Three Launches. One Week. One Direction.
This week brought a cluster of launches that made personal AI agents look much more like an emerging product category, with serious money behind them.
- Meta expanded Muse, its personal agent that connects to email, calendars, and payments. Next up: operating any app on a user’s Mac desktop, plus its own email address so users can forward messages for it to handle.
- Instinct, a 14-person startup whose agent books, buys, pays, and cancels on your behalf, raised $1 billion at a $10 billion valuation, about a month after its last round. Marketing spend so far, according to its founder: $0.
- OpenAI launched dots: always-on agents that run on their own cloud computers, connect to more than 4,000 apps, and keep working when you’re not prompting them.
These are impressive products, and I expect a lot of people to love them. The pitch is similar across all three: hand over access to your accounts, and the agent does the rest. Here’s the question none of the launch posts really answer: What happens when “your accounts” means your work accounts? The API keys, cloud tokens, and admin credentials that hold a company together?
Make no mistake: personal AI agents are coming to work. And they’re bringing your secrets with them.
Personal Agents Won’t Stay Personal
We’ve seen this movie before. The iPhone launched in 2007 as a consumer gadget, with no corporate email support and few IT controls. A few years later, executives were walking into the office demanding it, and bring your own device (BYOD) forced enterprises to rebuild mobile security around devices they never chose. BYOD security became a discipline of its own. Dropbox ran the same play. So did ChatGPT, which gave us the term shadow AI. Consumer tools that save people time tend to end up at work, usually before security knows they exist.
Personal AI agents will follow the same path, only faster. They’re the next wave of shadow AI, and they’ll spread quickly because erasing the line between personal and work tasks is part of the appeal. The person who asks Muse to rebook a flight will ask it to move the meeting that now conflicts. The agent that reconciles a household budget will get asked to chase down an expense report. And with Mac desktop access and its own forwarding address, Muse can reach a work inbox without IT approving a single integration.
OpenAI, to its credit, isn’t pretending this won’t happen. Dots are rolling out to Business and Enterprise workspaces, and companies can set up “specialist dots” with their own identities, credentials, and system access for procurement, invoicing, support, and contracting. Good on them for treating agents as something to govern. The same underlying shift is happening in a sanctioned environment: software that acts, holds credentials, and works while nobody is watching.
The question is how personal AI agents show up in the enterprise: as identities you can see and govern, or as ghosts wearing your employees’ credentials.
What Breaks When an Agent Walks in the Door
Enterprise access control was built on a simple assumption: the thing logging in is a person, or software a person deployed on purpose. Personal AI agents complicate that assumption in three ways.
Identity collapses. When an agent signs in with an employee’s saved password or session token, your logs show the employee. Did a human approve that wire transfer, or did an agent do it at 3 a.m. while “proactively researching” in the background? Your IdP may not be able to tell you. Neither may your SIEM or your auditors.
Secrets leave the building. These products need some form of access to the systems they use. Depending on the product, that can mean credentials, delegated access, or stored authentication material. Meta runs Muse in a dedicated “Muse Secure VM” and is adding 1Password. OpenAI says dots use saved passwords without exposing them to the model. Those are sensible consumer protections. The enterprise question remains: where does the secret live, and whose controls apply to it?
And it won’t stop at a work email password. Muse already connects to GitHub and Notion. Dots are pitched for procurement, invoicing, and contracting. The moment an agent stalls on a task, the fastest fix will often be to give it more access: a personal access token, a cloud API key, an admin login to “just fix it.” People have pasted secrets into Slack, wikis, and source code for 20 years. They’ll paste them into agents, too.
That’s access potentially held by a system outside your security domain. Your vault policies may not apply. Your rotation schedule may not reach it. Your conditional access rules may not have the context to distinguish the agent from the employee behind it. If the agent gets prompt-injected by a malicious page or email, the attacker may gain whatever access the employee handed over. And if the agent vendor gets breached, those credentials can become part of someone else’s incident.
Accountability blurs. Agents act on goals, not just explicit instructions. That’s the point. But when an agent working from inferred preferences shares a contract draft or accepts a vendor’s terms, who authorized it? Least privilege only works if you know which identity is asking, and why. An agent borrowing a human’s identity may inherit that human’s privileges without being separately visible or governed.
Banning personal AI agents is unlikely to solve the problem. Bans didn’t work for SaaS. They didn’t work for shadow AI. The more durable approach is to stop treating agents as a feature of a user and start treating them as non-human identities in their own right.
Isn’t This Just Another Endpoint Agent?
Fair question. Security teams are already wrestling with endpoint agents: Claude Code, Cursor, Copilot, and the rest, running on developer laptops. Personal AI agents create many of the same problems, with one important difference: where they live.
Both act with a human’s delegated access, and neither necessarily shows up as an identity of its own. An endpoint agent quietly inherits whatever sits on the laptop: the AWS profile, the GitHub token, the .env file. A personal agent gets credentials or delegated access handed to it. Either way, the agent may be wearing someone else’s badge.
Where they live changes the risk profile.
| Endpoint Agents | Personal AI Agents | |
|---|---|---|
| Where It Runs | The employee’s managed laptop | The vendor’s cloud |
| How It Gets Secrets | Inherits local credentials | Gets copies or delegated access, often stored in the vendor’s environment |
| Can Your Tools See It? | Partly: EDR, MDM, and network controls apply | Often less directly; it may never touch your devices or network |
| When It Works | While the user’s session or environment is available | Always on, even when nobody is watching |
| Blast Radius | One machine, but inside your network | Whatever it has been given access to, potentially outside your security domain |
| How You Shut It Off | Stop or isolate the endpoint, or revoke its access | Revoke the agent’s access without unnecessarily disrupting the user |
An endpoint agent is a risk inside your walls. A personal agent carries access outside them. You can at least see more of the first one. With the second, you may not know it exists until something goes wrong.
And the line is already blurring. Muse is coming to the Mac desktop. Dots can connect to a user’s laptop with permission. The next generation of personal agents will likely be both: cloud-resident, always on, and reaching into the endpoint. Endpoint controls alone won’t be enough. The control point has to be the access itself.
Are You Ready? Five Questions to Answer This Quarter
- Can You Tell an Agent From a Human in Your Logs? If an employee’s account books travel, pulls a CRM export, and sends an email in the same minute, would anyone notice that no human did it?
- Do Agents Get Their Own Identity? Sanctioned agents, like a specialist dot for procurement, should be first-class identities with their own attestation. They shouldn’t disappear behind a service account sharing a static key or a user with a borrowed password.
- Can Agents Work Without Long-Lived Secrets? Start with short-lived, just-in-time access: credentials issued per request, scoped to the task, and expiring on their own. A secret that doesn’t exist can’t be handed over, vaulted somewhere else, or replayed by an attacker. Then ask the fallback question: for the long-lived keys you can’t retire yet, do you know where they live? Assume employees will paste API keys and admin credentials into agents, because some will, and that any secret given to an agent may be harder to control afterward.
- Is Access Decided at the Moment of Action? Policy should weigh who the agent is acting for, what it’s trying to reach, and under what conditions. Every time, not once at setup.
- Can You Revoke One Agent Without Locking Out the Person? If an agent goes rogue or gets prompt-injected, you need a kill switch scoped to the agent rather than a password reset that takes the employee down with it.
If you can’t answer most of these with a confident yes, you’re in good company. Very few enterprises can today. That’s exactly why the time to start is now, before employees’ personal agents show up in production.
They’re Coming. Give Them a Name Tag.
Meta, OpenAI, and a $10 billion startup just told us where computing is headed: software that acts on our behalf, holds our keys, and doesn’t wait to be asked. Consumers will adopt it because it saves them time. Employees will bring it to work for the same reason. Personal AI agents are to enterprise identity what BYOD was to mobile security: a forcing function.
Companies will need to give every agent its own identity, grant it just-in-time access scoped to the task in front of it, and prove afterward what it did and on whose behalf. Blocking agents at the door won’t provide that control. Identity-first, secretless access can.
Vaulting secrets got us this far. Getting rid of them is what comes next.