Every enterprise now runs on SaaS applications, and security and IT teams have spent a decade building the discovery, review, and access controls to govern it. That model is breaking. Unsanctioned SaaS applications, embedded AI, AI agents, OAuth integrations, and SaaS-to-SaaS connections now arrive faster than any team can discover, understand, and govern them. This is not a staffing problem or a tooling gap. So where does a security team go for a single, authoritative view of what the business is actually running?
The Blind Spot Problem
Take identity providers (IdPs). Many organizations treat them as the authoritative inventory of what the business is running. They unfortunately are not. IdPs represent known sanctioned applications and user accounts. An IdP sees federated application access, meaning access that has been registered and routed through it for authentication and SSO. Everything else typically stays invisible to the IdP: local application accounts, personal account logins, marketplace-sourced extensions, and non-human actors such as service accounts and AI agents.
These are growing sources of Shadow IT. A business unit can directly subscribe to a new SaaS application. An individual employee can enable an embedded AI copilot with one click. Neither action goes near a security review or an IT asset inventory.
The Cloud Security Alliance has reported that 56% of organizations see employees uploading sensitive data to unauthorized SaaS applications. Separately, 62% of financial services organizations report they have already deployed AI agents, with 93% of those using agents granting some level of autonomy, but most believing a new agent authorization framework is still required. Discovery relying exclusively on traditional identity provider logs will miss both. The gap is not a rounding error in an otherwise solid application inventory.
Why the Risk Compounds
Discovering an application is not the same as securing it. OAuth grants, API tokens, browser plugins, and SaaS-to-SaaS integrations create trust paths that monitoring and threat detection tools rarely see. Excessive scopes accumulate. Integrations get abandoned but retain their access. Third-party applications often go unreviewed for security and data handling processes. Any one of these can turn a small, low-profile integration into a route for a serious breach.
AI agents raise the stakes further. An agent with delegated access acts at machine speed. Its reasoning path is not deterministic and thus can’t be predicted with certainty. AI agents can execute tasks and move data faster than any human reviewer can. Governance built around annual policy or access reviews cannot keep pace. What is needed instead is real-time operational control: permission analysis, runtime observability, and an auditable record of what an agent did and why.
Further creating risk, applications change security-relevant settings and capabilities regularly, and the defaults are not always set to the safest option. An application configuration that was reviewed and approved last quarter may be operating differently today. And who administers these applications day to day? Often not someone from the IT or security team. Treat posture as a point-in-time check rather than a continuously monitored state, and drift will go unnoticed.
The Solutions Market Is Evolving Quickly
The security market's response has been to move through and past SaaS Security Posture Management (SSPM) for configuration hygiene and drift monitoring. What has emerged is a combined SaaS security and AI governance solution market. These systems cover identity posture, OAuth governance, supply-chain visibility, data exposure management, threat detection, remediation workflows, compliance reporting, and AI agent governance.
Keeping pace with the growing SaaS and AI application scope depends heavily on the security system’s discovery architecture. In response, vendors have built multi-source telemetry pipelines that pull from SaaS applications, browsers, endpoints, identity systems, data stores, activity logs, procurement and ITSM systems, threat intelligence, and AI platforms, correlating all of it. The industry shorthand for this continuously updated, correlated view is an enterprise security graph. This graph turns a pile of disconnected findings into a connected view of the organization’s actual attack surface.
What This Means for Buyers
For anyone building a vendor shortlist or drafting a Request for Proposal (RFP) for solutions in this space, discovery architecture and coverage should be a key element of the evaluation. A tool cannot govern what it cannot see, and coverage gaps in one telemetry source rarely show up until after deployment.
Two other criteria are also important and thus deserve equal weight. Identity governance needs to extend beyond human users to non-human identities and AI agents, each with its own lifecycle and ownership requirements. In addition, runtime controls for production agents need to be real, since a governance policy that only applies before deployment does nothing once an agent is operating. There is more to SaaS and AI governance than these three, but these provide a good foundation from which to start.
Join the Conversation
These findings, along with the full vendor landscape, are the subject of a live webinar on October 7, 2026: “Security at the Convergence of SaaS, AI, and Identity.” This session will cover the central findings of the SaaS Security and AI Governance Leadership Compass and Buyer’s Compass research, identify which capabilities are moving from optional to essential, and point out where market maturity still lags.