> Okta bets on identity to control AI agents, but is identity enough?
[DATE: 23/09/2026 08:25]
[LANGUAGE: EN]
Concerns over agentic risks are rising, and identity and access management (IAM) giant Okta believes it’s making the moves of a would-be leader in this emerging cyber market.
“Identity is the primary control plane for securing AI,” said Okta CEO and co-founder Todd McKinnon in an earnings call in late August, telling investment analysts that the company’s customers see Okta as well-positioned to secure this agentic future. “And so we’re going after that on all fronts.”
“We think that being the system of record for agents in the enterprise and being the system of record for agent identity, in the fullness of time, could be the biggest category of cyber,” he added.
At the center of that strategy is Okta for AI Agents, an identity management and security platform for tracking and controlling agentic entities and activity.
The company is billing the solution as a blueprint for securing the agentic enterprise, and has kicked off its annual Oktane conference with a slew of enhancements aimed at managing agentic risk, including the expansion of its Agent SSO identity model, the ability to set rules for agent-to-agent interactions, and added policy and logging enforcement for interactions at runtime.
But even fully authenticated AI agents can go rogue and do harm, and there are other challenges ahead for the identity management company, experts say.
“Identity in itself is not the largest problem in the agentic world,” says Aisling Dawson, an analyst at ABI Research. “Authentication is only the first stage.”
Moreover, moving from human to agentic identities is also a challenge, given that AI agents operate at a very different scale than humans, Dawson notes. Vendors coming from the machine identity market already know how to handle this, she says.
That may put competitors from the non-human identity (NHI) side of the ledger in a better position for CISO budget in this area, especially as agentic identity also has agent-specific challenges, such as multi-hop delegation, she says.
The latest Hugging Face hack, for example, shows that runtime governance, behavioral monitoring, and excessive permissions are all rising threats, she says.
But Hugging Face would have been a much smaller event had there been better security practices in place, Ric Smith, president of products and technology at Okta, said in a media briefing last week. “There’s just basic primitives in security that were missed that allowed a lot of this to happen.”
That includes identity-related practices, such as the elimination of standing credentials, he said.
“Agentic AI is very interesting, and in some ways, the complexity of it makes us forget about the basic principles that we have to put in place to run a secure enterprise,” he said.
In addition, Okta’s new agentic gateway would have addressed some of the other issues that made the attack possible, he noted.
The agentic security space is a free-for-all
Gartner predicts that the average global Fortune 500 company will have more than 150,000 agents in use by 2028 — up from under 15 in 2025.
And security is not an afterthought. Headlines are rife with AI agents being used by attackers, being compromised, or going rogue and hacking other companies. OpenAI, Anthropic, and, most recently, Google, have all admitted that their AI agents have gone rogue and hacked other companies.
Gartner predicts that the market for securing AI will hit $2.8 billion this year, up 83% from 2025 — and grow to $4.8 billion in 2027 and $7.7 billion in 2028.
The identity security market, by comparison, is much larger and more mature. According to IDC, it was $29 billion in 2025 and is expected to grow to $56 billion by 2029.
The intersection of the two promises to be a hotly contested area.
Hyperscalers and third-party agentic development platforms have agentic security as part of their offerings. Identity and access management vendors, including Okta, Microsoft, and Ping, are expanding beyond human identities to AI agents.
Other companies are buying their way in — this year alone, Palo Alto bought CyberArk, CrowdStrike bought SGNL, and Zscaler bought Symmetry Systems.
“Everyone wants to own the traffic system of the agent economy,” says IDC analyst Emanuel Figueroa. “Identity vendors, cloud providers, AI platforms, and cybersecurity vendors all see an opportunity to become the control plane for autonomous actors.”
Identity providers are positioned well, he says, because agents operate through credentials, permissions, delegated access, and trust relationships. “The question is which layer enterprises ultimately trust to coordinate agent activity at scale.”
Okta could have an edge over Microsoft, says ABI’s Dawson, because it offers a more agnostic identity platform.
“Limiting vendor lock-in is increasingly a buy-side demand,” she says.
That’s partly due to sovereignty requirements, she adds, and is “bolstering the market positioning of players like Okta when compared to hyperscalers and agent provisioners like Microsoft.”
“Most enterprises are not looking for another dashboard,” says Figueroa. “They’re looking for fewer of them.”
Okta is in a unique position because of their focus on IAM and their broader platform independence, says Forrester analyst Geoff Cairns. “But the competitive landscape is getting more challenging.”