Hidden AI Agents Are Arriving Inside Your Business Software, and Most Security Tools Cannot See Them
The 2026 State of Agent Security Report studied a range of business environments and found roughly 1,280 third-party products that now embed AI. Only about 282 of them sit behind single sign-on. The remaining thousand or so are invisible to identity tools by default. Nobody hid them; identity systems can only govern what signs in through them, and most agents never do.
The report argues that earlier AI security assumed a business chose its AI, bought licences and placed a model behind a gateway. Agents do not arrive that way. They show up inside software a company already uses, through product updates, with no adoption decision. As an example, the article points to Salesforce's Slack Code, launched in August 2026, which lets a user tag a coding agent into any conversation. The agent reads shared context, writes code and opens a pull request. Slack says agents inherit its permissions and admin controls, but the article notes this means an autonomous actor with reach into GitHub and production systems is governed only by channel membership.
The article describes three kinds of agents: inherited (shipped inside existing platforms), configured (a company's own prompts and logic running on someone else's platform) and built (open frameworks on infrastructure the company owns). The first two make up most adoption and are growing fast. Built agents are the smallest group, yet the only ones with a code repository to scan and a build process to gate.