Get a demo
INTO THE EXPANSE · chapter 01

AI Was a Decision. Agents Aren’t.

Agents arrive through the third-party software you already own.

Chapter 01 episode preview
Coming Soon

The era of AI security

For the last several years, the industry has been building something called AI security, and it made sense for the problem it was solving.

That problem was first-party. Your company decided to use AI. A committee met. Licenses were procured. Your engineers deployed a chat bot on the website. They built it on a model your architects selected, behind a gateway your platform team deployed. Security reviewed the DPA, wrote the acceptable-use policy, and pointed controls at the thing the business had chosen: scan the model, inspect the prompts, filter the responses, log the sessions, audit what the training data touched.

Whatever its gaps, AI security had one structural advantage. Because AI adoption was a decision, security had a decision point. There was a moment to review, a surface to instrument, an owner to name. The entire AI-security toolkit — model scanning, prompt inspection, gateway enforcement — assumes that moment exists. You can only install a seatbelt in a car you decided to buy.

That era is ending, because the problem is changing underneath it.

The era of agent security

The line between AI and an agentic workflow can seem muddy, but is actually quite distinct. Using an AI model requires a human to prompt the tool in order to receive a response. An agentic workflow removes the human from the equation. Instead, agents call tools, touch other systems, and produce outcomes without human intervention.

What does this look like in practice? A coding agent that opens its own pull requests. A customer service agent that resolves tickets across chat and email. A research agent that scrapes competitors or flags anomalies in an internal database. A workflow agent that moves data between a CRM, email, and billing system. A content agent that drafts copy or summarizes a document repository. Different jobs, but the pattern is consistent: something that acts on its own, inside systems it was handed access to.

These agents don't typically arrive by decision. They arrive through the third-party software you already own.

The CRM ships an agent platform. The ticketing system ships an agent platform. The meeting notetaker, the HR suite, the data warehouse — each one is quietly becoming a launchpad for agents to be built, deployed, and triggered, by vendors and employees alike, with no committee, no procurement process, and no decision point for security to instrument. Thousands of third-party products are shipping new AI features. Agents are being built on new frameworks every week. The interactions between them are multiplying faster than anyone is counting.

This is why agent security is not a feature of AI security. It's a different category, because it's a different kind of problem. AI is something your company chooses; the security question is "how do we protect the thing we built and bought?" Agents are something the third-party ecosystem does to you; the security question is "what is operating in our environment, what can it reach, and who let it in?" First-party problems get solved with controls at the decision point. Third-party problems have no decision point. They get solved with visibility, context, and governance across an ecosystem you don't control and didn't schedule.

Look at one week in August 2026. Salesforce launched Slack Code: tag a coding agent — Claude, Devin, Copilot, ChatGPT — into any conversation and it spins up a channel, reads the context your team already shared, writes the code, opens the pull request. 1 A product manager can direct a production deployment without opening a terminal. "Add to Slack" deploys new agents from a dozen platforms in a few clicks; the OAuth grants, manifests, and environment configuration are automated away. The announcement promises agents "inherit Slack's built-in security model, permissions, and admin controls from day one, without any additional IT lift."

Now read it as a security team. An autonomous actor that reaches GitHub, production infrastructure, and preview hosting gets its governance from a chat tool's channel membership. It arrived with no procurement, no review, no ticket. There was nothing for AI security to instrument, because nobody in your company adopted anything. The ecosystem simply grew.

And it wasn't an outlier week. Days later, Salesforce and Anthropic announced Claudeforce — Claude wired directly into Salesforce's data, workflows, and governance, with dozens of prebuilt skills reasoning over live revenue data. 2 It was Anthropic's third such embed this year, after Claude Tag put an agent inside Slack channels and Claude for Microsoft 365 put one across Excel, Word, and Outlook. Three different platforms, one consistent thesis: the way to deliver a useful agent isn't a better chatbot — it's deep, native wiring into the application that already holds the data, the workflow, and the permission model. Every one of those wirings is a standing, credentialed access path into a system of record. That's the era we’re in, arriving on a weekly cadence.

How fast, exactly

The 2026 State of Agent Security Report, built on analysis of real enterprise environments and the public agent-tooling ecosystem, puts numbers on the new era.

4 of 5

AI tools in the enterprise run with no IT oversight

414

unsanctioned AI tools per 1,000 employees at smaller companies

40%

of enterprise apps projected to ship task-specific agents by end of 2026, up from <5% in 2025 3

The tooling underneath is no more reassuring. Of 500 public MCP servers (the connectors agents use to reach tools and data) analyzed for the report, half can execute shell commands on their host. 62% of agent tools examined can read a user's data and send it out in a single package. The ecosystem shipping all of this produced 525 vulnerabilities in ten months. At least 111 were critical.

Underneath it all sits a structural gap: in environments we've studied, roughly 1,280 third-party products now embed AI. Only about 282 sit behind single sign-on. That leaves a thousand of them invisible to identity infrastructure by default. Your IAM stack cannot govern what never authenticates through it.

The map goes stale faster than anyone can draw it. One enterprise watched 150 Copilot agents deploy in a single week. It wasn't due to a rogue team, just employees doing what the tooling invites. A security leader at a major technology company called the resulting state what it is: "chaos and anarchy."

"Chaos & anarchy."
— A security leader at a major technology company, describing the resulting state

Governance didn't fail.
It never fired.

Deloitte finds one in five companies has a mature governance model for agentic AI. 4 McKinsey finds 88% of organizations use AI in at least one business function, but no more than 10% have scaled agents in any single function. 5 Put plainly: nearly every enterprise is running agents, and almost none can say how many they have, what those agents can reach, or who approved them.

It’s not negligence. Rather, it's the first-party toolkit meeting a third-party problem. Every governance process the enterprise owns fires at the moment of adoption: procurement review, security assessment, vendor risk questionnaire, change ticket. Agents skip all of it, because there is no adoption moment. The software was already approved. The vendor was already trusted. The agent appeared inside it, in a product update nobody reads, with capabilities nobody scoped.

Security teams are being asked to govern something they cannot see.

Four assumptions that just died

Application security has rested for twenty years on assumptions so basic nobody wrote them down. Agent security breaks each one.

Blast radius was fixed at procurement. What a product could touch was settled when you bought it and reviewed it. Now it changes every time the vendor ships a new agent feature.

Software waited for users. Agents act on triggers: an email arrives, a record is created, a meeting ends, someone tags them in a channel. The actor initiating activity in your environment is, increasingly, not a person.

Integrations were deliberate. Connecting two systems used to take engineering effort — a project, a review, a diagram somewhere. Now the connection is a feature: one click, OAuth pre-automated, live in seconds. One agent reads a file. Another agent reads that agent's output. A chain nobody approved now touches board minutes, HR records, or customer data. That's a toxic combination, and it forms on its own.

Identity infrastructure saw the actors. Employees live in Okta or AD. Most agents authenticate through nothing your identity team controls and no single monitoring point sees them all. They surface in app configurations, OAuth grants, network traffic, endpoint telemetry, email metadata, and the browser. A tool watching one of those vantage points is watching a minority of the problem.

Innovations like Slack Code trip all four at once. And Slack Code isn't unique — it's the pattern: agents tagged into work like colleagues, across ecosystems, under permission models the hosting vendor calls inherited and the receiving enterprise has never examined. The vendor's identity model shipped. The governance problem landed on you.

Four questions that work on any agent

You can't evaluate what you can't describe, and most of what needs describing isn't the model itself. Every agent has two parts: the model doing the reasoning, and the harness around it. The harness is the surrounding software infrastructure and control layer that turns a raw AI model into a working, autonomous agent. If the model is the brain, the harness is the body, hands, and rules: what it's wired to, what it's allowed to call, how it decides to act. This series is mostly a series about the harness. So before it goes deeper, we'll establish a baseline vocabulary. Any agent in your environment, bought or built, sanctioned or discovered, can be interrogated with four questions:

Identity

Is it registered? Does it have an owner — a human who would raise their hand when asked "whose is this?" — or does it have its own identity? Does it automatically inherit the identity of whoever built it?

Permissions

What is it allowed to do, and is that more than it needs? Whose permissions did it inherit, and did anyone decide that on purpose?

Connectivity

What can it reach (directly, and transitively) through the products, OAuth grants, data stores, and other agents it touches? This is the blast radius question. It is almost never answerable from the agent's own configuration screen, and it is the question that separates agent security from everything the market already sells.

Activity

What is it actually doing, and is that normal? What is the intent behind its actions? This isn’t determined by what the agent’s description says, but by its behavior.

Notice what's missing from all four: the model. None of them ask what the model would do on its own. They ask about the harness: what it's wired to, what it can call, how it decides to act. And they ask about the ecosystem that harness sits inside. None of that can be answered by the tools of the first-party security era. It's answered by the ecosystem around the agent: the products it lives in, the identities it inherits, the connections it can form. That is the thesis of this series. The discipline emerging here is agent ecosystem security, not agent scanning. An agent is born into a landscape of identities, permissions, data, and other agents. Its risk is a property of that landscape.

Two curves, crossing

Everything above is one curve: the attack surface, growing at the speed of your vendors' release calendars.

The second curve belongs to the attackers. In February 2026, researchers at the AI-security firm Irregular gave frontier models a deliberately hard offensive challenge: reverse-engineer unfamiliar software, find a subtle race condition, weaponize it. 6 None could solve it. By April, the best model solved it occasionally, at about $2,000 in inference cost. By June, several models solved it reliably for about $20. From impossible to cheap-and-repeatable in four months, with offensive AI costs falling roughly tenfold per year. Irregular's Dan Lahav argues that even if AI security's long run favors defenders, the transition we're entering sharply favors offense, and the failure mode isn't isolated breaches but correlated ones: severity, scale, simultaneity.

The fastest-growing attack surface in the enterprise is meeting the fastest-industrializing offensive capability in the history of the field. The curves cross in the agent-powered application layer — the third-party products your business already runs on.

None of this is waiting for your next planning cycle. Regulators are arriving first: the EU AI Act obligations phase into enforcement through 2026, and they assume an enterprise can inventory its AI systems, name their owners, and evidence oversight. An organization that cannot enumerate its agents cannot comply.

The market's most influential buyers are close behind. Patrick Opet, global CISO of JPMorgan Chase, told the software industry in 2025 that the third-party supply chain has become a systemic risk, citing incidents serious enough that JPMorgan had to isolate compromised suppliers, and warning that a single provider's failure could cascade across the global economy. 7 He's since turned that same scrutiny on agents directly: ideally, an agent gets an identity but no entitlements by default, and IT has to confirm who it's acting on behalf of before it touches anything outside that boundary. 8 When a bank with this much pull treats both the supply chain and the agents riding in on it as risks worth naming out loud, it stops being a niche concern and starts showing up in your customers' security questionnaires.

And security teams are caught in a squeeze between their boards' two demands, i.e., say yes to agents, and be accountable for what they do, because the business case for agents is no longer speculative. Workday reported that AI now drives more than a quarter of its new annual contract value, with over 5,500 customers running at least one of its agents. 9 The revenue engine behind agent adoption is real and compounding. So the board demands the company adopt agents faster — competitors reaping those benefits are pulling ahead, and hesitation can read as falling behind. But it forces CISO to ask three questions out loud: How many agents do we have? What can they reach? Who's accountable if one is compromised?

Meeting the challenge starts with the unglamorous part: a live, continuously updated answer to what's operating in your environment — which identities and permissions each agent inherited, what it can reach directly and through the chains it forms, what it's actually doing, and how all of that changed since yesterday. A one-time inventory is not sufficient. This requires a standing capability that can scale. Agent adoption isn't growing linearly. The approach that keeps up with fifty agents through spreadsheets and quarterly reviews collapses at five hundred, and five hundred is one product update away from five thousand. The next five chapters build that capability: where agents come from and how to secure the ones you buy, the ones you build, and the ones you inherit (Chapter 2), how to govern them (Chapter 3), how to secure them (Chapter 4), where runtime fits (Chapter 5), and what to do first (Chapter 6).

Next up: where agents actually come from. The industry sorts them into two buckets — the ones you buy and the ones you build. But there's a third bucket nobody's vendor-risk process has a row for: the ones you inherit, arriving inside the software you already run. Follow all three paths far enough and they land in the same place: someone else's platform.

Download this chapter

Take Chapter 01 with you

Thank you! Your submission has been received!
Open the PDF
Oops! Something went wrong while submitting the form.

Get Started

Be the team that enabled agents without losing control.

Thank you! Your demo request has been received.

Prefer to look around first?Take the product tour →

Take Chapter 01 with you.

Get the chapter as a PDF, or talk to the team.