The endpoint is becoming the AI workbench.

For the past few years, most discussions about enterprise AI have focused on models, cloud platforms and data.

That made sense while AI was mainly consumed through a chatbot. A user submitted a question, the model generated an answer, and the interaction largely ended there.

But the chatbot is clearly not the final interface.

The direction is now much clearer. 

OpenAI has brought ChatGPT Work and Codex into the same desktop application. Work can use local files and desktop applications with the user's permission, while Codex can work with local folders, repositories, terminals and developer tools. Anthropic is following a similar pattern with Claude Cowork for knowledge work and Claude Code for development. Microsoft is also extending Microsoft 365 Copilot with Cowork.

The product names will change. What matters more is where the work happens.

The endpoint is becoming the AI workbench

The model may still run primarily in an external cloud environment, but an important part of its operational context sits on the endpoint.

That is where documents are opened, applications are installed, browser sessions are authenticated and employees access company resources. It is also where agents can increasingly read and modify files, interact with applications, run commands and coordinate work across several tools.

Modern devices already provide considerable memory, storage and local processing capacity. Combined with cloud-hosted models, they become execution environments capable of producing documents, analysing information, developing applications and automating repetitive work.

The endpoint is no longer simply displaying an answer generated somewhere else.

It is becoming one of the places where the agent performs the work.

This distinction matters for endpoint engineers. Managing the operating system, applications and compliance status is still necessary, but we also need to understand what the user, and increasingly the agent acting on their behalf, is allowed to do with the device.

Endpoint management without process knowledge will not be enough

An agent does not understand organisational boundaries unless those boundaries are represented by permissions, policies, application controls or explicit instructions.

Depending on the product and configuration, it may have access to local files, cloud storage, browser sessions, collaboration platforms, internal applications or development environments. Each connection increases what the agent can accomplish. It also increases the consequences of a bad instruction, excessive permission or compromised source of context.

The obvious risks include sensitive-data leakage and poorly controlled access to business information. Other problems may be less visible during early adoption of AI in the organization:

  • agents performing actions based on incomplete or incorrect context;
  • employees approving actions without understanding their impact;
  • sensitive content moving between applications with different controls;
  • automation operating through identities with excessive privileges;
  • scripts or documents being generated and then used without appropriate validation;
  • malicious content attempting to influence an agent through prompt injection;
  • insufficient monitoring when a task crosses several applications or systems.

The human factor remains significant. Giving someone a more capable tool does not automatically improve their judgement. In some cases, it simply allows a poor decision to be executed faster and at a larger scale.

This is why enterprise AI strategy cannot be separated from endpoint, identity and data governance. 

Security teams, workplace engineers and business owners need to agree on which processes can be delegated, which information can be accessed, what permissions are necessary and where human validation must remain mandatory.

You cannot govern these tools only from a model administration portal.

You need to understand the complete execution chain. A useful way to approach the problem is to look at it from the agent itself to the business action it is ultimately allowed to perform.

The endpoint sits between production and control

In one sense, none of this is new. The endpoint has always been where corporate controls meet operational reality.

Security baselines, device compliance, identity protection, application control and information protection look relatively clean in architecture diagrams. Real environments are less tidy. Users work with local files, legacy applications, personal workflows, browser extensions, temporary exports and tools that were never considered in the original design.

Agents are entering that same environment. The difference is the speed and scale at which they can operate.

A user can make one poor decision and manually apply it to a few files. An agent can potentially repeat the same decision across hundreds of files or several connected systems before someone notices. The exact impact depends on the permissions and tools available to the agent, which is precisely why those boundaries matter.

The same scaling effect also applies to attackers. Agentic tooling can reduce the effort required to automate parts of reconnaissance, social engineering and other attack workflows, while defenders are still operating many controls designed around primarily human interaction.

That makes endpoint architecture more strategic than it has been for years.

Blocking everything is not a strategy

Some organisations will react by closing every door.

They will disable agents, restrict integrations and prevent employees from experimenting with new tools. That can reduce immediate exposure, but prohibition alone does not remove demand. If employees can obtain equivalent capabilities through unmanaged applications or personal accounts, part of that experimentation may simply move outside approved tooling, logging and governance.

Other organisations will make the opposite mistake. They will enable broad capabilities because AI adoption has become an executive objective, without establishing ownership or understanding which business processes are actually being delegated.

Neither approach provides a sustainable operating model.

A pragmatic strategy starts by identifying where agents provide useful capabilities and what those use cases require. From there, the organisation can define acceptable use cases, prohibited actions, data boundaries, identity requirements, monitoring and validation points.

Not every process needs the same controls.

An agent helping prepare a presentation does not carry the same risk as one modifying production code, processing confidential documents or executing actions in an administrative portal. Governance should reflect those differences rather than treating "AI" as a single risk category.

The objective is not to make agents harmless. A tool with no access to relevant information and no ability to act will provide limited value.

The objective is to give agents controlled capabilities inside a managed environment.

Endpoint teams need a broader view

Endpoint engineers cannot remain focused only on deployment profiles, configuration policies and compliance dashboards.

Those controls still matter, but they cover only part of the problem.

The endpoint engineer of the agentic era needs to understand identities, permissions and business workflows — not just devices.

We need to understand the applications being used, the identities behind them, the information they process and the business workflows they support. We also need closer relationships with security, identity, data protection, application owners and the business teams defining how these agents will actually be used.

This is already visible in the products themselves. OpenAI's desktop Work experience can access local files and applications when permitted. Anthropic describes Claude Cowork as running on the user's desktop with access to a user-selected workspace, using isolation mechanisms to restrict what the agent can see. Even Microsoft Cowork introduces endpoint considerations such as network reachability, Conditional Access application identities and service dependencies.

These are not only AI platform questions. They are workplace architecture questions.

The organisations that close every door risk pushing useful experimentation elsewhere or missing valuable use cases. The organisations that leave every door open will eventually discover how quickly agentic tools can amplify weak permissions and weak governance.

The difficult work sits between those positions: building an endpoint environment where agents can be useful without being invisible, capable without being unrestricted, and integrated into business processes without operating beyond the organisation's control.

Sources

Post a Comment

0 Comments