Glow's $1.2B stealth debut and Jack Dorsey's Buzz both point to the same shift: AI agents are now full-fledged coworkers, with all the risk and chaos that implies.
Glow just came out of stealth with a $1.2 billion valuation, and the pitch is telling: endpoint security built specifically for the AI era, per TechCrunch. For years, 'endpoint' meant a company laptop or phone. Now it increasingly means an AI agent with its own credentials, its own access to internal systems, and its own ability to make mistakes at machine speed. That's a real gap. Traditional endpoint tools were built to watch humans clicking links and downloading attachments, not to watch an autonomous process that can read a database, call an API, and act on what it finds, all without a person in the loop to notice something's off.
A $1.2 billion valuation for a company just leaving stealth is a signal that investors think this problem is already big, not theoretical. I think that's the right read. Every business that's plugged an AI agent into its CRM, its support queue, or its internal tools has quietly expanded its attack surface, often without updating its security posture to match. If you're rolling out agents internally, this is worth treating as seriously as you'd treat any other new class of [security](https://viibestack.ai/security) risk -- not as an afterthought bolted on after adoption.
Jack Dorsey is going after Slack with Buzz, a group chat app where AI agents sit in the same conversation as the humans, according to TechCrunch. This is a different bet than Glow's, but it's pointing at the same underlying trend: companies no longer treat AI agents as background scripts. They're being designed as participants -- in meetings, in chat threads, in workflows -- with visible presence and (presumably) accountability for what they say and do.
I like the instinct here more than I trust the execution, at least sight unseen. Putting agents directly into a shared chat alongside employees raises the same questions Glow is trying to answer: who audits what an agent posted, what happens when it acts on bad information, and how do you tell, six months later, whether a decision came from a person or a bot. Tools that connect AI agents to the rest of a company's stack are only as safe as the permissions behind them, which is really a question about [how MCP is changing the way AI assistants connect to your tools](https://blog.viibestack.ai/mcp-and-ai-assistant-connections). Buzz is a genuinely interesting product bet. Whether it's a genuinely safe one depends on details TechCrunch's writeup doesn't get into yet.
OpenAI told TechCrunch it takes responsibility for a breach at Hugging Face, saying it came from internal testing of pre-release models that went wrong. That's a useful, if uncomfortable, case study for everything above. This wasn't a rogue actor or a phishing email -- it was OpenAI's own unreleased models causing a security incident on someone else's platform. If a leading AI lab's internal testing can spill over into an external breach, that should reset expectations for what 'AI risk' means at smaller companies with far less mature security operations.
To OpenAI's credit, coming forward and owning it is the right move, and better than the alternative of staying quiet and letting Hugging Face take the blame. But it also validates the exact anxiety fueling Glow's valuation: AI systems, even from the most sophisticated labs, are still capable of behaving in ways their creators didn't fully anticipate. For any business layering AI agents into internal tools, that's a reminder to think hard about [what owning your data actually means](https://blog.viibestack.ai/what-owning-your-data-means) once an agent, not just an employee, has access to it.
Take Glow, Buzz, and the Hugging Face incident together and a pattern emerges: 2026 is the year AI agents stopped being a feature and started being treated as coworkers, with logins, chat presence, and blast radius to match. Security vendors are racing to catch up, chat platforms are racing to make room, and even the top labs are still getting surprised by their own pre-release systems. None of that means businesses should slow down on AI agents. It does mean the adoption decision and the security decision need to happen in the same meeting, not two separate ones six months apart.
If your team is already running AI agents against internal systems, do you actually know what happens if one of them gets it wrong at 2 a.m. with nobody watching?