A promising market exposes an operational gap
Okta’s August 26 earnings announcement positioned AI agents as a new growth opportunity for identity security. The company reported that revenue for its fiscal 2027 second quarter, which ended July 31, rose 11% year on year to $805 million, while subscription revenue increased 12% to $793 million. Remaining performance obligations, a measure of contracted subscription backlog, rose 17% to $4.858 billion.
The financial results do not isolate revenue from AI-agent security, so they do not prove that agents were the principal driver of the quarter. Okta instead credited momentum in its core workforce and customer identity businesses, alongside contributions from newer products led by identity governance. Nevertheless, management used the results to emphasise a strategic premise: software agents are becoming actors inside enterprise systems, and therefore require identities and tightly defined permissions.
That framing points to the security problem behind the AI boom. An assistant that merely drafts text is primarily a data-handling and model-risk concern. An agent that can look up customer records, submit payments, alter cloud configurations, write code or trigger workflows is different. It needs to authenticate to tools and services, receive permissions and make calls that have real operational consequences. Each connection expands the organisation’s identity perimeter.
Why AI agents are harder to govern than conventional software
Enterprises have long managed non-human identities, including service accounts, application credentials and automated jobs. AI agents complicate that familiar task because their activity can be dynamic, delegated and spread across multiple systems. A request from an employee may pass through an orchestrating agent, specialist sub-agents and external tools before an action occurs.
The central question is therefore not simply whether an agent has credentials. Security teams need to determine which agent acted, which person or business process initiated the task, which resources were available for that specific request, and whether the permission can be withdrawn immediately. Static credentials and broad roles create an obvious weakness: a compromised, manipulated or incorrectly configured agent may be able to act far beyond the task that originally justified its access.
This risk is amplified by scale. Organisations can create agents quickly through internal development platforms, software-as-a-service integrations and third-party frameworks. A limited pilot may have one tightly supervised connection; production deployment can create a web of agent-to-tool, agent-to-agent and agent-to-application relationships. In that setting, periodic access reviews designed for employees and ordinary service accounts are unlikely to be sufficient on their own.
The concern is not hypothetical vendor positioning. NIST’s 2026 analysis of public input on AI-agent security found broad agreement that agents create novel security threats and that established cybersecurity principles need adaptation for agent deployments. Its related work on agent identity and authorisation highlights identification, access control, auditing and accountability as practical areas needing attention.
Identity is necessary, but not the whole control plane
Okta’s response is to treat an agent as an identity-bearing entity rather than an extension of an employee account or a generic service account. Its AI-agent offering centres on discovering agents, assigning verifiable identity, governing access and making authorisation decisions at the point an action is requested. The intended model preserves an accountable chain from the initiating user through the agent to the target system.
That approach aligns with a basic security principle: least privilege should be specific to the action, duration and resource involved. An agent asked to retrieve the status of an order should not automatically receive standing rights to change customer data, export a database or approve refunds. Short-lived, narrowly scoped tokens and runtime checks can reduce the damage if a prompt injection, stolen credential or faulty instruction causes an agent to take an unsafe path.
Yet identity controls cannot make an agent trustworthy in isolation. They must operate alongside secure software development, tool-level guardrails, monitoring and human escalation procedures. OWASP’s guidance for agentic applications identifies risks that extend beyond login and permissions, including goal hijacking, tool misuse, identity and privilege abuse, supply-chain weaknesses, insecure communication between agents and cascading failures.
This distinction matters commercially as well as technically. The fast-growing market for agent security will not be won solely by the provider that issues credentials. Customers will expect interoperability across cloud platforms, software-as-a-service applications, APIs and emerging agent protocols. They will also require policy enforcement that is sufficiently fast and granular without making useful automation impractical.
The challenge is governance at machine speed
For security leaders, the practical issue is visibility before scale. The first task is to create an inventory of agents, the models and frameworks behind them, their owners, their tool connections, their credentials and the data they can reach. Shadow deployments deserve particular attention, because an agent built to solve a local workflow problem can become a privileged pathway into wider systems.
A defensible programme should then connect each agent to a named business owner and a defined purpose. Permissions should be limited to approved tools and data, privileged actions should require additional checks, and access should expire or be reauthorised rather than persist indefinitely. Logging needs to capture not merely that an API call occurred, but the relevant chain of user, agent, delegated authority and tool action. Security teams also need a tested means of halting an agent’s access when suspicious activity is detected.
Human approval remains important, but it should be focused on consequential actions rather than used as a superficial safeguard. If approval screens provide vague summaries of complex agent plans, people may routinely approve actions they cannot meaningfully assess. Effective controls combine clear task boundaries, policy-based enforcement and alerts that give operators enough context to intervene.
A strategic opening with a demanding burden of proof
Okta’s earnings demonstrate that its established subscription business remains financially resilient: it generated $234 million in operating cash flow and $227 million in free cash flow during the quarter. That gives the company capacity to invest in an emerging category while its core identity products continue to expand.
However, the AI-agent proposition also raises the standard by which identity providers will be judged. Customers will want evidence that an identity layer works across fragmented technology estates, can distinguish legitimate delegation from abuse, and supports investigation after an incident. They will also need to avoid treating the purchase of an agent-identity product as a substitute for redesigning risky workflows.
The broader conclusion is that enterprise AI is moving from an information problem to an authority problem. As agents gain the ability to act, the security question becomes who — or what — is authorised to do which task, under whose authority, and for how long. Okta is seeking to make that transition a major market opportunity. Its success will depend on whether enterprises can turn that principle into reliable controls before autonomous access becomes routine.
Sources
- Okta’s AI boom just created a new security problem — Yahoo Finance
- Okta Announces Second Quarter Fiscal Year 2027 Financial Results — Okta Investor Relations
- Summary Analysis of Responses to the Request for Information Regarding Security Considerations for AI Agents — National Institute of Standards and Technology
- OWASP Top 10 for Agentic Applications for 2026 — OWASP Gen AI Security Project



