Okta and RSA pitch identity controls for AI agents
Okta and RSA launched identity platforms to govern AI agents, while analysts say identity alone will not secure them.
Okta launched 'Okta for AI Agents' at its Oktane conference, casting identity and access management as the main control plane for AI agents, and its CEO said managing agent identity could become the largest cybersecurity category. CSO Online reports that the agentic security market is predicted to reach $2.8 billion in 2026 and $7.7 billion by 2028, with competition from hyperscalers, other IAM vendors, and acquisitions by Palo Alto, CrowdStrike, and Zscaler; ABI Research and Forrester argue identity is only the first stage and that runtime governance, behavioral monitoring, and scaled non-human identity management are also needed. A later report says RSA launched Agent ID for regulated industries, with Discover, Secure, and Govern modules that find AI agents and MCP servers, check tool calls against policy, and log actions, including an inline gateway that can allow, deny, or escalate calls with phishing-resistant human approval. RSA president Jim Taylor said a medium-sized global bank that prohibited agents still had more than 4,000, and described an unnamed company whose Salesforce instance went offline after an employee's agent downloaded the full customer database, which Salesforce treated as a denial-of-service attack. Gartner expects roughly 150,000 agents at a typical Global Fortune 500 firm by 2028, and IBM says shadow-AI incidents cost $670,000 more on average. The reports do not contradict each other; they cover separate vendor launches and different forecasts rather than the same figures.
- Okta launched 'Okta for AI Agents' at Oktane to manage and secure agentic AI identities; its CEO said managing agent identity could become the biggest cybersecurity category.
- CSO Online says the agentic security market is predicted to reach $2.8 billion in 2026 and $7.7 billion by 2028, and that Gartner expects the market for securing AI to grow rapidly.
- ABI Research and Forrester say identity is only a first step; runtime governance, behavioral monitoring, and non-human identity management at scale are also required.
- Competition cited includes hyperscalers, other IAM vendors, and recent acquisitions by Palo Alto, CrowdStrike, and Zscaler.
- RSA launched Agent ID for regulated industries, with Discover, Secure, and Govern modules that find AI agents and MCP servers, check tool calls against policy, and log actions for compliance.
- An inline gateway can allow, deny, or escalate tool calls using phishing-resistant human approval.
- A medium-sized global bank that banned agents still had more than 4,000; an unnamed company's Salesforce instance went offline after an employee's agent downloaded the full customer database, which Salesforce treated as a denial-of-service…
- Gartner expects about 150,000 agents at a typical Global Fortune 500 firm by 2028; IBM says shadow-AI incidents cost $670,000 more on average.
Coverage timelineoldest first · each row is one article
- · 6d agoOkta bets on identity to control AI agents, but is identity enough?
CSO Online· 55
Okta launches an AI agent identity platform, betting that managing agent credentials will be a major cybersecurity market.
- · 5h agoOne Bad Prompt Took Down a Company’s Salesforce: RSA’s Jim Taylor on Agent ID and Taming the 4,000 Shadow AI Agents Hiding in Your Enterprise
MarkTechPost· 62
RSA launched Agent ID to discover, secure, and govern enterprise AI agents after finding thousands of shadow agents.