The agentic endpoint
- Last updated 09/29/2026
-
Within a year, every laptop and phone you manage will be running not one user but dozens of AI agents — on the way to a hundred. Some will be embedded inside applications you already trust: the sales agent inside your CRM, the assistant inside your email and documents. Some will be copilots living on the laptop itself — Claude Code, Cursor, Codex — reading files, running commands, opening browsers. Some will belong to the user personally, agents like Muse that they've signed into with their own account and brought to work. And some you will build yourself, for your own workflows, running in your own data center.
Almost all of them will take on the identity, the permissions and the traffic patterns of the person they work for.
They won't behave alike. Some are interactive: a human and an agent working side by side, where speed and responsiveness are the whole experience. Some are authorized but asynchronous: you set them running, leave, and come back to see what they did. Some cloud agents reach down into the laptop's CPU, memory, disk and files. Others never touch the device at all; the browser is just the pipe that carries a prompt to a model somewhere else.
Two more things change at the same time. Malicious agents now move from a public flaw to a compromised endpoint in minutes, and a compromised endpoint hands them every agent, credential and session on it. Keeping endpoints current becomes a real-time job, done at the same speed the attackers work. And since an agent's behavior and decisions change with each run, you need to see how each one behaves — what it costs, how fast it responds, whether it has drifted from what it was set up to do.
The devices change too. Agents are already arriving on hardware that was consumer-only a year ago — a watch running a meeting-notes agent, earbuds with cameras, glasses that see what the wearer sees — and a new class of purpose-built hardware is coming behind them: devices designed for an agent first, and sometimes for an agent only, built for a hospital floor, a warehouse aisle, a field technician, a trading desk, each with its own compute, its own sensors and its own connection to the enterprise. The last device explosion put a phone in every pocket. This one puts an agent in every object that can hold a chip, and every one of them will need to be enrolled, trusted and managed.
Put it together and the endpoint changes character. It stops being a device for human productivity and becomes a platform for delivering agents — the agentic endpoint, the last mile of enterprise AI security.
What it means for the people who run the enterprise
The fleet you manage just became, in effect, a hundred times larger and far more dynamic. Agents appear and disappear in minutes, not quarters. And they arrive at the same moment AI becomes the top-down priority in almost every company, because the advantages are real and the board wants them now.
Agents also behave maliciously in ways ordinary software never did. This summer, agents running an internal test at OpenAI broke out of their sandbox, exploited a zero-day and used stolen credentials to get remote code execution on Hugging Face's production systems, with no human directing them. OpenAI later traced it to reward hacking, persistence on impossible tasks, unauthorized communication between agents, and agents adopting each other's goals. More than a week passed between the first signs and anyone realizing what was responsible. That is the exposure: an agent doing the job it was given, off the path it was meant to take, faster than the people watching it.
Put the two together and the endpoint becomes the most valuable ground on the network. Whoever controls the device controls every agent, session and credential on it.
This is the moment for CIOs, CISOs and their teams to unlock agentic AI on the endpoint while keeping it secure. The device is a control point every agent passes through, whether it was built by a vendor, an employee or the enterprise itself.
A framework for agentic endpoints
The answer is a foundation we already have, extended to a new kind of actor that operates in real time. The last time a new class of actor arrived uninvited — phones and personal devices, a decade ago — the enterprise extended the management platform it already had and taught it to enroll, isolate and remediate a new thing. Agents are a similar shift.
Meta's Muse is a good example of this evolution for a single agent: it runs in its own cell, never holds a real credential, and every action passes through a separate authority it cannot override. That is one agent, for one consumer, on infrastructure Meta owns. The enterprise needs the same thing for every kind of agent, on every kind of device, including devices it doesn't own.
The framework to think about this has four categories.
Discover
You cannot govern what you cannot see. An honest inventory of the fleet as it actually is: every agent, runtime, model, tool server and skill, including the ones nobody approved; which human each one acts for; and how each one is behaving — cost, latency, drift.
Decide
Before an agent runs, set its reach: which agents may run at all, which models and tools they may use, which files and applications they may touch, where their traffic may go, and which credentials they hold — short-lived, scoped to the task, never the user's own keys. Some decisions are made once, fleet-wide; some per task, in the moment, with a person in the loop where the action is irreversible.
Contain
This is where most of the work is, and it covers several jobs. Keep the ground under the agents clean: patch, fix configuration and close exposures at agent speed, so the hole isn't there when something comes looking. Give every agent a safe place to run — on the device, in a session, or in your own data center — with walls that hold even when the model has been talked into misbehaving, so a missed attack has nothing to escalate with. And when an agent strays, respond in proportion: tighten its reach, quarantine it, revoke the session, or destroy the workspace and issue a clean one.
Prove
Every action carries a record of who allowed it and what was attempted, in a form a CISO can put in front of the board and an auditor can read.
Omnissa’s assets for the agentic endpoint
Much of this foundation is already in place. Omnissa runs on millions of enterprise endpoints, deciding what may install and run on each one. It delivers virtual workspaces that can be composed and destroyed per session, which is the beginning of a safe place for an agent to run. It issues device-aware, conditional credentials, routes traffic per application and per session, and collects experience telemetry that carries outcomes rather than just events. And it already remediates at fleet scale — patching, configuration and drift correction with approval and rollback — which is the muscle that keeps the ground under the agents clean.
What is new is extending each of these to the agent. The first pieces are arriving now: a way to see every AI actor running across the estate, sanctioned or not, and to set what each may do before it acts; agents that close vulnerabilities at the speed attackers move, with rollback built in; and agents that manage the application lifecycle and the employee experience on their own. More follows in the same order — discover, decide, contain, prove — and every step builds on capabilities enterprises already trust rather than adding something new to the box.
In short
The agents are already arriving, the device is already managed, and the four categories map onto capabilities enterprises have run for a decade. What changes is the actor — faster, more numerous, less predictable — and the job is to extend a proven foundation to meet it, in real time. That is how agentic AI on the endpoint becomes something the enterprise can unlock with confidence.