August 8, 2026
AI Agents Need Somewhere to Live: Why Persistent Execution Environments Are Enterprise IT's Next Big Decision
For most of the last three years, an “AI agent” was really just a clever prompt: a model spun up, read some context, produced an answer, and disappeared. The infrastructure question barely mattered because there was no infrastructure to speak of. That assumption is now breaking. Agents that fix a multi-file bug over a weekend, chase down a vulnerability backlog over several days, or reconcile a general ledger over a full close cycle can’t live inside a single request-response cycle — they need somewhere to actually run, persistently, with their own identity, credentials, and audit trail.
That “somewhere” has quietly become one of the more consequential infrastructure decisions in enterprise AI. In the last two months alone, OpenAI bought a cloud execution startup specifically to give its coding agents a permanent home, and Microsoft shipped a version of Windows built to be rented out to agents instead of people. Neither move is about smarter models. Both are about real estate — and enterprise IT leaders who are still evaluating AI purely on model quality are about to find the more urgent decision is where these systems are allowed to live.
From API Call to Tenant: Why Agents Need a Place to Live
A chatbot answering a support ticket doesn’t need persistent infrastructure — it reads, responds, and exits. A governed fleet of coding, ops, and finance agents is a different animal entirely. These agents need to hold state across sessions, retain access to specific tools and repositories, and resume work exactly where they left off — sometimes days later.
That requirement is why OpenAI announced in June 2026 that it would acquire Ona, the cloud execution platform formerly known as Gitpod, and fold it directly into Codex. Ona’s technology gives agents secure, persistent environments where they can hold onto tools, systems, and context over time, rather than starting from zero on every prompt. Crucially, the execution itself runs inside the customer’s own cloud, with OpenAI supplying only the model and orchestration layer on top — a split that hands enterprises control over data boundaries and security policy without limiting what the agent can actually do.
The Limits of Ephemeral, Prompt-Response Agents
The work OpenAI is targeting makes the case for itself: running a full test suite and fixing failures across a large repository over multiple sessions, modernizing a legacy application where context needs to persist across days, or working down a vulnerability backlog without losing progress every time someone logs out. Codex passed 5 million weekly users by early June 2026, up from 4 million just six weeks earlier — real evidence that “agent needs a persistent home” moved from theoretical to load-bearing in a matter of months.
Three Signals the Shift Is Already Underway
Ona isn’t an isolated data point. Three separate developments over the past year point at the same underlying trend: enterprises are starting to treat “where the agent runs” as a first-class procurement and governance question, not an implementation detail.
Microsoft Built an OS Product for This
Microsoft first outlined Windows 365 for Agents in January 2026 and pushed it into public preview ahead of Build 2026: pools of policy-controlled, Intune-managed Cloud PCs that spin up the moment a user invokes an agent and return to the pool once the task finishes, billed at roughly 40 cents per hour of active use. It’s a genuinely new SKU: an operating system product built for a non-human tenant, complete with the identity, policy, and endpoint-management controls IT already uses for human employees. Microsoft is betting that agents will need the same governed desktop infrastructure people do — just rented by the hour instead of assigned to a badge.
The Analysts Are Already Pricing This In
Gartner’s now-widely-cited forecast puts hard numbers on the pace of change: 40% of enterprise applications will feature task-specific AI agents by the end of 2026, up from under 5% in 2025 — an eightfold jump in a single year. That kind of density means the “where does this agent run, and under what policy” question stops being a one-off architecture review and becomes a repeatable, auditable process, the same way server provisioning or SaaS onboarding did a decade earlier.
Enterprise Buyers Are Asking Different Questions
Where procurement conversations in 2024 centered on model benchmarks, 2026 conversations increasingly start with the execution environment: Is it inside our VPC? Does it support our identity provider? What’s the audit trail for every tool call an agent makes? Vendors that can’t answer those questions in a sales call are increasingly losing the deal before the model comparison even starts — a shift our own writing on action-layer governance predicted was coming as agents graduated from advisory tools to systems that actually take action.
The New Attack Surface: When the Execution Layer Becomes the Target
Persistent, tool-connected execution environments solve a real capability problem — but they also hand attackers a much bigger target than a stateless chatbot ever was. An agent that holds live credentials, a standing connection to internal tools, and days of accumulated context is a far more valuable thing to compromise than a single prompt-response exchange.
CVE-2026-25253: The Wake-Up Call
That risk stopped being theoretical in early 2026. CVE-2026-25253, affecting the popular open-source agent runtime OpenClaw, carried a CVSS score of 8.8 and let a remote, unauthenticated attacker achieve full remote code execution with a single click, by exploiting a WebSocket connection that transmitted a user’s authentication token without confirmation. More than 40,000 OpenClaw instances were found exposed on the public internet at disclosure in February 2026, with 63% assessed as actively vulnerable — a number that later scans put at well over 100,000 exposed instances as security firms kept scanning through the spring. It was patched within days of disclosure, but the underlying lesson outlasted the patch: once an agent has a persistent runtime and standing tool access, a single flaw in that runtime can compromise everything the agent was ever trusted to touch — a dynamic we examined in detail after OpenAI’s own sandbox escape incident earlier this year.
Most Agents Are Still Running Unsupervised
The uncomfortable part is that most organizations aren’t watching this layer closely yet. Security researchers tracking agent deployments broadly agree that a large share of production agents run in fragmented environments — local machines, shared VMs, unmanaged cloud instances — where identity, policy, and logging are inconsistently enforced, if they exist at all. That gap is exactly why our earlier piece on AI agent security risks argued every agent needs a clear identity and a limited, auditable scope of access — advice that applies with even more force once the agent has a persistent place to live and standing credentials to lose.
What This Means for Enterprise IT Leaders
None of this means enterprises should slow down agent adoption — the productivity case is real and the market is moving regardless. It does mean the execution environment deserves the same procurement scrutiny that used to be reserved for the model itself.
Questions to Ask Before You Deploy
Before greenlighting a new persistent agent, IT and security teams should be able to answer a short list of questions: Where physically does this agent execute — our VPC, the vendor’s cloud, or an unmanaged local environment? What identity does it authenticate as, and is that identity scoped to only what the task requires? Is every tool call logged to an audit trail that a human can review after the fact? And what happens to the agent’s credentials and accumulated context if the environment itself is compromised?
Treat the Environment Like You’d Treat a New Employee’s Laptop
The most useful mental model is the one Microsoft’s own product implicitly encodes: a persistent agent environment deserves the same lifecycle discipline as a managed employee device — provisioned with least-privilege access, monitored continuously, and decommissioned cleanly when the task or the agent’s role ends. Enterprises that already have a mature endpoint management practice have a real head start here; the tooling concepts translate, even if the tenant is a piece of software rather than a person.
Conclusion
The model race will keep generating headlines, but the more consequential shift for enterprise buyers right now is happening one layer down, in the infrastructure that decides where an agent actually lives while it works. OpenAI’s acquisition of Ona and Microsoft’s Windows 365 for Agents are the clearest signals yet that persistent execution environments are becoming standard enterprise infrastructure — and CVE-2026-25253 is the clearest signal yet that securing that layer isn’t optional. The practical takeaway for IT leaders: before approving the next agent deployment, ask where it will run, who can audit it, and what happens if that environment is breached — not just how good the model behind it is.
Frequently Asked Questions
What is a “persistent execution environment” for an AI agent?
It’s a standing, reusable environment — typically a cloud sandbox or virtual machine — where an AI agent can hold state, retain access to tools and credentials, and resume long-running work across multiple sessions, instead of starting fresh with every prompt.
Why did OpenAI acquire Ona?
OpenAI acquired Ona, the cloud execution platform formerly known as Gitpod, to give Codex agents secure, persistent cloud sandboxes so they can work on tasks like large repository fixes or legacy modernization over multiple days without losing context.
What is Windows 365 for Agents?
It’s a Microsoft product, first outlined in January 2026 and moved into public preview ahead of Build 2026, that provisions policy-controlled Cloud PCs specifically for AI agents to run in — billed by the hour and returned to a shared pool once the agent’s task is complete.
Is CVE-2026-25253 still a risk to my organization?
The specific OpenClaw vulnerability was patched shortly after disclosure in early 2026, but the underlying risk pattern — persistent agents with standing credentials and unmonitored runtimes — remains relevant to any organization running self-hosted or lightly governed agent infrastructure.
Do we need a dedicated execution environment for every AI agent we deploy?
Not for simple, stateless tasks like a single Q&A or summarization call. But any agent that needs to hold credentials, access internal tools repeatedly, or resume multi-day work should run in a governed, auditable environment rather than an ad hoc local or shared setup.
How should we start evaluating agent execution environments?
Start by mapping which of your current agents are stateless versus persistent, then require vendors to answer concrete questions about deployment location (your VPC vs. theirs), identity scoping, audit logging, and credential handling before approving any new persistent deployment.
Sources
- OpenAI to acquire Ona - OpenAI’s official announcement of the Ona acquisition and its rationale.
- OpenAI buys Ona to help rein in AI agents - InfoWorld’s analysis of what Ona’s technology adds to Codex.
- OpenAI Buys Ona To Run Codex Agents Inside Enterprise Clouds - Forbes breakdown of the enterprise cloud execution model.
- OpenAI Acquires Ona to Run Codex Coding Agents for Hours Without Your Computer On - Tech Times coverage including Codex weekly user figures.
- Windows 365 for Agents: The Cloud PC’s next chapter - Microsoft’s official announcement of Windows 365 for Agents.
- Windows 365 for Agents, AI Cloud PCs Launch in Preview - Petri’s coverage of features and pricing.
- Gartner Predicts 40% of Enterprise Apps Will Feature Task-Specific AI Agents by 2026 - Gartner’s original press release and forecast.
- OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link - The Hacker News report on CVE-2026-25253 and exposure figures.
- CVE-2026-25253: 1-Click RCE in OpenClaw Through Auth Token Exfiltration - SOCRadar’s technical breakdown of the vulnerability and CVSS score.
Have a project like this in mind?
Tell us what you're building — we'll help you scope it and ship it.
Talk to usKeep reading

September 30, 2026
Dots Are Here: What OpenAI's Always-On Agents Mean for Enterprise Oversight

September 29, 2026
Meta's Muse Goes Enterprise: What the New Meta Enterprise Platform Means for Your AI Vendor Strategy

September 26, 2026