BleepingComputer πŸ” Cybersecurity πŸ‘ 0 πŸ“– 7 min read

AI's Third Wave: Coworkers Break the Security Model That Worked for Agents

Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities

AI's Third Wave: Coworkers Break the Security Model That Worked for Agents

Sponsored by
Token Security
  • September 30, 2026
  • 10:01 AM

AI Agent

An AI agent borrows your credentials. An AI coworker never gives them back.

By Itamar Apelblat, Co-Founder and CEO, Token Security

We no longer have the luxury of adapting to change over several years. The fundamental shift in AI-driven work keeps morphing month after month, so much so that in just three years we've already experienced distinct waves of work-related AI, and another one is no longer on the horizon but right around the corner.

First came the session-scoped chats, where the risk was what the model says. Then came task-scoped agents, where the risk is in what the model does. Broadly speaking, that's where we are now, but the goalposts are already elsewhere. Truly persistent AI coworkers are nearly here, and with them, the dissolution of current access models.

As with so much in this space, you can see that's where the AI companies want to go by their vocabulary. Microsoft talks about agents as "digital colleagues," and OpenAI's Sam Altman outlined the plan for virtual co-workers what seems like a lifetime ago, in February 2025.

That vision is now becoming a reality, and we need to adapt our security models to address fundamental differences in how AI colleagues work.

Persistence changes everything

You should plan for this sooner rather than later. For a few years, we were able to pigeonhole AI into existing access models, but a "true" coworker that works independently requires a different way of thinking.

Agentic co-workers will require access front-loading or a more machine-friendly (yet secure) way of provisioning it, as approving actions on a case-by-case basis only works if there's a human available to review. True digital co-workers can't rely on regular approvals for everything but should be able to request additional access when it's needed for their tasks.

Currently, provisioning identities purpose-built for AI agents is still far from being the norm. The standard is to use OAuth grants, in-session hand-offs, and service accounts. The first two options usually place humans as the primary entity; the third one is rarely created specifically for agents.

Persistence leads to a different risk profile for the digital co-worker's credentials in yet another respect. They're essentially becoming a standing privilege, same as with people. We'll need to address their lifecycle, including the all-important deprovisioning step, to ensure security.

And consider access creep. If a digital co-worker is persistent, it's bound to accumulate access from different projects. For humans, access creep is the oldest unsolved problem in identity governance. For machines, it's bound to be much worse, both because of the speed with which access will accumulate and the agentic propensity to use all access they're given. Agents can combine several reasonable grants into an overall reach that no one intended to give them.

Beyond The Checkbox

Your SOC 2 report says the controls worked, but it never says what they missed. Agents run on borrowed credentials, with no owner and no off switch.

Token Security finds every agent, assigns it an identity, and remediates its access to the job it was intended to do.

Find your agents

Everyone will need to adapt

Businesses aren't the only ones that will need to adapt to the third wave of agentic workflows. For now, the two most widely deployed agent platforms do not issue agents their own credentials. Neither Anthropic nor OpenAI run the OAuth client credentials grant in their hosted chat products, while ChatGPT connectors reject service accounts and JWT assertions outright.

Both do allow a developer to hand an agent a static bearer token via their APIs, but that’s far from a proper identity.

As a result, not only do AI systems hold full standing privileges that were right-sized for humans, but the logs are also tainted. When AI acts under its user-granted privileges, the human is usually recorded as the actor in any audit trail.

The desire to keep a human in the loop doesn't just impact AI; it also creates a burden on people. OAuth assumes a human will read a consent screen and approve a fixed list of scopes. Agents are rarely satisfied with their initial access; they discover tools at runtime and attempt to use them.

Confirming sensitive actions every few minutes is both annoying and a security risk, since there's only so much attention to go around.

The people building coworkers are explicit about what they need

Tara Seshan, who leads product for ChatGPT Work and Codex at OpenAI, described what actually makes an agent useful on Lenny's Podcast in August 2026.

Model intelligence is only part of it. The rest comes down to what she described as "meat and potatoes tactical" work: access to data, cloud infrastructure, and reliability.

Her analogy was this: you hire a colleague and then lock them in a room with no access to Google Docs, Slack, or the company database. That colleague is not going to be effective. An isolated cloud agent, she argued, is useless for the same reason.

She is right about the requirement. The route to a useful coworker runs through the same systems a human employee touches.

Seshan also described her agent spawning sub-agents to parallelize work, and a near future where her agents and her colleagues' agents collaborate on shared tasks. Both are reasonable directions that assume an identity model that does not exist.

When one person's agent hands work to another person's agent, the credential that executes belongs to whichever human happened to start the chain.

Google built the right model in 2024. It never shipped.

At I/O in May 2024, Google demoed a Workspace agent named Chip. Chip had its own Workspace account, a designated role, configured permissions, and a stated set of objectives. It joined chat rooms and answered from the history it could see.

Workspace VP Aparna Pappu said at the time that Google had a lot of work to do before "agentive" experiences, such as virtual teammates, could reach the product. Chip stayed a demo.

What Google (and all its competitors) shipped instead are agents where the coworker inherits a human's authority.

What to do about it

The platform vendors have started adapting. Microsoft shipped Entra Agent ID with first-class agent identities and a named human sponsor. Okta added agent identities to Universal Directory, with short-lived, scoped tokens and a revocation path. SailPoint and CyberArk have comparable offerings. The downside is that each secures agents inside its own estate.

If you want to be platform-agnostic, identity controls are the only de facto checkpoint at which you can enforce policies, since identity governs access to every action. Here are five things you should do:

  • Give every persistent agent an identity of its own. If it authenticates as human, no downstream control can distinguish the two, and no investigation can correctly attribute an action.
  • Scope access to the agent rather than to the person who started it. An agent that reads Jira should not hold a token that also writes to your cloud provider just because the engineer who launched it happened to have both.
  • Decide in advance when it dies. Digital coworkers aren't project-based, so they aren't tied to them, but that doesn't mean you should scope them as immortal. Let's say a team they're "a part of" gets disbanded, or the employee who's responsible for an agent is let go. Write those conditions down when you create the agent, along with an idle period after which it expires on its own.

What the third wave asks of you

For wave one, where the risk was driven by the model's output, we had prompt filtering, guardrails, and output classification. For wave two, with action-based risk and a human-in-the-loop process, the focus was on access controls and approvals. Wave three takes the human away and leaves the access in place.

The pressure is about to rise. Seshan's account has agents that spawn sub-agents and collaborate across teams. One person's coworker might soon hand work to another person's coworker. Those handoffs are governable only if the coworker holds an identity of its own. In other words, give it a badge before you give it a job.

For us at Token, we’re already identifying the AI agents and MCP servers running in your environment, including those nobody registered, based on their OAuth grants, API keys, and login traffic. We’re giving each agent its own identity and a human owner, scopes and rotates its credentials, and retires it when the owner leaves or it sits idle.

Token Security covers your cloud and SaaS systems as a whole, not just one vendor's.

Book a Token demo to see how many of your agents are running on borrowed human credentials.

Sponsored and written by Token Security.

πŸ“° Read the original article on BleepingComputer

Originally published by BleepingComputer. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.