Unmanaged Third-Party AI Agents Expose Identity Blind Spots

A 2026 report examined environments where many third-party products include AI agents. Around 1,280 such products were found, but only about 282 authenticate through single sign-on. The remaining agents typically bypass identity infrastructure, leaving security teams unable to govern them by default.
The 2026 report examined settings where third-party products include AI agents. It counted about 1,280 such products. Only roughly 282 of them authenticated through single sign-on.
That means most of these agents did not use SSO. By bypassing identity infrastructure, they left security teams without default governance. The gap was not an exception but the common pattern in the environments studied.
Organizations using third-party AI agents could find their security teams less able to monitor access or enforce consistent identity rules. Employees, customers, and partners whose identities are involved with these tools may be affected by oversight gaps if agents continue to bypass single sign-on. This may push technology providers and buyers to reassess how AI agents are authenticated and governed, though the report does not predict specific outcomes.