New research from Software Analyst Cyber Research (SACR) and Stanford Graduate School of Business , makes it clear: AI agent adoption has outpaced the security architectures designed to contain it, especially across enterprise AI programs.

The momentum is real. With over 3 million agents operating globally and enterprises spinning up thousands per week, the security challenge has shifted from whether to deploy agents to how to secure them at runtime—the moment an agent decides to act, calls a tool, and touches enterprise data.

The scale makes manual oversight impossible. Enterprises now run roughly 144 non-human identities for every human user, and when shadow agents and ephemeral instances are included, active identities can reach thousands per team across AI systems and services.

Yet the identity systems managing them were never designed for this. As the researchers conclude: "Traditional identity and access management systems were designed for two primary actors: humans and deterministic machine identities. AI agents fit neither model cleanly".

In working with thousands of organizations deploying AI agents, we've found that getting this right comes down to three questions:

These are the key questions that the Okta blueprint for the secure agentic enterprise enables you to answer. The organizations that have invested in answering all three will be meaningfully better positioned to detect, respond to, and contain the failures that are inevitable at scale.

You need the ability to discover agents no matter where they were built or deployed—across SaaS platforms, browsers, endpoints, and emerging agentic AI ecosystems.

This isn't a security tooling gap. It's an architectural one.

Agents aren't deployed like traditional software. They're created everywhere, by anyone, at any time. Visibility isn't a one-time inventory problem; it's a continuous discovery problem.

Most organizations don't have an agent inventory.

Leading teams have continuous agent discovery.

Once an agent exists, its risk isn't defined by what it is —it's defined by everything it can reach .

Agents don't operate in isolation. They connect to SaaS applications, APIs, databases, MCP servers, and other agents, often simultaneously and at machine speed across AI systems.

These security risks aren't edge cases. This is the baseline.

A compromised agent doesn't fail gracefully. It moves laterally across systems, chains access across SaaS applications, APIs, and data stores, and operates at machine speed. The blast radius isn't theoretical; it's immediate.

This is where the model breaks for most organizations.

Knowing where agents are and what they can connect to isn't enough—because agents don't behave like traditional systems. As Lawrence Pingree, Distinguished Analyst at SACR, notes, "an agent can stay within its permitted access boundaries while still doing something unexpected, harmful, or misaligned with its original intent."

They are non-deterministic, adaptive, and capable of acting in ways that weren't explicitly predefined.

This is the core failure—and it calls for agentic security.

Traditional security asks: "Is this person authorized to run this code?" Runtime identity security for agents asks a harder question: "Should this code run, even if this agent is authorized?"

The shift from access control to intent evaluation and behavioral analysis is what makes deterministic governance alone insufficient.

Leading teams control behavior in real time.

SACR's research offers clear guidance for security leaders evaluating their approach to agentic AI security:

SACR's research recognizes that Okta starts from a fundamentally different position than other vendors in this space: as the identity provider already trusted by 19,000 organizations, agent security becomes an extension of existing infrastructure for enterprise AI rather than a new point product.

Okta's approach maps directly to the three questions:

As the report concludes, Okta's strongest differentiation is consolidation—a single control plane that eliminates tool sprawl across identity types and covers the full spectrum from enterprise API-accessing agents through to developer-workstation MCP clients.

The organizations that understand this early aren't just deploying agents. They're building the systems to:

Because at scale, the question isn't whether agents have access. It's whether you can see what they're doing — and stop it when it matters.