{"id":613426,"date":"2026-05-31T09:13:18","date_gmt":"2026-05-31T09:13:18","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/613426\/"},"modified":"2026-05-31T09:13:18","modified_gmt":"2026-05-31T09:13:18","slug":"okta-writes-its-own-license-to-kill-rogue-ai-agents","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/613426\/","title":{"rendered":"Okta writes its own license to kill rogue AI agents"},"content":{"rendered":"<p>Rogue agents are dangerous, but eliminating them is never easy.\u00a0<\/p>\n<p>Jason Bourne, Ethan Hunt, and James Bond have each run afoul of their governance at various junctures, yet stopping them takes sequel after sequel until all the loose ends are tied up and they eventually die or retire, only to get rebooted.\u00a0<\/p>\n<p>It\u2019s not so different in the world of AI agents.\u00a0<\/p>\n<p>Okta leaders, citing the company&#8217;s own research, say enterprises are deploying AI agents faster than they are securing them, with <a href=\"https:\/\/www.okta.com\/newsroom\/articles\/ai-agents-at-work-2026-agentic-enterprise-security\/?utm_source=chatgpt.com\" rel=\"nofollow noopener\" target=\"_blank\">92 percent<\/a> of executives reporting moderate or widespread use of autonomous AI agents, but only 22 percent saying their organizations have identities tied to those agents.<\/p>\n<p>\u201cThat is a real problem,\u201d Okta president and chief operating officer Eric Kelleher said during the company&#8217;s earnings call on Thursday. \u201cIt&#8217;s a measurable, quantifiable exposure customers have right now within their companies, and they need to invest to fix it.&#8221;\u00a0<\/p>\n<p>In short, when agents go sideways, someone has to handle the dirty work.\u00a0<\/p>\n<p>Okta CEO Todd McKinnon told investors that\u2019s what <a href=\"https:\/\/www.okta.com\/blog\/ai\/okta-for-ai-agents-general-availability\/\" rel=\"nofollow noopener\" target=\"_blank\">ServiceNow<\/a> was asking for when the ITSM market leader came calling.\u00a0<\/p>\n<p>\u201cWhat they were really interested with Okta was this kill switch capability,\u201d McKinnon said during earnings. \u201cWhen agents go awry and agents aren&#8217;t following the policy, how do you shut them down? \u2026 The one thing we do really well, and that they wanted from us, is the ability to sever the connections, the access tokens, the actual logical connection at the authorization layer to the backend resources, and we&#8217;re really good at that.\u201d\u00a0<\/p>\n<p>ServiceNow has <a href=\"https:\/\/www.theregister.com\/software\/2026\/05\/05\/servicenow-adds-agent-kill-switches-to-ai-control-tower\/5228579\" rel=\"nofollow noopener\" target=\"_blank\">previously said<\/a> its acquisition of Veza could provide that capability. In a statement to The Register, a ServiceNow spokesperson said\u00a0Okta serves as the logical connection to backend resources at the identity layer, while Veza gives ServiceNow visibility and control over the permissions graph. <\/p>\n<p>&#8220;To clarify how the pieces fit together: ServiceNow&#8217;s AI Control Tower is the orchestration and governance layer that monitors risk and detects when an agent is behaving outside policy. When that happens, the platform can trigger remediation actions across multiple identity and access systems, including Okta, which handles token revocation at the authorization layer,&#8221; the spokesperson said.\u00a0<\/p>\n<p>Veza, which ServiceNow acquired earlier this year, operates at a different layer, the spokesperson said, mapping permissions across human, machine, and AI identities at scale, and it lets ServiceNow revoke agent permissions directly within the ServiceNow platform, which is its own &#8220;kill switch.&#8221;\u00a0<\/p>\n<p>\u00a0<\/p>\n<p>McKinnon said that he has spent the past six months meeting Okta&#8217;s largest customers in person, reaching roughly 75 of the company&#8217;s top 100 accounts. The pattern he saw across those conversations was that agents are widely deployed, but the controls around them are immature.<\/p>\n<p>\u201cYou\u2019ll have a development team that\u2019s using Claude Code, but it&#8217;s connected to GitHub and their Jira system with static tokens in the local developer box,\u201d he said. \u201cSo that company is using agents, but they\u2019ve really done it in a haphazard, non-secure way.\u201d\u00a0<\/p>\n<p>He said the company\u2019s two leading products for controlling AI agents \u2013 Okta for AI Agents and Auth0 for AI Agents \u2013\u00a0 are not yet contributing substantially to the company\u2019s revenue, but Okta sees an industry in need just over the horizon.\u00a0<\/p>\n<p>\u201cIt\u2019s going to be big. We\u2019re pouring a lot of R&amp;D effort into this and focused on it. The interest is super high and unlike anything we\u2019ve ever seen,\u201d he said.\u00a0<\/p>\n<p>McKinnon said that there are several ways to control rogue agents, whether it&#8217;s stopping them from running or quarantining them at a network level, but all of that relies on observability and permissions that need to be set from the beginning.\u00a0<\/p>\n<p>Okta&#8217;s proposed answer is to apply the model it already uses for employee and customer access to the AI agents themselves. McKinnon said Okta can identify the agents operating inside an organization, maintain a record of them, and set rules governing what systems each agent may reach.<\/p>\n<p>&#8220;We tell you who your agents are. There&#8217;s a directory of agents,&#8221; he said. &#8220;We can scan multiple platforms and multiple systems and give you that source of truth of where your agents are, and we can help you set a policy on what they can connect to.&#8221;<\/p>\n<p>For large enterprises running thousands of applications, he said, rewiring each one to accommodate agents is not practical, so Okta instead places an authorization layer around the agents to control their permissions and connections.\u00a0<\/p>\n<p>Rival identity platform Microsoft Entra also boasts that it has similar capabilities. Autonomous agents authenticate directly with the Microsoft Entra ID platform using their agent identity and the client credentials flow, <a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/agent-id\/security-for-ai-overview\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft says<\/a>.\u00a0<\/p>\n<p>Entra assigns identities to agents, autodiscovers them across an organization, applies Conditional Access rules and permissions, and lets customers disable entire classes of agents in a single operation, Redmond says.\u00a0<\/p>\n<p>McKinnon said that, while the market is busy hunting for winners and losers in the AI agent race, customers want a secure experience regardless of the vendor. In addition to its work with ServiceNow, Okta partnered with Salesforce last year and AWS this month.<\/p>\n<p>Okta for AI Agents integrates with <a href=\"https:\/\/www.okta.com\/resources\/whitepaper-okta-for-ai-agents-amazon-bedrock-for-identity-security-and-governance\/\" rel=\"nofollow noopener\" target=\"_blank\">Amazon Bedrock AgentCore<\/a>, a fully managed AI service from AWS to provide identity governance for agents, including ownership assignment, lifecycle management, and &#8220;the ability to deactivate rogue agents.&#8221;\u00a0<\/p>\n<p>\u201cI think there&#8217;s going to be way more working together than people think,\u201d McKinnon said. \u201cWe&#8217;re really excited about our conversations with Amazon and their AgentCore, Agentforce from Salesforce, and the message from customers is clear. They want this identity layer and this connectivity layer to be independent to give them more flexibility, and I think the industry is coalescing around that.\u201d \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"Rogue agents are dangerous, but eliminating them is never easy.\u00a0 Jason Bourne, Ethan Hunt, and James Bond have&hellip;\n","protected":false},"author":2,"featured_media":613427,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,733,4308,86,56,54,55],"class_list":["post-613426","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/613426","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=613426"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/613426\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/613427"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=613426"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=613426"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=613426"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}