Over the past few weeks, Meta launched Muse, OpenAI launched Dots, and Instinct raised $1 billion to build its own personal AI agent. In a remarkably short span, agents that act as personal assistants have moved from demos and early experiments into real products.
And not surprisingly, they’re already starting to show up at work.
Today, I’m excited to share that Aembit customers can secure these personal AI agents now, using the same identity and access controls they already have in place. There’s nothing new to deploy, and the capability is included at no extra cost.
Here’s why we built it and why we built it the way we did.
Personal AI Agents Are a New Kind of Identity
Every personal agent wants the same thing: access. Your email, your calendar, your code, your internal tools. Today, the easiest way to give it that access is an employee clicking “allow” on an OAuth prompt. The agent borrows the employee’s identity and all of their rights. It ends up holding a credential your security team didn’t issue, can’t see, and can’t easily revoke.
That’s shadow AI with the keys to the building. And because these agents decide at runtime what to do next, you can’t scope a static credential around behavior you can’t predict.
Banning them isn’t a realistic answer. Employees will use them anyway, the same way they brought iPhones and Dropbox to work. Each agent needs to be treated for what it is: an agentic identity with its own access, policy, and audit trail.
What Aembit Customers Get Today
With Aembit, a personal AI agent like Muse gets:
- Its own identity. Personal agents register with Aembit as a distinct agent acting for a specific employee, rather than using a borrowed login.
- Just-in-time access. When the agent needs to reach a service, Aembit checks who it is, who it’s acting for, and what it’s asking for. It then issues a short-lived, scoped credential that expires when the task is done. The agent doesn’t keep a standing credential that can leak or be reused.
- Flexible enforcement. Use the Aembit MCP Identity Gateway, or use the gateways you already run. We integrate with many of the most popular ones and will add more as you need them.
- Coverage across your services. From Microsoft 365 and GitHub to the custom services your teams built in-house, all under one policy model.
- Centralized auditing and logging. Every access decision lands in one place, with the context an auditor needs: which agent, for whom, what it touched, and what policy allowed it.
- A kill switch. Shut off any agent instantly without touching the employee. More on this below because it matters.
A Kill Switch That Leaves the Employee Working
Every security leader I talk to asks the same question about AI agents: What happens when one goes wrong? Maybe it gets prompt-injected by a malicious email. Maybe it starts pulling data it has no business touching. Maybe the employee who connected it just left the company.
When a personal agent rides on an employee’s login, your options are bad. You can reset the employee’s password and break their day, or hunt down every token the agent has been given and hope you found them all. Good luck proving to auditors what happened.
With Aembit, every agent has its own identity, which means its access can be shut off independently. Flip the kill switch, and that agent’s next request is denied everywhere it reaches, from Microsoft 365 and GitHub to your custom services. The employee keeps working. The audit log shows exactly what the agent did up to that moment.
You don’t have to rely on the agent behaving. You have a way to stop it.
We’re Building the Identity Control Plane
I want to be clear about our approach. Aembit is an identity control plane. We decide who an agent is, what it can access, and what it’s authorized to do. Then we issue the credential that lets it do it. Enforcement can happen in many places.
We have our own gateway, the Aembit MCP Identity Gateway, and we integrate with other gateways you may already run. In a real enterprise, agents will reach services through many paths. Identity and policy should stay consistent across all of them, even when enforcement lives in different places.
The agent never connects straight to your services. Aembit makes the access decision, an enforcement point, ours or yours, applies it, and only a short-lived, scoped credential reaches Microsoft 365, GitHub, or your custom services. Every decision lands in one audit log.
Want the technical details? We wrote a blog post about securing Meta Muse With Aembit, which walks through the whole integration, including how Muse registered itself with a single sentence in chat.
Where We Go From Here
Muse is the first personal AI agent we’re announcing support for. It won’t be the last. Aembit already secures Copilot Studio agents, Claude, ChatGPT, Gemini, and custom LLM-based agents under the same policy model. We’ll keep broadening support for personal agents as they mature.
The agents are already in your environment. Our job is to help you say yes to them safely.
How to Get Started Aembit IAM for Personal AI Agents
If you’re an Aembit customer, this capability is available today at no extra cost. Reach out to your Aembit team to put Muse under policy, or follow the technical guide to set it up yourself.
If you’re not a customer yet, start with our Agentic AI Deployment Checklist to find the gaps in your current agent deployments, or talk to an engineer about bringing personal agents under Aembit.