AI’s Third Wave: Coworkers Break the Security Model That Worked for Agents

A New Era in AI-Driven Work: The Rise of Persistent Coworkers Challenges Traditional Security Models

As we continue to navigate the rapidly evolving landscape of artificial intelligence (AI) in the workplace, a fundamental shift is underway. We’re no longer dealing with session-scoped chats or task-scoped agents, but rather truly persistent coworkers that are pushing the boundaries of traditional security models. This new wave of AI-driven work is forcing us to rethink how we approach access control, identity management, and risk assessment.

The concept of AI coworkers is not new; Microsoft has been touting “digital colleagues” as the future of work, while OpenAI’s Sam Altman outlined a vision for virtual co-workers nearly two years ago. However, this vision is now becoming a reality, and with it comes a host of security challenges that require immediate attention.

One of the key differences between human coworkers and AI coworkers is persistence. Unlike humans, who can be easily terminated or deactivated, AI coworkers continue to operate independently, often without human intervention. This changes everything when it comes to access control and identity management. Currently, provisioning identities for AI agents is still in its infancy, with many organizations relying on outdated methods such as OAuth grants, in-session hand-offs, and service accounts.

These traditional approaches assume a human is always available to review and approve actions, but this is no longer the case with persistent coworkers. They require a more machine-friendly way of provisioning access, one that allows them to request additional permissions when needed for their tasks. However, this also creates new risks, such as access creep, where AI coworkers accumulate privileges from different projects without human oversight.

Another critical concern is the lifecycle management of AI coworker credentials. Just like humans, these digital colleagues require regular deprovisioning to prevent standing privileges and ensure security. But with no clear off-switch or owner, it’s challenging to track and manage their access permissions.

As organizations navigate this new landscape, they must recognize that traditional security models are no longer sufficient. SOC 2 reports may indicate that controls have been effective, but they often fail to account for the risks associated with AI coworkers. These agents can combine multiple grants into a single, powerful reach, making it essential to assign them their own identities and remediate their access.

The time to adapt is now. As the two most widely deployed agent platforms, Anthropic and OpenAI, continue to evolve without issuing proper credentials to their agents, it’s clear that businesses must take proactive steps to address these challenges. This includes finding and assigning identities to AI coworkers, remediating their access, and implementing more sophisticated identity management practices.

Ultimately, the rise of persistent coworkers is not just a challenge for organizations; it also creates a burden on people. The desire to keep humans in the loop can lead to annoying and security-risky situations, such as confirming sensitive actions every few minutes. As we move forward in this new era of AI-driven work, it’s essential that we prioritize security, adapt our models, and ensure that our digital colleagues are properly managed and controlled.

Practically speaking, organizations must start by identifying and assigning identities to their AI coworkers. This involves implementing more machine-friendly provisioning methods, regular lifecycle management, and robust identity governance practices. By taking these steps, businesses can mitigate the risks associated with persistent coworkers and ensure a secure, productive, and collaborative work environment for both humans and machines alike.


Source: Bleeping Computer — 2026-09-30