Token Security CEO warns AI 'coworkers' will outgrow current access models
In an op-ed, Token Security co-founder and CEO Itamar Apelblat argues that AI has moved through three waves—chat sessions, task-scoped agents, and now persistent 'AI coworkers'—each carrying different security risks. He notes that companies like Microsoft and OpenAI already describe agents as digital colleagues, signaling a shift toward AI systems that operate independently rather than under case-by-case human approval.
GoKawiil's interpretation of the reporting above, not reported fact.
Apelblat's argument suggests that existing identity and access tools—OAuth grants, service accounts, session hand-offs—were built for human or task-bound use and may not hold up once AI systems act continuously and autonomously. This framing implies organizations could face new exposure if they don't rethink how credentials and permissions are issued to long-running AI agents, though the piece is written from the perspective of a security vendor with a stake in that problem.
- The op-ed identifies three phases of workplace AI risk: chat outputs, agent actions, and now persistent AI coworkers.
- Author Itamar Apelblat argues current access models—built for human oversight—won't scale to autonomous, always-on AI identities.
- Major AI vendors' language, like Microsoft's 'digital colleagues,' reflects an industry push toward persistent, independent AI agents.
Source: bleepingcomputer.com, 2026-09-30
Published there as: “AI's Third Wave: Coworkers Break the Security Model That Worked for Agents”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.