AI's Third Wave: Persistent Coworkers Break Security Models
As persistent AI coworkers emerge, security models built for session-scoped chats and task-scoped agents are facing unprecedented challenges.

The Evolution of Workplace AI and Persistent Coworkers
The rapid shift in AI-driven work continues to evolve across distinct waves. Initially, users experienced session-scoped chats where risks were tied primarily to model output. This was followed by task-scoped agents where the primary risks shift to model actions. Now, the industry is moving toward truly persistent AI coworkers, bringing about a fundamental dissolution of current access models.
Industry vocabulary reflects this transition, with Microsoft discussing agents as digital colleagues and OpenAI outlining plans for virtual coworkers. According to insights shared on Lenny's Podcast in August 2026, building useful agents requires deep tactical access to data, cloud infrastructure, and core enterprise systems.
Security Challenges of Persistent AI Credentials
Unlike session-scoped chat models, persistent AI coworkers operate continuously with standing access. This creates identity risks that existing security frameworks were not originally designed to handle. Currently, provisioning identities purpose-built for AI agents is still far from being the norm across enterprises.
Instead, standard practices rely on OAuth grants, in-session hand-offs, and general service accounts. Furthermore, persistent agents are prone to access creep, accumulating privileges across multiple projects much faster than human workers due to their agentic propensity to utilize all provided access.
Platform Limitations and Audit Trail Issues
Major agent platforms currently do not issue dedicated credentials to AI agents. Neither Anthropic nor OpenAI run the OAuth client credentials grant in their hosted chat products. Meanwhile, ChatGPT connectors explicitly reject service accounts and JWT assertions outright.
Because developers often hand agents a static bearer token via APIs, AI systems end up holding full standing privileges originally sized for humans. This results in tainted audit logs, where human users are frequently recorded as the primary actor for actions executed entirely by autonomous software.
Historical Context and Emerging Solutions
Early demonstrations of agent autonomy pointed toward dedicated identities. At Google I/O in May 2024, Google demoed a Workspace agent named Chip that featured its own account, designated role, and configured permissions. However, Google Workspace VP Aparna Pappu said at the time that considerable development remained before virtual teammates could safely reach commercial products.
To address these risks, various security vendors and platform providers have begun introducing native agent identity controls. Microsoft has shipped Entra Agent ID with named human sponsors, and Okta has integrated agent identities into Universal Directory with short-lived, scoped tokens. Similar offerings have been introduced by SailPoint and CyberArk.
Recommended Security Steps for Enterprise AI
Security experts recommend several key measures to manage autonomous agent access safely. Organizations must detect shadow coworkers by monitoring authentication traffic, and administrators need to ensure that every persistent agent receives a dedicated identity rather than mimicking a human user.
Additionally, tracking human owners is essential to prevent security vulnerabilities introduced by orphaned agents with live credentials. Establishing proper lifecycle controls and enforcing the all-important deprovisioning step remains critical for maintaining long-term enterprise security.
Sources
- BleepingComputerAI's Third Wave: Coworkers Break the Security Model That Worked for Agents