They can inherit credentials already present on the device and use them to reach enterprise systems without going through normal approval flows. That creates hidden delegation, where a local installation turns into persistent access across cloud, collaboration, and SaaS services. The risk is not the endpoint alone, but the access paths the agent can combine.