By  Insight UK / 2 Sep 2026 / Topics: Cybersecurity
For most organisations, artificial intelligence has so far been synonymous with the cloud. A user submits a request to Microsoft Copilot, ChatGPT, Gemini or another enterprise platform, processing takes place somewhere else, and a response is returned across the network. The first model has driven rapid adoption, with 56% of organisations having already implemented an AI-enabled work model¹, and governance programmes have grown up around the same assumption of central delivery.
The second phase looks different. AI-enabled PCs with dedicated Neural Processing Units make it practical to run sophisticated workloads directly on end-user devices, and open-source models are becoming smaller, faster and more capable. With 50% of organisations expecting their PC fleet to be AI-enabled by 2028², intelligence is moving closer to the work, the data and the user, and it may arrive sooner than many governance programmes anticipate.
For security leaders, the location of the model matters less than the autonomy that travels with it. Local AI can improve privacy, performance and cost predictability. Local agents, however, operate outside the control points that cloud AI governance depends on, and that gap is the subject of this article.
There are clear business reasons to move some AI workloads to the endpoint. In regulated sectors and across the public sector, local processing reduces the need to send sensitive information to external services, making data sovereignty, confidentiality and third-party exposure easier to manage. Operationally, local models reduce latency, keep working when connectivity does not and lessen dependency on external services.
The third driver is economics. Consumption-based pricing feels manageable during experimentation, but as adoption grows from hundreds to tens of thousands of users, and agentic AI begins executing many actions for each human interaction, cloud inference costs become significant and hard to predict. For some workloads the question becomes one of economic efficiency: why pay for cloud inference when capable endpoint hardware already exists?
Cloud AI will remain essential for the most demanding work; the emerging pattern is hybrid, with routine or sensitive tasks running locally and complex work staying in the cloud.
The security conversation changes when we move beyond models to agents. Generative AI responds to prompts; agents take action. They gather information, interact with applications, orchestrate workflows and update records, in effect becoming digital workers acting on behalf of a user.
To be useful, agents need access to the same resources employees use every day: files, email, browsers, collaboration platforms and line-of-business applications. Those resources live on and around the endpoint, so that is where many agents will run. Early open-source projects such as OpenClaw show where this leads, and enterprise-supported equivalents are beginning to emerge.
Adoption will not wait for permission. Employees already use free AI tools at nearly twice the rate of employer-provided ones, 37% versus 21%³, and locally installed agents follow the same grassroots path: downloaded, configured and extended by users, on hardware increasingly capable of running them.
When AI is consumed as a centrally managed cloud service, the provider gives the organisation a natural control point. Tenant policies restrict what the service can reach, administrative consoles show what is deployed, API gateways can inspect traffic, and provider-side logs record activity.
An agent running on a laptop has none of this by default. It executes under the user’s local credentials, its configuration and plugins live in files on the device, its connections to internal systems are indistinguishable from the user’s own, and it can be installed, extended or updated without passing through change control. Distributed across thousands of endpoints, this creates three risks that centrally delivered AI does not.
1. A Compromised Endpoint Now Includes a Digital Worker
Today, a compromised endpoint gives an attacker the user’s data, applications and permissions. An AI PC hosting a local agent gives them considerably more: a capable assistant that can search enterprise knowledge, map internal systems and automate actions at machine speed. Because the agent runs entirely on the device, there is no provider-side anomaly detection, throttling or kill switch to fall back on.
What could go wrong? A compromised local agent accelerates the attack
A threat actor compromises a single employee device and inherits an agent already authorised to locate sensitive information and act across internal systems. Reconnaissance that once took days of manual effort completes in minutes, entirely on the endpoint, with nothing for cloud-side AI controls to observe.
2. Local Agent Drift Is Invisible to Central Inventory
Agents are deployed for a purpose, then accumulate capability. In a managed cloud service, new connectors and permissions at least appear in an administrative console. On the endpoint, capability growth happens in local configuration files and stored credentials, and nothing changes in any system of record. A device fleet can quietly accumulate thousands of agent-to-system connections that no asset register or identity platform has ever seen.
What could go wrong? A low-risk assistant quietly gains high-impact access
An agent approved to summarise documents is later connected by its user to collaboration platforms, a CRM system and workflow tools, using API tokens stored on the laptop. It can now retrieve customer data and update business records, yet centrally it still looks like a document summariser, if it is visible at all.
3. On-Device Actions Escape the Audit Trail
Security monitoring assumes activity is performed either by users or by known software, and a local agent blurs both. Its inference happens on the device, so no API gateway sees the prompts or the decisions, and its actions reach internal systems through the user’s own sessions and credentials. Hundreds of legitimate-looking operations per hour become normal, and the reasoning behind them appears nowhere in the logs.
What could go wrong? A harmful action cannot be attributed with confidence
A critical record changes and sensitive information is disclosed. Investigators can see that the user’s account performed the action from the user’s device, but cannot determine whether the user, the local agent or an attacker abusing that agent initiated it, because the agent’s on-device reasoning was never recorded.
Prohibition rarely works for technologies that deliver real productivity, and the shadow AI figures above suggest it would fail here too. A more practical approach is to build visibility, governance and control around agents before local deployment becomes widespread. Most security architectures were designed to govern users, applications and data; agent management now needs to become a discipline in its own right.
| Priority | What it means |
|---|---|
| Discover local AI usage | Identify which AI tools, models and agents are already operating across the environment, including those installed and configured directly on endpoints. |
| Extend identity governance to agents | Treat every agent as a digital identity with a named owner, defined permissions, access controls and accountability, whether it runs in the cloud or on a device. |
| Define agent approval policies | Establish clear criteria for approved models, agents, integrations and automation frameworks, including what may run locally. |
| Prepare endpoint strategies for AI PCs | Evolve device management, monitoring and data protection so that AI PC deployments include agent controls from day one, ahead of the refresh horizon. |
| Monitor behaviour, not just access | Capture agent activity on the endpoint and assess whether it is appropriate, explainable and aligned to business intent, going beyond checks of technical permission. |
Just as organisations built mature disciplines around endpoint, identity and cloud governance, they will need equivalent capability for AI agents, and the endpoint is where that capability will be tested first. Emerging agent governance platforms that discover agents, apply policy, monitor behaviour and integrate with identity and security controls may become as central to the next decade as endpoint detection and response was to the last.
Whatever tooling is chosen, governance must be able to answer six practical questions:
AI at the endpoint is the product of durable forces: better hardware, growing privacy expectations and the need to control AI economics at scale. The future will be hybrid, with cloud and local intelligence each used where they deliver the greatest value. What changes with the edge is that intelligence increasingly operates where central controls cannot see it.
With improving cybersecurity cited as the number one transformation priority for organisations⁴, governance of AI-enabled endpoints and the agents they host belongs on the boardroom agenda now. Security teams have spent decades managing users, devices and applications; the next challenge is managing autonomous digital workers. The organisations that succeed will establish visibility, identity and accountability for those workers before adoption outpaces control.

Rob O’Connor is EMEA Chief Information Security Officer (CISO) and Cybersecurity Practice Leader at Insight. He is responsible for cybersecurity governance and risk management across the region while also helping organisations improve their security posture through modern managed security services and strategic advisory engagements. Rob is a recognised contributor to the cybersecurity profession, with particular interests in cyber resilience, AI governance, regulatory compliance and the practical application of security to support business growth and innovation.
Download the solution sheet for Managed AI Governance ServiceDiscover Insight's Digital Workplace
¹ IDC, Digital Workplace in the AI Era (June 2026): 56% of European organisations have already implemented an AI-enabled work model (page 4).
² IDC, Digital Workplace in the AI Era (June 2026): 50% of organisations expect their PC fleet to be AI-enabled by 2028 (page 8).
³ IDC, Digital Workplace in the AI Era (June 2026): 37% of employees use free AI tools versus 21% using employer-provided tools (page 5).
⁴ IDC, Digital Workplace in the AI Era (June 2026): improving cybersecurity is the number one modernisation and transformation initiative organisations plan to start in the short term (page 10).
Report: Digital Workplace in the AI Era: Optimising Investment, Talent and Experience to Drive Business Outcomes, IDC, June 2026, sponsored by Insight.