Good afternoon and thank you for joining our session. So, let's talk about how we enforce trust when the actor isn't human.
So, let's start with the boring slides, some safe harbor, forward-looking statements and let's keep going. My name is Arkadiusz Krowczynski. I'm part of the product organization at Okta and work as a principal product acceleration specialist. My name is Raphaël Bert. I'm part of Accenture. I'm leading AI identity across Europe, Middle East and Africa. Let's start with a question for the audience. How many of you know which AI agents are deployed in your organization today? Anyone?
Okay, so I think it's a good question to keep in mind for our session because there are not so many hands raising. And before starting talking about AI and identity, a quick word about our partnership between Okta and Accenture. I would say that Okta is bringing the platform, Accenture is bringing the transformation expertise and together we are addressing workforce, customer and agentic identities with great offerings and accelerators.
So, any discussion on this, please feel free to go in our booth and we're happy to discuss with you. Before starting, I would like to share a personal story. A couple of weeks ago, I was with my niece and she asked me for sushi.
So, I went to a restaurant and in front of the restaurant on the door, it was written that the restaurant is closed for the day. I was about to pick my phone, look for another restaurant, but my niece reacted differently. She tried to open the door, she pushed and it opened. Was she wrong? I don't know. Maybe she reacted differently. But I think that's what we need to get prepared for AI agents. They are much more creative and they're not always doing what we expect from them.
So, for a sushi restaurant, it's charming, but when it comes to your enterprise, this door open could be overprivileged service accounts, this could be orphaned token, or this could be an MCP connection that is not managed and left like that. And the most funny thing about these AI agents that are really creative is that most of them don't have a proper identity. And that's what we want to talk about today.
With Okta, we had since January several sessions across Europe with plenty of clients, what we call AI on tour. And what comes from all this discussion is always three points.
First one, these AI agents are accessing plenty of data. They are accessing your financial information. They are accessing your customer information. They are always sometimes accessing your HR records. And that's increasing the attack surface. The second point is that these AI agents can be autonomous, can make decisions and take action in your organization. If you browse on the internet, you will find plenty of cursors trying to delete production database and all backups with that. And this is a new risk.
This is a risk that we didn't have before because initially we had humans that were knowing what to do. Now we have some new entities. And the third element is that we have an explosion of identities. Usually we had human accounts, human identities. Now for each human identity, we can have 82 non-human identities on average, even 100 based on the numbers of Okta. And this is a new paradigm. This is giving something that we have never seen before. And we need also to work at scale. So how do we do it? I think you have heard about identity fabrics.
So what we need to do is not anymore just governing accesses, but it's governing identity risk. It means that everything you built in the last decades, all your identity governance platform, your access management platform, your privilege access management platform, everything you have today, it's perfect. It's the basic. But we cannot just limit identity to this. We need to be proactive and we need to be reactive. Proactive is getting visibility on where my agents are. It's knowing how to address shadow AI. Being reactive, it's knowing that there will be identity incidents.
And if there is an identity incident, we need two things. We need to be able to detect it quickly and we need to be able to react quickly. So to make it happen, I will let Arki explain from a technological perspective what is the identity security fabric.
Thanks, Raphael. So if we look back last year, September, Las Vegas, at our annual conference Octane, we talked about the concept of the identity security fabric. Our unified approach to identity security where we are providing security for every identity type, every use case, and every resource before, during, and after authentication. So with the arrival of our new co-workers, AI agents, we are now extending our capabilities and providing security for them. That's why we're extending the whole powerful identity security fabric to AI agents now. Why?
Because the future of the enterprise is agentic. So we are moving away from software that waits for a click to software that acts on its own behalf.
So today, your agents are already helping your employees, customers, and partners. And this brings for sure one of the biggest opportunities but challenges today. And as Raphael mentioned, how do we securely roll out agents across B2B, B2C, and workforce use cases? We know and we heard that 92% of Fortune 500 have adopted AI. But big surprise, only 22% of them secured them. Agents are being built over weekends, spun up with no code tools, already touching your most sensitive data. So ungoverned agents and ungoverned trust are untraceable, unaccountable, and they're already in your environment.
And to be honest, these aren't edge cases. When we look into the news, AI is moving faster than security can respond. So the people deploying it and the people securing it, unfortunately, are not in the same room. And that gap is the problem. And it's not only a technology problem, it's an identity security problem. We also heard 100 machines for every human. So most of the organizations can't exactly tell you how many agents they have, let alone what they are doing. We asked a CIO last month, hey, can you list every AI agent in your environment when the board asks you tomorrow?
Guess her answer? I can't. I'm flying blind. And this from an enterprise with a mature security program. RSA conference this year, researchers took over a full Azure tenant. And all it took them was one misconfigured MCP connection. Just one. So let me ask you, do you have an answer for this? Not in six months. Now. Because I'm more than sure that you will ask about it. And the result, 88% have had an incident. And 97% of those breached lack proper controls. We all spent decades building least privilege, adaptive ORs, and zero trust for humans. But agents aren't human.
No SSO, no MFA, no standard workflows. And agents create risk not because of the models, but because they have an identity. They authenticate, authorize, and they're accessing data. So securing agents is an identity problem. And identity is what we at Okta are building for more than 17 years. But we also have some good news for you today. So we meet you where you are. Managing agents and building agents. So we are focused when you look at the identity security fabric on a management part. One control plane, every agent, full visibility. And for us, everything starts with these three questions.
Where are my agents? What can they connect to? And what can they do?
And again, most of the enterprises organizations can't confidently answer all three. And to be very honest, these aren't aspirational goals. They are really the baseline operating AI agents safely. So let me answer all of these for you.
First, where are my agents? Discovery is really the first thing every customer asks for.
Hey, show me what I have. The problem is agents come from everywhere. An employee creates an automation in a browser, a developer spins up one on the device, a SaaS tool starts running agents on the user's behalf without your knowledge. So at the end of the day, you need a single inventory for every agent, every owner, and every policy. Because otherwise you're making security decisions without the most basic information and fragmented visibility is limited visibility. Once you know where your agents are, you need to map everything they can reach. Rafael also mentioned it.
MCP servers, SaaS apps, other agents, service accounts, our legacy systems. Every connection multiplies the attack surface. Remember the RSA demo. And every static credential is an open door to the attacker. And this is exactly where most of the organizations have the most exposure because agents inherit the same long-lived service account credentials. They've been sitting there for years and nobody touching or even reviewing them. Third question, what can they do? And this is the governance gap. And it's what every CISO and auditor starts asking about.
Can you control what the agents do in real time? Can you require human approval before high-stakes action? Can you recertify access and run governance reviews? And last but not least, can you shut one down if it goes off script? So if all of you can't answer all of these questions, so we don't have governance. Maybe we have hope. But hope is definitely not a security strategy.
Thank you, Haki. So as you can see, we have a great technology with Okta. But as identity practitioners, we know that's not enough. Identity is not just about technology. It's about process. It's about people. And we at Accenture, when we think about people, process, technology, we think about frameworks. How to make it concretely happen in your organization, not just from an identity perspective, but from an end-to-end perspective. What does it mean registering an agent in your organization? What is the repository? How do we know the purpose of the agent? Where do we store this information?
In your ITSM, in your CMDB? All of this should then lead to our topic of the day. The identity, how we authenticate, how we authorize an agent, and of course, how we enable all the processes that we all know for humans. And this will be the foundation for all the elements, for the protection elements, when we're talking about AI security, for the guardrails we'll set up in our environments, but also the foundation for our ability to defend, for the anticipation of the next stage of threats, and how we'll react to that.
So in this slide, you can see our framework end-to-end, from governance, to protection, to defense, and that's the way we address AI security in Accenture. Very often, we hear people saying, yeah, AI agents will replace humans, there will be no place in the coming years for humans. That's not our vision. Our vision of the world of tomorrow is that we will augment humans with agents.
For sure, agents can work 24-7, can connect to plenty of systems much faster than any human, but at the end of the day, the decision should be on the human side. The decision is based on judgment, on instinct, on business context. You will not send an agent to your CISO, to your C-level for a discussion. And that's where human is important, and that's the way human and agents will work together. And our role as security professionals, and also as identity professionals, is to reduce risk, to augment operational efficiency, and to enable business, because that's our role at the end.
It's to enable business, not to say no, but to say, this is the way to go, and this is the way to go to build confidence. So all the principles that we know, the least privileged principle, the need to know, everything related to just-in-time, everything related to auditability, governance, and security, auditability, governance, all of this will apply in the AI world. But this concept should be adapted, and adapted to this human augmented with agentics. So very often, we are discussing with our clients, and they are telling us, OK, but what to do, where to start?
So we have built an AI identity journey to share with our clients what to do first, and what to do next. And our view is that it always should start with a strategy, and it always should start with clear objectives. It should be based on your use cases, it should be based on your company objectives, and it should be measurable. And I want to give an example.
With Okta, we are doing ISPM assessment, Identity Security Postal Management. We are going in just three to four weeks in the organization, connecting to a few systems that should be critical in the organization, and getting results very visible, very tangible, on what is the risk, why we are talking now today about identity. And this is something that you can leverage with your level to say, hey, we have something to discuss, but we have also a solution, we have an approach, we have a framework that we can set up to make it work. When this is done, you will be able to start proof of concept.
We really consider that testing everything is critical, and then you need to embed all these new tools in your identity platform, as shown before. The last step, but I think we can take it for the future, is how to manage and operate, what it means, continuous improvement in AI identity landscape, what are the key figures, the key numbers we need to follow in an AI environment. But we'll keep that for next year. I will let Arki conclude for the last step.
Thank you, Raphael. Great approach, so we are really looking forward, and that's why we built Okta for AI agents, right? Three questions, one platform. Where are my agents? Discover them, register them, and own them. What can they connect to? Short-lived credentials, least privilege, and no open doors. What can they do? Govern them, audit them, and kill switch if needed. Every agent, every environment, under full control.
So, we call it a blueprint, and this blueprint isn't a framework for someday. So, it's a minimum for managing agents in your production. When the board, CISO, auditor, or whoever asks, I don't know, isn't acceptable anymore. The organizations moving really fast aren't waiting for an incident anymore. They are treating AI agents like first-class identities and building governance around them.
So, from our point of view, this is what it takes to become a secure agentic enterprise. If you want to learn more about how Okta secures AI, scan the QR code, visit us at the booth, or just register for our amazing AI Identity Summit that is happening next month in Frankfurt, and I'm more than sure that Raphael and his team will also be on site.
So, thank you so much for joining our session and Okta secures AI. Thank you. Thank you.
Yeah, thanks a lot for sharing your view and your insights and already how to solve it somehow, yeah. Maybe one question, and this is the point to remind you, all the people here on site and online to go into the live stream and add your questions so that we can answer them if you have one. Maybe one question to you. When we now really start to treat these AI agents not just as extension of a human, yeah, or maybe some service account, from your perspective, what is the thing that changes for the companies then the most?
So, what they gain if they start to treat them as first-class identities? I believe that in order to give confidence on AI adoption, you need to have the right security layers. Identity is a key component. We saw it in the presentation, and having identity will build trust. It's not a matter of saying you should not do it. It's a matter of saying this is the right way to do it, and this is the way we can build trust and confidence for the business. Thanks a lot again, and a round of applause for them.