When Your Shadow Comes to Work

Posted by Mike Walsh

8/15/26, 7:46 AM

shutterstock_2697928115

 

The next employee your company hires may not arrive alone. Alongside them will come a personal agent that knows their history, remembers what they forget and is authorized to act in their name. The company will see an external system seeking access. The employee may see part of themselves. That encounter will be the first operational test of distributed intelligence.

 

At first, Bring Your Own Agent (BYOA) sounds like the modern version of Bring Your Own Device (BYOD), the challenge companies faced when employees began connecting personal phones and laptops to corporate systems. The resemblance breaks down almost immediately. A phone carries applications, credentials and files. A mature personal agent will carry memory, learned methods, inferred preferences, delegated authority and a mental model of the person it represents. BYOD brought privately owned technology into the enterprise. BYOA will bring something closer to a second self.

 

Mark Zuckerberg recently published a sprawling essay, The Future Is for Everyone, outlining Meta’s philosophy for the age of superintelligence. Most of the reaction to Zuckerberg’s essay focused on his renewed support for open-weight models. Less attention went to the more consequential idea beneath it. Zuckerberg was presenting a political theory of AI based on a balance of power between intelligences. He rejects the idea that one perfectly aligned superintelligence could represent humanity’s conflicting values. Instead, he imagines billions of people possessing personal agents that understand their goals and work continuously across their relationships, health, career, finances and home life. These agents would give individuals the capacity to check the power of governments, corporations and the institutional intelligences acting upon them.

 

The line that resonated most with me was this: “As intelligence becomes abundant, the most important question will be how we direct it.” That is also the premise of my forthcoming book, Abundant Intelligence, co-authored with Nitin Mittal. Zuckerberg asks who should direct abundant intelligence across society. We ask how organizations should configure, route and govern it once digital labor becomes pervasive. Risk and cybersecurity may set the boundaries, but the design of intelligence will determine leverage and competitive advantage.

 

BYOA will be the point where two worlds collide. Companies will have their own agents, trained around institutional goals, policies and knowledge. Employees will increasingly possess agents of their own, carrying different histories, loyalties and objectives. The result will be a workplace populated by intelligences that do not all belong to the organization.

 

What does it mean to bring your own agent?

The term BYOA is already being used in several different ways. It can refer to employees using unauthorized AI tools, developers connecting preferred agents to an enterprise platform, workers building agents for their company, or businesses admitting third-party agents into a managed environment. For the purposes of this article, I mean something more specific: BYOA is the admission of an employee-controlled, persistent personal AI agent into an organization, with bounded permission to access information, participate in work and represent the employee.

 

Employee-controlled is the critical distinction. A corporate assistant personalized around an employee remains part of the institution’s intelligence. A genuine personal agent has an independent and continuing relationship with the individual. It follows them between jobs and may carry years of conversations, professional methods, private goals and accumulated patterns of judgment across organizational boundaries.

 

That distinction also exposes the tension inside Zuckerberg’s vision. Wide distribution does not automatically create personal sovereignty. An agent can be deeply personalized while remaining structurally dependent on the company that controls its model, memory layer, interface and compute. Meta says its agents should align with the goals of individuals rather than the values of the company, but the practical test will come when those interests diverge.

Personalization is not allegiance.

 

BYOD brought hardware across the technical perimeter. BYOA brings a decision-making system across the cognitive perimeter. A device carries applications, credentials and files. An agent interprets ambiguous situations, communicates with other agents, makes recommendations, initiates actions and continues working while its human principal is absent. It can learn from each interaction and apply that learning somewhere else. It may also act with access to both the private context of an individual and the proprietary context of an institution.

 

Autonomous personal agents create security problems that mobile-device management was never designed to solve. A company will need to know which person an agent represents, who built and operates it, what systems it can access, what authority it has been given, which actions it has taken and whether the employee actually authorized a particular decision. In February 2026, the US National Institute of Standards and Technology began exploring exactly these questions, including agent identification, authorization, auditing and non-repudiation. The fact that this work is only beginning indicates how immature the security foundations remain.

 

The legal questions are even harder. When a personal agent sends an email, agrees to a deadline, changes a record or negotiates with a corporate agent, whose action is it? Can an employee’s agent make commitments that bind the company? Who owns work jointly produced by a personal and institutional agent? Can an employer inspect a personal agent’s total memory during an investigation? Should personal agents be able to challenge a performance review, a compensation decision or the terms of an employment contract on the employee’s behalf?

 

These questions will eventually require new contractual, security and legal scaffolding. For now, their importance lies in showing why BYOA belongs in a different category from conventional workplace software.

 

The problem of what the agent learns

Organizations eventually made BYOD manageable by controlling access, separating corporate and personal data, restricting applications and remotely removing work information from privately owned devices. NIST’s BYOD guidance reflects this approach, combining enterprise mobility management with technologies for protecting organizational data while preserving some degree of employee privacy. A comparable boundary will be much harder to draw around a personal agent because the disputed asset will include the residue of collaboration: what the agent has learned after the work is complete.

 

Imagine an executive who has used the same personal agent for ten years. It has accompanied her through several roles and learned how she evaluates risks, communicates with management, handles difficult colleagues and recognizes the early signs of a failing project. She then spends five years at a company where the agent interacts with confidential documents, internal systems, corporate agents and thousands of consequential decisions.

 

When she leaves, deleting company files may be relatively straightforward. Separating institutional knowledge from her accumulated professional judgment will be far more difficult. Some of what the agent learned came from corporate information. Some came from her experience. Much of it emerged through the interaction between them. The recent legal dispute between Apple and OpenAI over trade secrets even gave this a new name: residual access.

 

The company may see proprietary knowledge that must remain behind. The employee may see part of the intelligence she developed through five years of work. A remote wipe could begin to resemble imposed forgetting. BYOD policies were designed to separate data. BYOA will force organizations to confront the ownership of learning.

 

Last week, I argued that grieving about which jobs that AI will replace is both unhelpful and melodramatic. The more interesting question is how people will reinvent their relationship with AI. I offered three new archetypes: the cyborg, the centaur and the cyberpunk. What I did not explore was the form through which those identities and power dynamics might enter everyday life.

 

A personal agent could embody all three archetypes at once. It will be a cyborg when it carries part of our memory, recognizes our patterns and participates in our judgment. It will be centaur when it works alongside us and the organization’s agents to interpret information, evaluate options and coordinate action. And It will become cyberpunk when it represents us against institutional intelligence, reconstructing the evidence behind a decision, identifying what a corporate system failed to consider and helping us argue back

 

The shadow that remembers

In J. M. Barrie’s Peter Pan, Peter escapes through the Darling family’s nursery window, but Nana closes it before his shadow can follow. The window snaps the shadow off. Mrs Darling examines it, rolls it up and stores it in a drawer. When Peter returns, he assumes that placing the shadow beside his body will make them rejoin. He tries to attach it with soap, fails and begins to cry. Wendy finally sews it back onto his foot, after which Peter dances around the nursery, delighted to feel complete again.

 

Peter’s shadow is recognizably part of him, yet it can become detached. It can be captured, examined, stored, recovered and reattached. Peter remains alive without it, but experiences its absence as a loss of wholeness.

 

It is a charming children’s story, but it is also a useful analogy for understanding what a mature personal agent could become. It will begin as a projection of the person, formed from their language, correspondence, preferences, decisions and relationships. Over time, it will accumulate memory and judgment. It will know the shape of its human because it has followed them through the world. In other words, it will become a shadow that remembers.

 

BYOD was largely a question of what device an employee could carry across the corporate perimeter. BYOA raises a more unsettling question: what part of the person comes with them?

 

Peter Pan could leave the nursery, but he could not bear to leave his shadow rolled up in someone else’s drawer. Employees may soon face the same dilemma. Will they be allowed to bring their intelligent shadow through the organizational window? What can it see once inside? What will it learn while it is there? And when the person leaves, can they take their shadow with them intact?

Topics: AI

New call-to-action

Latest Ideas