Around 1.000 AI products don't appear in corporate access systems
A Reco analysis based on the 2026 State of Agent Security Report examines how AI assistants enter company environments through third-party products. In the environments studied, about 1,280 products included AI, while only 282 were behind company single sign-on. Reco argues that an assistant's access to other systems may not be visible in its own settings—a useful distinction when assessing…
A new analysis reveals that around 1,000 AI-powered digital assistants may be lurking undetected within company systems. According to the 2026 State of Agent Security Report, out of 1,280 AI products studied, only 282 were protected by a company's single sign-on system. The analysis, conducted by Reco and published in The Hacker News, highlights the challenge of tracking these assistants as they infiltrate corporate environments through third-party products.
Many digital assistants appear in programs that employees already use without the company's explicit adoption, making them invisible in digital identity management systems. The analysis categorizes these assistants into three types: those added to existing products, those built into third-party services, and those created entirely by the company's own systems.
The first two categories are growing rapidly, while the latter two are fewer and growing more slowly. While an assistant's settings may indicate the actions it can perform within a program, they often do not reveal the broader systems and data it can access. Therefore, companies should not only consider the assistant's capabilities within the program but also its potential reach through other systems and its practical behavior.
The analysis suggests that companies should verify the identity of each assistant, the person responsible for it, its permissions, the systems it can access directly or indirectly, and its practical behavior. Experts like Patrick Opet, JPMorgan Chase's global head of security, have warned about the systemic risks posed by the external supply chain and urged companies to authenticate assistants, limit their default access rights, and clarify their actions on behalf of the company.
Furthermore, the European AI Regulation, set to take effect gradually through 2026, requires AI systems to be registered, have appointed responsible persons, and have their oversight documented. Reco emphasizes that the increasing number of assistants, potentially rising from 50 to 5,000 after product updates, necessitates more than the current spreadsheets and quarterly checks for monitoring.
The analysis introduces Reco Graph, a tool that visually represents the relationships between people, digital identities, applications, permissions, and assistant actions, aiming to provide a comprehensive overview of AI assistant integration within company systems.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.