Persistent AI coworkers could outlast the access models built for chatbots and task-based agents, according to Token Security co-founder and CEO Itamar Apelblat. In an opinion article published by BleepingComputer, he argues that systems with continuous access need their own identities, owners and controls for granting and revoking permissions.
Apelblat describes earlier AI tools as session-based chats, followed by agents that perform specific tasks. Persistent coworkers, he says, would need access to workplace systems without a person approving every action. Existing approaches often rely on human credentials, OAuth hand-offs or service accounts that were not created specifically for AI agents.
Long-lived access also raises the risk that an agent accumulates permissions across projects. Apelblat warns that several individually reasonable grants could combine into broader access than anyone intended. Audit logs can also identify the human whose permissions an agent used, rather than the agent itself.
He points to hosted ChatGPT and Anthropic chat products as examples: he says neither issues agents their own credentials through the OAuth client credentials grant. ChatGPT connectors, he adds, reject service accounts and JWT assertions, while APIs allow developers to provide static bearer tokens.
The article also cites OpenAI product lead Tara Seshan, who discussed agents’ need for access to data and infrastructure on Lenny’s Podcast in August 2026. It recalls Google’s Chip, a Workspace agent demonstrated at I/O in May 2024 with its own account, role and configured permissions. The supplied article text ends before completing its account of the demo.
Comments
0No comments yet. Be the first to comment.