Okta AI Security Risks
· marketing
The AI Identity Crisis
The rise of artificial intelligence (AI) in the workplace has brought about many benefits, including increased productivity and improved accuracy. However, it also creates new challenges for businesses and their IT departments. One pressing concern is securing these autonomous agents, which increasingly have access to sensitive data and systems.
Okta, a leading provider of identity-management software, reported an 11% increase in revenue in the past quarter, with subscription revenue up 12%. According to CEO Todd McKinnon, every agent needs a trusted identity and clear controls over what it can access and do. This problem is similar to the one businesses faced with employee passwords, but now they must also worry about AI “workers.”
The use of autonomous AI agents is becoming more common in mainstream commercial IT. They’re used for tasks like reading emails, updating customer records, querying databases, and triggering corporate processes. While this may seem convenient for businesses, it creates new security risks. If these systems are compromised, they can cause significant damage.
One key issue is that AI agents need their own authentication credentials, permissions, and audit trails. This adds complexity for IT departments to manage. Okta has released software designed to find AI agents, enforce least-privilege access, and centrally manage what these agents may do. However, this creates a new potential security category: companies may soon have to pay to govern armies of digital workers.
The promise of AI agents is that they can automate tasks, freeing up human employees to focus on more strategic work. But if these systems are not properly secured, the autonomy they offer becomes a liability rather than an asset. Verizon’s 2026 breach research found that shadow AI usage has risen to 45%, increasing the risk of data loss.
The economics of this problem are clear: IBM estimates that the average hack costs over $5 million globally. Some attacks on AI models are even more costly. Okta’s pitch is resonating with businesses, who have reported significant operating cash flow and free cash flow during the quarter. Remaining performance obligations have increased by 14%.
For individuals, this means an unseen layer of identity-security software is critical to their interactions with technology. They may not realize they’re using it when logging in or verifying identities. With AI agents, sensitive data can be fed into these systems, causing serious problems.
The security question has shifted from “Who has access to my data?” to “What has access to my data?” This problem will only grow in importance as AI agents become more widespread. Securing these systems is not just a technical issue but also one of educating users about the risks and benefits of using them.
As Wall Street continues to drive Okta’s stock higher, it’s clear that businesses face many challenges in securing their AI agents. The issue is not just technical but also cultural: companies may take longer than expected to implement these systems or huge software platforms may package identity controls into their offerings.
For now, the AI identity crisis remains a pressing concern for businesses and their IT departments. As we move forward with increased automation, it’s essential that we address this issue head-on, ensuring our digital workers are secure and trustworthy.
Reader Views
- ABAriana B. · marketing consultant
The real concern here isn't just securing AI agents but also understanding that this is not just about tech, it's about organizational culture and change management. Businesses will need to rethink their entire approach to access control and data governance to accommodate these digital workers, which can be a daunting task. What's often overlooked in discussions around AI security is the human factor - how do you train employees to work alongside these autonomous agents without compromising their own roles or introducing new vulnerabilities?
- MDMateo D. · small-business owner
As Okta continues to rake in revenue from its identity-management software, one thing's clear: businesses are just starting to grasp the magnitude of AI security risks. The article touches on the need for separate authentication credentials and permissions for AI agents, but what about accountability? If an AI system is compromised, who's responsible - the vendor, the IT team, or the business itself? Companies need to start thinking beyond just securing these digital workers and consider the broader implications of introducing autonomous systems into their operations.
- TSThe Stage Desk · editorial
The real challenge with AI security lies in ensuring that autonomous agents are not just identity-managed, but also risk-assessed. Okta's solution may help with authentication and access controls, but what about the potential for AI-driven lateral movement? If an agent is compromised, can it spread malware or exfiltrate data through other connected systems? The industry needs to move beyond mere identity management and focus on behavior-based monitoring and anomaly detection to mitigate these risks.