{"id":379,"date":"2026-10-06T09:41:20","date_gmt":"2026-10-06T09:41:20","guid":{"rendered":"https:\/\/managedt.com\/blog\/third-wave-ai-coworkers-security-model\/"},"modified":"2026-10-09T02:44:37","modified_gmt":"2026-10-09T02:44:37","slug":"third-wave-ai-coworkers-security-model","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/third-wave-ai-coworkers-security-model\/","title":{"rendered":"The third wave of AI coworkers breaks the security model that worked for agents"},"content":{"rendered":"<p>Persistent AI coworkers are about to outgrow every access model built for chat sessions and task-scoped agents. The shift from session to coworker hands machines standing privileges, accumulated scope, and a lifecycle that current identity governance does not cover. Organizations that issue each agent its own identity, record a human owner, and write an expiration policy into the agent from day one will keep control when handoffs start crossing team boundaries.<\/p>\n<p>Current agent platforms still lean on borrowed human authority. ChatGPT connectors reject service accounts and JWT assertions, and the most widely deployed agent products do not run the OAuth client credentials grant, so an agent acts under the identity of whoever launched it. Audit trails record the human, not the machine, and the consent flow that OAuth assumes does not match how agents actually behave at runtime.<\/p>\n<h2>How AI work evolved in three waves<\/h2>\n<p>The first wave was session-scoped chat, where the main risk sat in what the model said. Output filtering, prompt guardrails, and classification caught most of it. The second wave moved to task-scoped agents, where the risk shifted to what the model does, and access controls plus human-in-the-loop approvals carried the weight. The third wave removes the human from the loop and leaves the access in place, and that is the gap the current model cannot close.<\/p>\n<p>The vocabulary at the major vendors signals the direction. Microsoft describes agents as digital colleagues. OpenAI&#8217;s public roadmap since early 2025 has pointed at virtual co-workers that hold their own state across sessions. A true coworker is persistent, accumulates access from project after project, and acts without waiting for a human to approve every step.<\/p>\n<h2>Why persistence breaks the current access model<\/h2>\n<p>An agent that runs for weeks or months cannot rely on case-by-case approvals. Humans are not available to review every action, and consent prompts every few minutes erode both security and attention. The result is that agents end up holding standing privileges sized for the human who started them, which is a different risk profile from a short-lived task agent.<\/p>\n<p>Three problems follow from that standing privilege.<\/p>\n<ul>\n<li>A persistent agent gradually accumulates permissions across every project it touches.<\/li>\n<li><strong>Tainted audit trails.<\/strong> When an agent acts under a human&#8217;s user-granted privileges, the log records the human as the actor, so investigation and attribution both fail.<\/li>\n<li><strong>No defined end of life.<\/strong> Project-based agents have a natural end. Persistent coworkers do not, and an orphaned agent with live credentials is a standing privilege with no owner.<\/li>\n<\/ul>\n<h2>What the major platforms actually ship today<\/h2>\n<p>Neither of the two most widely deployed agent platforms issues agents their own credentials in the hosted product. Anthropic and OpenAI both allow a developer to hand an agent a static bearer token through their APIs, which is far from a proper identity, and ChatGPT connectors reject service accounts and JWT assertions outright. The result is that AI systems hold full standing privileges right-sized for humans, and the logs are written under the human&#8217;s name.<\/p>\n<p>Google previewed a different model in May 2024. The Workspace agent demo, named Chip, had its own Workspace account, a designated role, configured permissions, and stated objectives, and it joined chat rooms under that identity. The Workspace VP said at the time that a lot of work remained before agentive experiences like virtual teammates could reach the product. Chip stayed a demo. What Google and its competitors shipped instead are agents that inherit a human&#8217;s authority.<\/p>\n<h2>How coworker behavior outpaces the OAuth consent model<\/h2>\n<p>OAuth assumes a human reads a consent screen and approves a fixed list of scopes, and that assumption is breaking. Agents discover tools at runtime and try to use them, so the fixed scope granted at the start rarely covers what the agent ends up needing. Confirming sensitive actions every few minutes is both annoying and a security risk, because there is only so much human attention to go around. The product lead for ChatGPT Work and Codex has described what makes an agent useful in the same terms: access to data, cloud infrastructure, and reliability, with the analogy that locking a hired colleague in a room with no access to documents, chat, or the company database makes the colleague useless. An isolated cloud agent is useless for the same reason, which means the route to a useful coworker runs through the same systems a human employee touches.<\/p>\n<p>That requirement reaches further when an agent spawns sub-agents to parallelize work, and when one person&#8217;s agent hands work to another person&#8217;s agent across teams. Those handoffs are governable only if the coworker holds an identity of its own.<\/p>\n<h2>What vendors are shipping for agent identity<\/h2>\n<p>The platform vendors have started adapting. Microsoft shipped Entra Agent ID with first-class agent identities and a named human sponsor. Okta added agent identities to Universal Directory, with short-lived, scoped tokens and a revocation path. SailPoint and CyberArk have comparable offerings. Each of these secures agents inside its own estate, and for organizations that want to stay platform-agnostic, identity controls are the de facto checkpoint where policies can be enforced, because identity governs access to every action.<\/p>\n<h2>Five things to do before the third wave arrives<\/h2>\n<ul>\n<li><strong>Find the shadow coworkers.<\/strong> Registration only captures agents that someone remembered to register, so detection has to run on authentication traffic, OAuth grants, and API key use.<\/li>\n<li><strong>Give every persistent agent an identity of its own.<\/strong> If an agent authenticates as a human, no downstream control can tell the two apart and no investigation can correctly attribute the action.<\/li>\n<li><strong>Record a human owner.<\/strong> Orphaned agents with live credentials are the most common source of agent-related standing privilege.<\/li>\n<li><strong>Scope access to the agent, not to the person who started it.<\/strong> An agent that reads Jira should not hold a token that also writes to the cloud provider just because the engineer who launched it happened to hold both.<\/li>\n<li><strong>Decide in advance when it dies.<\/strong> Persistent agents are not project-based, but they still need a written end condition, such as a team disbandment, an owner leaving, or an idle period that triggers automatic retirement.<\/li>\n<\/ul>\n<p>For organizations that want a structured way to track where their own agent identities are running, an AI visibility scan can surface which AI agents and MCP servers are active in an environment and which credentials they are using. SEOScanPro&#8217;s AI Agent Readiness check is one way to see whether the site itself is readable and usable to the agents that will soon be coworkers on the other side of the request.<\/p>\n<h2>What the third wave asks of the security team<\/h2>\n<p>Wave one needed output controls. Wave two needed access controls and approvals around a human in the loop. Wave three takes the human away and leaves the access in place, and the pressure is about to rise. One person&#8217;s coworker will hand work to another person&#8217;s coworker, and those handoffs only stay governable when the coworker carries its own badge. Give it an identity before you give it a job.<\/p>\n<h2>FAQ<\/h2>\n<h3>What is the third wave of AI work?<\/h3>\n<p>The third wave is persistent AI coworkers, agents that hold their own state across sessions, accumulate access over time, and act without a human in the loop. It follows session-scoped chat, where the risk was the model&#8217;s output, and task-scoped agents, where the risk was the model&#8217;s action.<\/p>\n<h3>Why do current access models break for AI coworkers?<\/h3>\n<p>OAuth assumes a human approves a fixed list of scopes, agents discover tools at runtime and use them, and persistent agents accumulate grants from project after project. Combined grants can exceed anything a human intended to give, and audit trails record the human who started the agent rather than the machine.<\/p>\n<h3>What is the first step to secure persistent agents?<\/h3>\n<p>Find the shadow coworkers by looking at authentication traffic, OAuth grants, and API key use, since registration only captures agents that someone remembered to register. Then give each persistent agent its own identity, record a human owner, scope access to the agent rather than the launcher, and write a retirement condition into the agent at creation.<\/p>\n<h2>SEOScanPro<\/h2>\n<p><a href=\"https:\/\/seoscanpro.ai\/ai-visibility\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" data-src=\"https:\/\/seoscanpro.ai\/shots\/og-home.jpg\" alt=\"SEOScanPro, which includes the AI visibility report\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" \/><\/a><\/p>\n<p>SEOScanPro has the AI visibility report runs a full technical audit of a site and shows the measured result behind every check. <a href=\"https:\/\/seoscanpro.ai\/ai-visibility\" target=\"_blank\" rel=\"noopener\">Open the AI visibility report<\/a>.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is the third wave of AI work?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"The third wave is persistent AI coworkers, agents that hold their own state across sessions, accumulate access over time, and act without a human in the loop. It follows session-scoped chat, where the risk was the model's output, and task-scoped agents, where the risk was the model's action.\"}},{\"@type\":\"Question\",\"name\":\"Why do current access models break for AI coworkers?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"OAuth assumes a human approves a fixed list of scopes, agents discover tools at runtime and use them, and persistent agents accumulate grants from project after project. Combined grants can exceed anything a human intended to give, and audit trails record the human who started the agent rather than the machine.\"}},{\"@type\":\"Question\",\"name\":\"What is the first step to secure persistent agents?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Find the shadow coworkers by looking at authentication traffic, OAuth grants, and API key use, since registration only captures agents that someone remembered to register. Then give each persistent agent its own identity, record a human owner, scope access to the agent rather than the launcher, and write a retirement condition into the agent at creation.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/ais-third-wave-coworkers-break-the-security-model-that-worked-for-agents\/\" target=\"_blank\" rel=\"nofollow noopener\">bleepingcomputer.com<\/a>.<\/p>\n<p><!-- seo-pro:slop-fixed --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Persistent AI coworkers need their own identities, not borrowed human credentials. Here is what changes in the access model and what to do before the third wave<\/p>\n","protected":false},"author":3,"featured_media":378,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-379","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/379","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=379"}],"version-history":[{"count":2,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/379\/revisions"}],"predecessor-version":[{"id":492,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/379\/revisions\/492"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/378"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=379"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=379"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=379"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}