A New Era in AI-Driven Work Forces a Reevaluation of Security Models
As we navigate the rapidly evolving landscape of artificial intelligence (AI) in the workforce, it’s becoming increasingly clear that our current security models are no longer sufficient. The latest development in this space is the emergence of “true” AI coworkers – persistent, agentic entities that require a fundamentally different approach to access and identity management.
For several years, we’ve been able to adapt existing access models to accommodate AI agents, which were initially treated as simply another user within our systems. However, with the advent of truly persistent AI coworkers, this approach is no longer tenable. These digital colleagues are designed to work independently, without human oversight or intervention, and they require a more machine-friendly way of provisioning and managing access.
One of the key challenges posed by these new entities is their persistence. Unlike traditional users, who may log in and out of systems as needed, AI coworkers remain active for extended periods, accumulating access and privileges along the way. This creates a unique risk profile, with credentials becoming standing privileges that are difficult to manage or revoke.
To compound this issue, agentic co-workers often require access to multiple projects and tools, leading to what’s known as “access creep.” As they accumulate permissions from different initiatives, their overall reach can become formidable, far exceeding the original intent of the granting authorities. In humans, access creep is a well-documented problem in identity governance; in machines, it promises to be even more insidious.
The current state of affairs is that many AI platforms do not issue agents their own credentials or identities. Instead, they rely on borrowed credentials or static bearer tokens, which are far from proper identities. This lack of ownership and off-switch capability creates a significant security risk, as these digital co-workers can continue to operate with impunity, even when no human is actively involved.
The need for more sophisticated identity management solutions has never been more pressing. As we move towards a future where AI coworkers become ubiquitous, it’s essential that we develop security models that can accommodate their unique requirements and limitations. This will require significant investment in new technologies, processes, and procedures – but the alternative is to risk exposing our organizations to unnecessary vulnerabilities.
Ultimately, this new era of AI-driven work forces us to confront some uncomfortable truths about our current security practices. We must acknowledge that our existing models are no longer sufficient and begin building a more robust and machine-friendly framework for identity management. Only by doing so can we ensure the integrity and security of our systems, even as they become increasingly reliant on autonomous entities.
To readers, this means taking proactive steps to adapt your organization’s security posture to the changing landscape. This may involve investing in new technologies or reevaluating your existing access models to ensure they’re prepared for the demands of agentic co-workers. By doing so, you’ll be better equipped to navigate the challenges and risks associated with AI-driven work – and position your organization for long-term success in this rapidly evolving space.
Source: Bleeping Computer — 2026-09-30