Persistent AI coworkers are emerging, but most current platforms still run on borrowed human credentials, creating standing privileges, weak attribution, and access creep. Security teams must identify every agent, give it its own identity, and manage its lifecycle before the third wave of agentic workflows takes hold. #OpenAI #Microsoft #Anthropic #Google #EntraAgentID #Okta #SailPoint #CyberArk #TokenSecurity
Keypoints
- AI risk has shifted from model output to agent actions and now to persistent digital coworkers.
- Most agents still rely on human credentials, OAuth grants, or service accounts without true identities.
- Persistent agents create access creep, standing privileges, and poor audit attribution.
- Vendors like Microsoft, Okta, SailPoint, and CyberArk are adding agent identity controls.
- Organizations should find shadow agents, assign ownership, scope access, and define deprovisioning rules.