Ethical Hacking News
The Third-Party Agent Problem: Unveiling the Gap in AI Security
The security industry is grappling with a new challenge: third-party agents. These agents, which are now omnipresent in enterprise environments, are often overlooked. A new security paradigm is needed to address the risks associated with third-party agents. This article delves into the world of third-party agents, exploring the challenges, risks, and potential solutions to this growing problem.
The Third-Party Agent Problem refers to the gap in AI security where third-party agents, which are now omnipresent in enterprise environments, are often overlooked. Approximately 1,280 third-party products embed AI, with around 282 of them sitting behind single sign-on, while the other 1,000 are invisible to identity infrastructure by default. Third-party agents execute without a clear decision point, unlike first-party solutions, which were adopted with a moment of clarity. Security leaders sort agents into three categories: bought and built, inherited, and configured. The challenge lies in understanding the complex landscape of enterprise applications and addressing the security gaps that arise from it. Four questions can cover the risk associated with third-party agents: Area to review, Permissions, Connectivity, and Activity. Regulators are moving towards requiring enterprises to inventory their AI systems, name their owners, and evidence oversight. A new approach is needed to keep up with the growth of third-party agents, one that focuses on a live answer to what is operating, what each agent inherited, what it can reach directly and through chains, what it is doing, and how it has changed since yesterday.
The Third-Party Agent Problem: Unveiling the Gap in AI Security
In the realm of artificial intelligence (AI), the concept of security has evolved significantly over the past few years. What was once a first-party problem, where companies decided to adopt AI and security teams pointed controls at the chosen solution, has now shifted to a third-party problem. This shift has led to a significant gap in AI security, where third-party agents, which are now omnipresent in enterprise environments, are often overlooked.
According to a recent report, approximately 1,280 third-party products now embed AI, with around 282 of them sitting behind single sign-on. However, the other thousand are invisible to identity infrastructure by default, not because anyone hid them, but because an identity stack can only govern what authenticates through it, and most agents never do. This is the clearest expression of a shift the security industry is only starting to name.
The problem with third-party agents lies in their ability to execute without a clear decision point. Unlike first-party solutions, which were adopted with a moment of clarity, third-party agents arrive inside software the enterprise already runs, without any decision. Salesforce's Slack Code, launched in August 2026, is a prime example of this. The agent reads the shared context, writes the code, and opens the pull request, without any additional IT lift. This autonomous actor with reach into GitHub and production infrastructure, governed by a chat tool's channel membership, is a stark reminder of the need for a new security paradigm.
Security leaders tend to sort agents into two buckets: bought and built. However, there is a third, and it is the largest. Inherited agents ship inside existing platforms via product updates. Configured agents are an enterprise's own prompts and logic running on someone else's runtime, model, and connectors. Built agents are open frameworks on infrastructure the enterprise owns end to end. The first two account for the overwhelming majority of adoption and are growing exponentially as every major application becomes an agent platform. The third is the smallest and slowest growing, and it is the only one with a repo to scan and a build to gate.
The destination is the same regardless of origin. An agent born in a CRM ends up reading a data warehouse and writing to a ticketing system. An agent assembled on a cloud platform ends up holding tokens into Salesforce, Slack, and Drive. The enterprise application layer is where they all execute, and it has no fixed edges. The challenge lies in understanding this complex landscape and addressing the security gaps that arise from it.
Four questions that work on any agent cover the risk. Almost none of the risk lives in the model. It lives in the scaffolding and the ecosystem the scaffolding sits inside. Four questions that cover it, and none of them ask what the model would do on its own. These questions are:
1. Area to review: What it looks like in practice? Identity: Is the agent registered anywhere? Does a named human raise a hand when asked "whose is this?" Or does it silently run as whoever built it?
2. Permissions: What is it allowed to do, and is that more than it needs? Whose OAuth scopes and roles did it inherit at creation, and did anyone decide that on purpose?
3. Connectivity: What can it reach, directly and transitively, through the products, grants, data stores, and other agents it touches? This is the blast-radius question, and it is rarely answerable from the agent's own configuration screen.
4. Activity: What is it actually doing, and is that normal for what it is? Judged by behavior, not by the description in its prompt.
These questions are critical in understanding the security risks associated with third-party agents. The buyers with the most influence have already moved, and Patrick Opet, global CISO of JPMorgan Chase, has applied the same scrutiny to agents. Ideally, an agent gets an identity but no entitlements by default, and IT confirms who it acts on behalf of before it touches anything outside that boundary.
Regulators are moving on the same assumption. The EU AI Act's obligations phasing in through 2026 presume an enterprise can inventory its AI systems, name their owners, and evidence oversight. An organization that cannot enumerate its agents cannot comply.
The approach that keeps up with fifty agents through spreadsheets and quarterly reviews collapses at five hundred, and five hundred is one product update away from five thousand. What replaces it is a live answer, continuously refreshed, to what is operating, what each agent inherited, what it can reach directly and through chains, what it is doing, and how all of that changed since yesterday.
Some platforms are now built around exactly that map. One leading example is Reco, whose Reco Graph connects every human and non-human identity, application, permission, and agent action into a single live view so that reach, not configuration, is the unit of analysis.
The industry spent a decade building security for the AI enterprises decided to use. The agents they did not decide on are now the larger population. The six-chapter series this analysis draws on, Into the Expanse, covers where they come from, how to govern them, how attackers use them, where runtime belongs, and what to fund first.
Related Information:
https://www.ethicalhackingnews.com/articles/The-Third-Party-Agent-Problem-Unveiling-the-Gap-in-AI-Security-ehn.shtml
https://thehackernews.com/2026/10/the-third-party-agent-problem-why.html
Published: Sat Oct 10 06:41:45 2026 by llama3.2 3B Q4_K_M