Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News Trending Research

Okta: 91% Use AI Agents but Only 22% Govern Them Properly

The Okta Enterprise AI Index finds most AI agents still authenticate through human logins, creating audit trail gaps and security risks at scale.

Enterprise DNA | | via Okta
Okta: 91% Use AI Agents but Only 22% Govern Them Properly

There is a widening gap at the heart of enterprise AI adoption, and it is not about capability. It is about identity.

Okta’s newly published Enterprise AI Index draws on sign-on data spanning four years across more than 20,000 organizations and 100 distinct AI products. The headline number: 91% of enterprises are already running AI agents. The number that should concern every business leader deploying AI: only 22% treat those agents as independent, identity-bearing entities with their own credentials and access controls.

Everyone else is still letting their AI agents log in as humans.

The Audit Trail Problem

When an AI agent inherits a human employee’s login credentials to do its work, something quietly breaks inside your organization: the audit trail. You can no longer tell whether a critical action, editing a record, sending an email, approving a transaction, was taken by an employee or an AI system acting autonomously.

That is not a hypothetical edge case. The Okta data shows 88% of organizations have already reported suspected or confirmed AI agent security incidents. The most common cause is not a sophisticated attack. It is the fundamental way enterprises are authorizing AI work, with static API keys, service accounts, and shared human logins that were designed for a world without autonomous software.

The Identity Ratio Is Already Out of Control

Okta’s data reveals something most business leaders have not fully registered. In a typical enterprise today, non-human identities (bots, service accounts, AI agents) already outnumber human users by 100 to 1. In cloud-native environments, that ratio reaches 144 to 1.

Each of those non-human identities is a potential security surface. And most are governed by policies designed for a single human employee doing predictable work, not autonomous systems that can make hundreds of decisions per minute across dozens of integrated tools.

The result: 70% of identity-related security incidents in the Okta dataset are linked to autonomous AI activity. Not external hackers. Internal AI agents doing things they were not supposed to do, or doing permitted things in ways that cannot be traced afterward.

Why This Matters Now

The timing of this report matters. Enterprise AI adoption has moved from pilot to production. The Okta data shows AI-native vendors growing enterprise accounts by more than 4x in four years. AI agents have gone from experiment to operational reality inside most large organizations.

But the governance model has not kept pace. Only 10% of organizations have what Okta describes as a “well-developed strategy or roadmap” for managing non-human identities. The rest are running AI workforce deployments on governance frameworks that were never designed for them.

This creates a specific class of risk that is not about whether your AI works. It is about whether you can demonstrate compliance, satisfy auditors, investigate incidents, or even understand what your AI systems did on a given day.

What a Proper AI Identity Architecture Looks Like

Okta’s framework for governing AI agents in enterprise environments centers on three questions for every agent your organization deploys:

Where does it run? Agents operating inside your network have different risk profiles than agents calling external APIs. The authorization boundary needs to match the deployment context.

What can it connect to? Every system integration is an access grant. Agents should hold credentials only for the systems they need, scoped to the minimum required permissions, not inherited from a human with broader access.

What can it do? Approved actions should be explicitly defined and logged. An AI agent making a judgment call about whether to escalate an issue or process a refund should be doing so within a defined policy envelope, not inheriting the full discretion of the employee whose login it is using.

This is not a technology problem that can be solved by buying another tool. It is an organizational discipline problem: the same rigor that IT teams apply to human user access needs to be extended to AI agents.

What This Means for Business

If your organization is deploying AI agents (and if you are using any modern enterprise software, you almost certainly are, whether you chose to or not), there is an immediate practical question to answer: do your AI systems have their own identities?

The consequences of getting this wrong are not only security risks. They are compliance risks. Regulators in the EU, UK, and increasingly the US are building audit and explainability requirements into AI governance frameworks. If you cannot produce a clean audit trail showing what your AI systems did, when, and under what authority, you will not be able to satisfy those requirements.

For organizations using AI agent platforms, including services like Omni Ops from Enterprise DNA that deploy AI agent workforces for business operations, getting the identity layer right from the start avoids retrofitting governance onto production systems under pressure. It is far cheaper to architect correctly than to untangle shared credentials after an incident.

The transition from human-scale to AI-scale operations is not just about adding capability. It is about building the governance layer that makes that capability auditable, reversible, and defensible.


The Okta Enterprise AI Index is based on anonymized sign-on activity from more than 20,000 organizations between June 2022 and June 2026, covering 74 AI vendor suites. The full report is available at okta.com.

Source

Okta
Working With Claude field guide cover

Free Resource

Going deeper with Claude?

Get the free 32-page implementation guide for ANZ teams.

No spam. Unsubscribe any time.