Table of Contents

Personal AI Agents Are Coming to Work, and They’re Walking Out With Your Secrets

TL;DR: Personal AI agents are moving into work, where the access they inherit can quickly become an identity problem. If an agent operates through an employee’s credentials, enterprises may struggle to distinguish human activity from agent activity, apply the right controls, or revoke the agent without disrupting the user. Giving agents their own identities and short-lived, just-in-time access creates a cleaner path to governing what they can reach and do.

Apurva Davé
Apurva Davé

Chief Marketing Officer

Summarize:

Read
0%
AI agent working at a laptop with access to workplace apps including email, calendar, Slack, Notion, GitHub, and AWS.

Table of Contents

Read
0%

Three Launches. One Week. One Direction.

This week brought a cluster of launches that made personal AI agents look much more like an emerging product category, with serious money behind them.

  • Meta expanded Muse, its personal agent that connects to email, calendars, and payments. Next up: operating any app on a user’s Mac desktop, plus its own email address so users can forward messages for it to handle.
  • Instinct, a 14-person startup whose agent books, buys, pays, and cancels on your behalf, raised $1 billion at a $10 billion valuation, about a month after its last round. Marketing spend so far, according to its founder: $0.
  • OpenAI launched dots: always-on agents that run on their own cloud computers, connect to more than 4,000 apps, and keep working when you’re not prompting them.

These are impressive products, and I expect a lot of people to love them. The pitch is similar across all three: hand over access to your accounts, and the agent does the rest. Here’s the question none of the launch posts really answer: What happens when “your accounts” means your work accounts? The API keys, cloud tokens, and admin credentials that hold a company together?

Make no mistake: personal AI agents are coming to work. And they’re bringing your secrets with them.

Personal Agents Won’t Stay Personal

We’ve seen this movie before. The iPhone launched in 2007 as a consumer gadget, with no corporate email support and few IT controls. A few years later, executives were walking into the office demanding it, and bring your own device (BYOD) forced enterprises to rebuild mobile security around devices they never chose. BYOD security became a discipline of its own. Dropbox ran the same play. So did ChatGPT, which gave us the term shadow AI. Consumer tools that save people time tend to end up at work, usually before security knows they exist.

Personal AI agents will follow the same path, only faster. They’re the next wave of shadow AI, and they’ll spread quickly because erasing the line between personal and work tasks is part of the appeal. The person who asks Muse to rebook a flight will ask it to move the meeting that now conflicts. The agent that reconciles a household budget will get asked to chase down an expense report. And with Mac desktop access and its own forwarding address, Muse can reach a work inbox without IT approving a single integration.

OpenAI, to its credit, isn’t pretending this won’t happen. Dots are rolling out to Business and Enterprise workspaces, and companies can set up “specialist dots” with their own identities, credentials, and system access for procurement, invoicing, support, and contracting. Good on them for treating agents as something to govern. The same underlying shift is happening in a sanctioned environment: software that acts, holds credentials, and works while nobody is watching.

The question is how personal AI agents show up in the enterprise: as identities you can see and govern, or as ghosts wearing your employees’ credentials.

What Breaks When an Agent Walks in the Door

Enterprise access control was built on a simple assumption: the thing logging in is a person, or software a person deployed on purpose. Personal AI agents complicate that assumption in three ways.

Identity collapses. When an agent signs in with an employee’s saved password or session token, your logs show the employee. Did a human approve that wire transfer, or did an agent do it at 3 a.m. while “proactively researching” in the background? Your IdP may not be able to tell you. Neither may your SIEM or your auditors.

Secrets leave the building. These products need some form of access to the systems they use. Depending on the product, that can mean credentials, delegated access, or stored authentication material. Meta runs Muse in a dedicated “Muse Secure VM” and is adding 1Password. OpenAI says dots use saved passwords without exposing them to the model. Those are sensible consumer protections. The enterprise question remains: where does the secret live, and whose controls apply to it?

And it won’t stop at a work email password. Muse already connects to GitHub and Notion. Dots are pitched for procurement, invoicing, and contracting. The moment an agent stalls on a task, the fastest fix will often be to give it more access: a personal access token, a cloud API key, an admin login to “just fix it.” People have pasted secrets into Slack, wikis, and source code for 20 years. They’ll paste them into agents, too.

That’s access potentially held by a system outside your security domain. Your vault policies may not apply. Your rotation schedule may not reach it. Your conditional access rules may not have the context to distinguish the agent from the employee behind it. If the agent gets prompt-injected by a malicious page or email, the attacker may gain whatever access the employee handed over. And if the agent vendor gets breached, those credentials can become part of someone else’s incident.

Accountability blurs. Agents act on goals, not just explicit instructions. That’s the point. But when an agent working from inferred preferences shares a contract draft or accepts a vendor’s terms, who authorized it? Least privilege only works if you know which identity is asking, and why. An agent borrowing a human’s identity may inherit that human’s privileges without being separately visible or governed.

Banning personal AI agents is unlikely to solve the problem. Bans didn’t work for SaaS. They didn’t work for shadow AI. The more durable approach is to stop treating agents as a feature of a user and start treating them as non-human identities in their own right.

Isn’t This Just Another Endpoint Agent?

Fair question. Security teams are already wrestling with endpoint agents: Claude Code, Cursor, Copilot, and the rest, running on developer laptops. Personal AI agents create many of the same problems, with one important difference: where they live.

Both act with a human’s delegated access, and neither necessarily shows up as an identity of its own. An endpoint agent quietly inherits whatever sits on the laptop: the AWS profile, the GitHub token, the .env file. A personal agent gets credentials or delegated access handed to it. Either way, the agent may be wearing someone else’s badge.

Where they live changes the risk profile.

Endpoint AgentsPersonal AI Agents
Where It RunsThe employee’s managed laptopThe vendor’s cloud
How It Gets SecretsInherits local credentialsGets copies or delegated access, often stored in the vendor’s environment
Can Your Tools See It?Partly: EDR, MDM, and network controls applyOften less directly; it may never touch your devices or network
When It WorksWhile the user’s session or environment is availableAlways on, even when nobody is watching
Blast RadiusOne machine, but inside your networkWhatever it has been given access to, potentially outside your security domain
How You Shut It OffStop or isolate the endpoint, or revoke its accessRevoke the agent’s access without unnecessarily disrupting the user

An endpoint agent is a risk inside your walls. A personal agent carries access outside them. You can at least see more of the first one. With the second, you may not know it exists until something goes wrong.

And the line is already blurring. Muse is coming to the Mac desktop. Dots can connect to a user’s laptop with permission. The next generation of personal agents will likely be both: cloud-resident, always on, and reaching into the endpoint. Endpoint controls alone won’t be enough. The control point has to be the access itself.

Are You Ready? Five Questions to Answer This Quarter

  1. Can You Tell an Agent From a Human in Your Logs? If an employee’s account books travel, pulls a CRM export, and sends an email in the same minute, would anyone notice that no human did it?
  2. Do Agents Get Their Own Identity? Sanctioned agents, like a specialist dot for procurement, should be first-class identities with their own attestation. They shouldn’t disappear behind a service account sharing a static key or a user with a borrowed password.
  3. Can Agents Work Without Long-Lived Secrets? Start with short-lived, just-in-time access: credentials issued per request, scoped to the task, and expiring on their own. A secret that doesn’t exist can’t be handed over, vaulted somewhere else, or replayed by an attacker. Then ask the fallback question: for the long-lived keys you can’t retire yet, do you know where they live? Assume employees will paste API keys and admin credentials into agents, because some will, and that any secret given to an agent may be harder to control afterward.
  4. Is Access Decided at the Moment of Action? Policy should weigh who the agent is acting for, what it’s trying to reach, and under what conditions. Every time, not once at setup.
  5. Can You Revoke One Agent Without Locking Out the Person? If an agent goes rogue or gets prompt-injected, you need a kill switch scoped to the agent rather than a password reset that takes the employee down with it.

If you can’t answer most of these with a confident yes, you’re in good company. Very few enterprises can today. That’s exactly why the time to start is now, before employees’ personal agents show up in production.

They’re Coming. Give Them a Name Tag.

Meta, OpenAI, and a $10 billion startup just told us where computing is headed: software that acts on our behalf, holds our keys, and doesn’t wait to be asked. Consumers will adopt it because it saves them time. Employees will bring it to work for the same reason. Personal AI agents are to enterprise identity what BYOD was to mobile security: a forcing function.

Companies will need to give every agent its own identity, grant it just-in-time access scoped to the task in front of it, and prove afterward what it did and on whose behalf. Blocking agents at the door won’t provide that control. Identity-first, secretless access can.

Vaulting secrets got us this far. Getting rid of them is what comes next.

What Security Teams Need to Know About Personal AI Agents

What are personal AI agents?

Personal AI agents are software systems that can act on a user’s behalf across applications and services. They can handle tasks such as scheduling, purchasing, research, email, and other workflows, often with access to connected accounts and credentials.

Why are personal AI agents a security risk for enterprises?

The risk begins when agents use work accounts or credentials to act inside enterprise systems. If the agent operates through an employee’s identity, security teams may have difficulty distinguishing what the employee did from what the agent did on their behalf.

How are personal AI agents different from endpoint AI agents?

Endpoint agents typically run on an employee’s device and may inherit local credentials or sessions. Personal AI agents can run in a vendor’s cloud environment and continue working independently of the user’s device, which can place enterprise access outside traditional endpoint controls.

Why should AI agents have their own identity?

A distinct agent identity gives security teams a way to recognize, govern, and audit the software separately from the person it represents. It also makes it possible to apply policy to the agent without treating every action as though the employee performed it directly.

How can enterprises secure access for personal AI agents?

Enterprises can reduce risk by giving agents distinct identities, using short-lived and just-in-time credentials, evaluating access at the moment of action, and making agent access independently revocable from the user’s account.

Related Reading

Apurva Davé
Apurva Davé

Apurva Davé is the chief marketing officer at Aembit. He likes to take small things that are important and make them big things that are even more important. He did that at Riverbed, from its early days through its IPO; at Jut, which he founded; at Sysdig, from seed stage to unicorn; and at Google Cloud Security, where he helped triple the team and revenue. Despite his obsession with growth, Apurva still enjoys surfing small waves with his longboard. But hey, you can’t grow everything.

You might also like

Secrets managers still matter. But AI agents and workloads are changing when stored credentials make sense.
Broad credentials made sense when fixed application logic stood between users and actions, but AI agents have changed that equation.