Identity management giant Okta is betting that controlling agent identities will become "the biggest category of cyber" as enterprises deploy autonomous AI systems, according to statements from CEO Todd McKinnon during an August earnings call reported by CSO Online. The company has launched Okta for AI Agents, a platform designed to track and secure agentic entities, and announced upgrades including expanded Agent SSO identity models, rules for agent-to-agent interactions, and runtime policy enforcement at its annual Oktane conference. McKinnon told analysts that identity serves as "the primary control plane for securing AI," positioning Okta to lead what he sees as an emerging cyber market.
Gartner forecasts that the typical global Fortune 500 firm will operate more than 150,000 agents by 2028, up from fewer than 15 in 2025, according to the report. The market for AI security is projected to reach $2.8 billion this year, reflecting an 83% jump from 2025, and is expected to climb to $4.8 billion in 2027 and $7.7 billion in 2028. By comparison, the identity security market stood at $29 billion in 2025 and is forecast to expand to $56 billion by 2029, according to IDC figures cited in the report. Major acquisitions this year include Palo Alto's purchase of CyberArk, CrowdStrike's acquisition of SGNL, and Zscaler's purchase of Symmetry Systems, underscoring industry interest in controlling autonomous agent activity.
However, analysts quoted in the report question whether identity management alone can address agentic risks. "Authentication is only the first stage," said Aisling Dawson of ABI Research, noting that even fully authenticated AI agents can malfunction and cause damage. The shift from human to agentic identities presents challenges because AI agents function at vastly different scales than people, the report states, and vendors from the machine identity sector may already understand how to handle this volume. Dawson also pointed to agent-specific problems such as multi-hop delegation, and cited the recent Hugging Face breach as evidence that runtime governance, behavioral monitoring, and overly broad permissions represent growing threats. Okta president Ric Smith countered that the Hugging Face incident would have been far less severe with stronger foundational security practices, including eliminating standing credentials and deploying Okta's new agentic gateway.
The competitive landscape is heating up as hyperscalers, third-party agentic platforms, identity vendors including Microsoft and Ping, cloud providers, and cybersecurity firms all position themselves to manage agent traffic, according to the report. IDC analyst Emanuel Figueroa said identity providers hold an advantage because agents rely on credentials, permissions, delegated access, and trust relationships, though "the question is which layer enterprises ultimately trust to coordinate agent activity at scale." Okta may have an edge over Microsoft due to its platform-agnostic approach, Dawson noted, as limiting vendor lock-in is increasingly important to buyers driven by sovereignty requirements. Forrester analyst Geoff Cairns acknowledged Okta's unique position thanks to its IAM focus and broader platform independence, but warned that "the competitive landscape is getting more challenging." Enterprises aren't looking for another dashboard, Figueroa said—they want fewer of them. The race to become the control plane for autonomous actors will likely hinge on whether companies prioritize identity infrastructure or prefer integrated solutions from the platforms already running their AI workloads.

