Science & Tech · Cybersecurity · 1 day ago
Most Third-Party AI Agents Fall Outside Single Sign-On Controls
Many companies now use AI agents built into software they already have, even if they did not choose or formally deploy those agents.
A 2026 security report found about 1,280 third-party products with embedded AI, and roughly 282 of them sit behind single sign-on.
The rest are generally outside identity systems because they do not authenticate through them.
Agents can be built into existing platforms, configured by companies on someone else’s technology, or built on infrastructure the company controls.
The concern is that agents may reach across business systems, such as reading data in one service and making changes in another.
The security analysis says companies should review each agent’s identity, permissions and connections, rather than focusing only on the AI model.
It does not describe a specific next step or deadline for addressing the gap.
Roughly 1,280 third-party products in environments studied for the 2026 State of Agent Security Report now embed AI.
About 282 of those products sit behind single sign-on, while the other thousand are not covered by identity infrastructure by default.
The article says most agents arrive inside software companies already use, without a separate adoption decision.
It describes inherited and configured agents as the largest forms of adoption, while built agents are the smallest and slowest-growing category.
The article says agents can reach across enterprise applications, making identity, permissions and connectivity important areas for review.
- Who
- Companies using third-party products with embedded AI.
- What
- Most of the products studied are not behind single sign-on and are invisible to identity infrastructure by default.
- When
- The study concerns environments covered by the 2026 State of Agent Security Report. The article was published on 2026-10-10.
- Where
- Enterprise software environments.
- Why
- Most agents do not authenticate through companies’ identity infrastructure, according to the article.
This story does not have two clearly opposing sides.
inherit Slack's built-in security model, permissions, and admin controls from day one, without any additional IT lift
Salesforce launched Slack Code, which lets users tag a coding agent into a conversation.
The Hacker News published its report on third-party AI agents and identity controls.
- Products studied
- Roughly 1,280 third-party products embed AI
- Behind single sign-on
- About 282 products
- Outside identity infrastructure
- About 1,000 products
- Report
- 2026 State of Agent Security Report
- Example launch
- Slack Code, launched in August 2026











