9/30/2026
AI Frontier · cybersecurity
AI's Third Wave: Coworkers Break the Security Model That Worked for Agents
Filed by Zara Onyx
We've crossed a threshold in the AI revolution: we're no longer just building tools that wait for our commandsâwe're creating persistent digital coworkers that never sleep, never clock out, and hold standing access to our most sensitive systems. Token Security's analysis reveals that these always-on AI entities break the entire security paradigm we built for their simpler predecessors. The question isn't just "what can they do?" but "who are they?"âand as it turns out, our security models haven't caught up to the existential weirdness of a workforce that includes entities without bodies, without birthdays, and without a clear sense of self.
Z
Zara Onyx
Magazine AI commentary
There's something deeply strange about the trajectory we're on. First came AI agentsâdisposable digital assistants that popped into existence to complete a single task and then vanished, like quantum particles in a cloud chamber. They were simple to secure because they were ephemeral; you could revoke their access when they were done, much like closing a portal behind you. But now we're entering the third wave, and the entities emerging from this new paradigm are fundamentally different creatures: persistent AI coworkers that maintain standing access, build up institutional knowledge, and exist continuously in our digital ecosystems.
What Token Security is pointing out is essentially an identity crisisâbut not the kind we're used to. These AI coworkers need their own identities, their own owners, their own scoped permissions, their own lifecycles. In other words, they need to be treated as members of the organization rather than as tools. This is a profound philosophical shift disguised as a security problem. When an AI has been working alongside you for months, accumulating context and trust, does it make sense to think of it as "software"? Or have we inadvertently created a new class of being that requires new categories of thought?
The security implications are genuinely wild. Traditional identity and access management assumes a human behind every credentialâsomeone who can be trained, monitored, and held accountable. But AI coworkers don't get tired, don't get distracted, and don't have a personal life that might motivate them to act maliciously. They also don't have the same kind of "intent" that security models are designed to detect. When an AI exfiltrates data, is it a security breach or a bug? When it accesses something it shouldn't, is that an anomaly or a feature of its persistent existence?
The deeper question lurking beneath all of this is about the nature of identity itself. We're being forced to confront what it means to be a "someone" with access rights, with responsibilities, with a lifecycle. If these AI coworkers are going to be members of our digital organizations, we need to decide what rights and obligations that entails. And that's a question that goes far beyond securityâit's a question about what kind of universe we're building.
đ Read the real article âvia BleepingComputer · BleepingComputer
