
AI brokers are shifting into manufacturing sooner than safety groups can govern them. They’re connecting to apps, dealing with information, calling APIs, and appearing throughout enterprise programs—usually with out the identical controls utilized to human customers.
In keeping with Okta’s World CISO Insights 2026 report, solely 47% of CISOs are assured they will establish each AI agent of their setting. Even amongst those that really feel assured about visibility, roughly 80% nonetheless fear that extreme entry could also be going unreviewed.
That’s the actual drawback: seeing an agent shouldn’t be the identical as controlling what it may well do.
Be part of Matt Immler, Regional CSO at Okta, for a sensible session on learn how to deliver AI brokers below stronger identification governance earlier than extreme entry turns into tougher to comprise.
Most Organizations Are Nonetheless Utilizing Yesterday’s Controls
AI brokers create a brand new identification problem, however many organizations are nonetheless managing them with controls designed for conventional service accounts.
Just one in 4 organizations surveyed has adopted a purpose-built framework for securing AI brokers. In the meantime, 21% nonetheless depend on shared credentials or broad-permission service accounts.
That makes fundamental questions tougher to reply:
- Which agent has entry?
- Who authorized it?
- What programs can it attain?
- Does it nonetheless want these permissions?
- Can its entry be revoked with out disrupting different providers?
As AI adoption grows, these gaps develop into harder to handle.
A greater mannequin is to deal with each AI agent as a first-class identification—with its personal proprietor, permissions, lifecycle, and entry opinions.
Shadow AI Needs Governance, Not Just Blocking
Security teams also have to deal with AI tools appearing outside normal approval processes.
Trying to block everything may slow adoption, but it does not solve the underlying governance problem. Teams need a way to discover AI agents, understand what they can access, assign ownership, and bring them under consistent controls.
Okta’s research suggests organizations with more mature identity governance are better positioned to manage this risk. They report less shadow AI, faster response to rogue agents, and lower concern around AI-enabled breaches.
The takeaway is straightforward: AI agent security is becoming an identity governance problem.
Security teams need to know what agents exist, what they can access, whether that access is justified, and how quickly it can be removed when risk changes.
Register for the webinar to learn how to govern AI agents as first-class identities, control shadow AI, and prevent excessive access from becoming the next major identity gap.
📅 Save Your Spot: Watch the Webinar

