The "end user" in End User Computing is changing

For thirty years, EUC has meant one thing: putting a managed operating environment for application and data access in front of a person. That definition is now quietly evolving... non-human identities already outnumber humans in a typical enterprise by roughly 45 to 1, and AI agents are the fastest-growing slice of that population. These are spawned per task, per workflow, sometimes per sub-task, and frequently outlive the pilot that created them.

What has not changed is that identity remains the cornerstone in EUC. Every control that made EUC governable — conditional access, device compliance, least privilege, session audit — hangs off a known identity accessing a known workspace. Agents do not break that model… but they will stress-test it. The organizations that extend the identity-plus-workspace discipline to agents will scale; those that let agents inherit a human's credentials on a shared box will spend 2027 in incident response.

The applications that run the business still don't have APIs

The agent frameworks are ready and the models are capable; however, what is missing is the integration surface. Gartner puts roughly three-quarters of organizations on applications that lack modern APIs, and 71% of the Fortune 500 on mainframe-backed processes without adequate programmatic access. The claims system, the trade-settlement terminal, the order-entry green screen, the underwriting client — these are reachable by a person through a screen and by nothing else.

App refactoring is the standard answer to this problem, and it is a good one on a five-year horizon. It is also hard, expensive, and slow. Very slow. The death of the Win32 application has been forecast for two decades. Microsoft's own telemetry says more than 90% of desktop applications in active use on Windows 11 are still Win32 binaries, and Azure CTO Mark Russinovich reaffirmed in May 2026 that Win32 remains a first-class API for the foreseeable future. 

One of my favorite sayings goes as follows (originally attributable to the esteemed Shawn Bass) - "Three things will survive the nuclear holocaust: cockroaches, Twinkies, and Win32 apps". This continues to be proven year after year. 

VDI unlocks the application estate you already own

This is where the magic happens... instead of building agents an API, give them what employees already have: a managed and secure desktop with the application installed, authenticated, and entitled. The agent sees the screen, reads it, and operates the interface. The application never learns its operator isn't a person, and nothing about it is modified, rebuilt, or integrated.

Every Win32 and Linux application in the estate becomes agent-addressable on the day the agent gets a seat — not after the modernization program completes. That collapses time-to-value from years to weeks, and it changes the shape of the AI business case from "fund the integration" to "fund the outcome."

Don't call it a comeback — VDI has been here for years

VDI has spent years and years solving exactly the problem agents now present, for a user population that just happened to be human.

A secure remote execution environment for business applications. A virtual desktop delivers a known-good configuration every time — both the operating environment and the application stack, sealed in an image. That determinism is a convenience for people; for a vision-driven agent, whose reliability depends on the screen looking the same tomorrow as it did in testing, it is a prerequisite. The agent also inherits everything the human workflow already has: the thick client, the terminal emulator, the certificate store, the drive mappings, the SSO posture. Same workflows, same resources, same policy boundaries. And because agent workloads are short-lived by nature, ephemeral non-persistent desktops shrink attack exposure to the duration of the task. If something goes wrong, it goes wrong inside a box you delete at logoff.

Dynamic, elastic scalability. Agent demand spikes, executes, and dissolves. Pooled provisioning, autoscale, and instant reset were built for exactly this shape — standing up a fully entitled workspace in seconds and tearing it down when the work ends. Purpose-built agent sandboxes are rebuilding this capability from scratch where VDI platforms have it in production, with a decade-plus of operational hardening behind it.

The market has reached the same conclusion

Between May and August 2026, four platforms shipped or positioned agent-hosting capability, and they converged on one architecture without coordinating.

Windows 365 for Agents (Microsoft) reached general availability in mid-2026. Each agent gets its own Intune-managed Cloud PC and its own Entra agent identity — not a borrowed human login — and Conditional Access evaluates agent users the way it evaluates people. Agents check a Cloud PC out of a pool, work, and check it back in. Compute is metered hourly (roughly $0.40 in the US), with an optional per-machine monthly fee to keep capacity warm. Governance sits alongside in Agent 365 at $15 per agent per month.

Amazon WorkSpaces for AI agents (AWS) reached general availability on 1 July 2026. An administrator grants two discrete permissions on a desktop pool — computer input and computer vision — and the platform exposes a managed MCP endpoint that any agent framework can connect to. Screenshots are retained for audit through CloudTrail and CloudWatch. The agent capability carries no additional charge.

Omnissa positions Horizon as the secure host for agentic work, arguing from capabilities it already ships: contained and auditable isolation, IdP-integrated least-privilege policy, and a runtime stable enough for repeatable UI-driven work. Its most distinctive argument is commercial — concurrent-user licensing charges for sessions in flight rather than identities on a list, which fits bursty agent demand.
 Note: Omnissa ONE 2026 is currently in progress, and related announcements are expected. This section will be updated accordingly. 

Citrix splits the problem: NetScaler MCP Gateway governs agent-to-tool traffic, and SecurSpaces Flex hosts the agents in sandboxed, per-agent workspaces with DLP, RBAC, and audit logging, aligned to Gartner's emerging agentic development sandbox category.

Considerations before the first pilot

Agent identity management is immature. Only one vendor above has a first-party agent identity type with conditional access parity today. Everywhere else, agent identity is a service account with better intentions. Establish per-agent identity, scoped entitlements, and lifecycle (who retires an agent's identity when the workflow is decommissioned?) before the first pilot, not after the twentieth.

Compromise risk is evolving, not shrinking. An agent that reads a screen will act on whatever appears on it — including instructions placed there by an attacker. Zero-click prompt injection against a production AI assistant has already been demonstrated. Treat every rendered surface as untrusted input and gate consequential actions. Separately, reliability on long tasks is still evolving, so scope initial use cases to short, deterministic, reversible work. Think claims intake, not claims adjudication.

Get the economics right. Hourly consumption, warm-standby fees, per-agent governance licensing, and concurrency-based entitlement produce very different three-year costs depending on whether the workload is a steady trickle or a nightly surge. Model the actual duty cycle before selecting a platform. This is where we expect most early programs to get the numbers wrong.

Conclusion

The scarcest asset in agentic AI is not a model but a governed, instrumented, entitlement-aware fabric for provisioning workspaces on demand — and organizations with a mature virtual desktop estate already own one. The end user has changed; the discipline has not.

Start with an inventory of workflows blocked on missing integrations, ranked by volume and reversibility. Decide deliberately whether agents get their own estate or share the human one — the isolation, image, and licensing consequences are hard to reverse. Then bring the identity, security, and VDI teams into the same room before the first agent checks out its first desktop. That conversation, not the vendor selection, is where the program is won or lost.