Third-party agent due diligence: the vendor risk framework your governance is missing
88% of organizations reported confirmed or suspected AI agent security incidents in the past year. 91% of AI tools operate without IT approval. The average SaaS application now has at least 10 AI agents associated with it. Yet most governance frameworks focus exclusively on agents you build. Third-party agents, embedded in your SaaS tools, managed by your vendors and chained through partner integrations, operate outside your governance perimeter. This is the due diligence framework for the agents you did not build but are accountable for.