI exposure may be operating with a dramatically incomplete picture. Security teams should prioritize discovering embedded AI agents across third-party software inventories, rather than relying solely on SSO logs or sanctioned-tool lists to understand their AI attack surface.