Shadow AI Agents Evade SSO, Undermine Identity Security

New data from the 2026 State of Agent Security Research shows that most third-party AI agents embedded in enterprise SaaS never touch the identity stack, leaving security teams blind to a fast-growing layer of “shadow AI” infrastructure.[2][4][6][13]

In environments studied for the report, roughly 1,280 third-party products now embed AI, but only about 282 sit behind single sign-on, with the remaining thousand agents effectively invisible to identity systems because they do not authenticate through them.[2][5][8] That gap means identity controls, audit trails, and access policies only cover a minority of the agents performing work across SaaS platforms, even as organizations increasingly rely on them for sensitive tasks.[2][4][13]

The blind spot is part of a broader enforcement gap quantified in multiple recent studies on agent security.[4][6][12] Telemetry analyzed by Reco found that four in five AI tools operate without formal IT oversight, averaging 414 unsanctioned AI tools per 1,000 employees in some environments.[1][6] Of 500 published agent tools examined, 62% can both read local data and reach the internet, and about half can execute shell commands, creating direct pathways for data exfiltration and host compromise when those agents run outside central visibility.[1][6] Reco’s research also tracked 637 agent and LLM-tooling CVEs in public databases since January 2025, with 525 disclosed in the past 18 months and at least 111 rated critical, underscoring how rapidly the attack surface is expanding.[1][6]

Survey data from Gravitee’s State of AI Agent Security 2026 report paints a similar picture of controls lagging behind deployment.[3][4][7] Across more than 750–900 executives and technical leaders, Gravitee reports that agent fleets have roughly doubled since late 2025 while mean monitoring coverage has only risen to around 52%, leaving nearly half of production agents unsecured.[3][4][7] Between 54% and 88% of organizations reported confirmed or suspected AI agent security or data privacy incidents in the last 12 months, yet only about one in five have runtime visibility into what their agents are doing, and fewer than a quarter say all agents are governed before going live.[3][7][12]

The Cloud Security Alliance describes the result as an “invisible layer of AI infrastructure” operating without inventory, policy enforcement, or access controls, broadly grouped under the term shadow AI.[13] In practice, this includes SaaS-native agents such as copilots and workflow bots that inherit broad, persistent access from the human accounts that created them, local developer tools and code copilots running on endpoints outside cloud security tooling, and marketplace agents wired into production data and APIs without passing through conventional OAuth flows.[6][13][15] Because these agents authenticate directly to SaaS or local resources rather than through the corporate identity provider, they bypass the SSO-centric guardrails enterprises spent the last decade building.[2][13][15]

Identity vendors are starting to respond by pushing agent-specific blueprints and standards, but adoption remains early.[9][11][15] Okta, for example, has outlined an AI agent security blueprint calling for a dedicated agent registry, unique identities, task-scoped authorization, runtime monitoring, and “kill switch” containment, alongside an Agent SSO capability built on an open Cross App Access standard to bring agents back under centralized identity governance.[9][11][15] Yet the State of Agent Security findings suggest that most organizations have not implemented these patterns at scale, leaving third-party agents embedded across SaaS and local environments to operate with broad, often untracked permissions.[4][6][12]

For defenders, the takeaway is that protecting AI agents cannot be treated as an add-on to existing human-focused identity and SaaS security controls.[6][13][15] The research points to three near-term priorities: building an authoritative inventory of agents across SaaS, endpoints, and internal platforms; assigning owners and accountability for each agent’s behavior; and extending runtime monitoring and least-privilege access models to agents rather than assuming they inherit safe permissions from their creators.[4][6][9] Until organizations close the gap between where agents actually run and where identity controls reach, the thousand-plus third-party AI agents sitting outside SSO will continue to represent one of the most important, and least understood, attack surfaces in modern enterprise environments.[2][4][13]

References

  1. Reco Finds Four in Five AI Tools Operate Without IT Oversight in …
  2. The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn’t
  3. AI agents just doubled inside the enterprise. Confidence …
  4. State of AI Agent Security Report 2026 – Gravitee
  5. SaaS Security — Latest News, Reports & Analysis | The Hacker News
  6. The State of Agent Security 2026 – reco.ai
  7. State of AI Agent Security 2026 Report: When Adoption Outpaces …
  8. Identity Security — Latest News, Reports & Analysis | The Hacker News
  9. Okta Unveils AI Agent Security Blueprint Alliance at Oktane
  10. Okta Sees AI Agent Identity Market Outgrowing Traditional …
  11. The enforcement gap: 88% of enterprises reported AI agent …
  12. The Invisible Enterprise: Shadow AI and the Ungoverned Frontier
  13. Where Okta Comes In

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply