Enterprise AI is moving into what security researchers are calling its "third wave": from one-off, task-scoped agents to persistent digital coworkers that hold long-lived credentials, sit in chat channels, and increasingly delegate work to other agents. That shift is quietly breaking the identity and access model most companies still rely on.
What happened
In the first two waves of enterprise AI adoption, agents were largely disposable: spun up for a single task, granted narrow access, and torn down once the job was done. The main risk was what the model produced — hallucinations, unsafe output, prompt injection.
That's no longer the full picture. A growing share of AI deployments now behave like coworkers: they keep a standing identity, accumulate access across multiple projects over time, and are expected to be available on demand rather than re-provisioned for every task.
The problem is that most organizations still provision these persistent agents the way they provisioned temporary ones — through OAuth grants borrowed from a human's session, hand-offs made mid-session, or generic service accounts never designed for a self-directed, non-human actor. None of these gives an agent a durable, auditable identity of its own, and none makes it easy to tell afterward whether an action was taken by a person or by an agent using that person's credentials.
The companies building these products are starting to say so directly. Product leaders at major AI platforms have described basic operational access — to documents, infrastructure, internal tools — as the real bottleneck to making an agentic coworker useful, not the underlying model's intelligence. At the same time, leading AI vendors currently avoid hosting long-lived client credentials themselves and block attempts to authenticate agents as service accounts, pushing the identity problem back onto the businesses deploying them.
Compounding this, OAuth-style consent flows were built around a human reading a permissions screen before granting access. Agents don't do that reliably, tend to request broader access than they ultimately use, and rarely give any of it back — so access accumulates instead of resetting, and it tends to pile up faster than it would for a human employee, simply because agents work faster and touch more systems.
One major technology company reportedly built and demoed a working version of this model back in 2024: a workplace AI agent with its own account, an assigned role, and scoped permissions, able to join conversations and answer questions drawing on its own history. The demo worked, but the company's own leadership later said substantial groundwork remained before that kind of experience — a virtual teammate holding its own identity — could reach production. It never shipped; the agents that company has released since largely inherit a human's authority rather than holding their own.
Why it matters
Identity platform vendors have started responding. Several major identity and access management providers have introduced dedicated "agent identity" categories over the past year — distinct from human user accounts, with short-lived scoped tokens, a named human sponsor, and a built-in revocation path. That's a meaningful step, but each offering only secures its own vendor's ecosystem. It does nothing for the agents and AI integrations running across the rest of a company's cloud and SaaS footprint, many of which were never formally registered in the first place.
That's the quiet part of the problem: a meaningful share of AI agents and connected tools in a typical environment are "shadow coworkers" — provisioned by an individual employee using borrowed or improvised credentials, with no recorded owner. When that employee leaves or changes roles, the agent's access frequently isn't reviewed, revoked, or even noticed. An orphaned agent holding live, standing credentials is one of the most common ways AI-driven access creep turns into a real exposure.
What to do about it
Security teams adapting to this shift are converging on a few practical steps, regardless of which AI platforms are in use:
- Find the shadow coworkers. Formal registration only ever captures the agents someone remembered to register. Detecting agents from their authentication traffic — not from a manual inventory — is the only reliable way to surface the rest.
- Give every persistent agent its own identity. If an agent authenticates as the human who deployed it, no downstream system can tell the two apart, and no audit trail can attribute an action correctly.
- Assign a human owner to every agent, and keep the record current. Orphaned agents with live credentials are the most common source of unmanaged, standing agent privilege.
- Scope access to the agent, not to whoever launched it. An agent that only needs to read a project's tickets shouldn't inherit a token that can also write to company cloud storage or source control, just because the person who deployed it can.
- Decide in advance when an agent's access ends. Unlike project-based work, a digital coworker doesn't naturally reach a stopping point. Set expiry and disablement conditions when the agent is created, not after something goes wrong.
The common thread: as AI agents move from task-scoped tools to persistent coworkers — and start delegating work to each other — the identity question stops being optional. An agent that can act, remember, and now hand work to another agent needs an identity, an owner, and an expiry date, the same way a human employee does.
