Okta unites 12 tech players to secure enterprise AI agents

Share

Okta announced on September 23, 2026, at its Oktane conference in Las Vegas, the creation of the Blueprint Alliance, a coalition of twelve technology providers aimed at establishing an open framework to secure AI agents in the enterprise. The initiative comes as Gartner estimates that Fortune 500 companies will, on average, operate more than 150,000 AI agents by 2028, while governance mechanisms remain largely inadequate.

🔑 Key takeaways

  • Coalition of 12 tech players launched by Okta on September 23, 2026 at Oktane (Las Vegas)
  • Framework built around 4 key questions: location, capabilities, actions, response
  • Gartner forecasts +150,000 AI agents per Fortune 500 enterprise by 2028
  • Only 13% of organizations say they have adequate governance in place

A twelve-member coalition to standardize AI agent security

The Blueprint Alliance brings together twelve technology vendors spanning the identity, cloud, and security stack. Alongside Okta, the founder and convener, sit Amazon Web Services (AWS), CrowdStrike, Databricks, Docker, Google Cloud, Lovable, Proofpoint, Salesforce, ServiceNow, Wiz and Zscaler. GE Appliances and World Central Kitchen round out the coalition as strategic advisors, contributing operational perspectives from manufacturing and humanitarian response respectively.

The alliance extends a first blueprint published by Okta in March 2026, which only addressed three governance questions. The 2026 version adds a fourth dimension: the ability to react to abnormal behavior. Initial reporting from the event mentioned only four members; the official announcement subsequently expanded the scope to the full twelve companies and confirmed the final composition.

Four structuring questions and six common principles

The framework proposed by the Blueprint Alliance addresses four questions that any organization deploying AI agents must be able to answer systematically:

  • Where are my agents? — inventory and discovery across multi-cloud and multi-vendor environments
  • What can they do? — fine-grained mapping of permissions granted to each agent
  • What are they actually doing? — real-time observability of executed actions
  • How should I respond to abnormal behavior? — instant and reversible containment capability

These questions translate into six guiding principles shared by all members. Each agent must be treated as a first-class identity, on par with human users. Access rights must be limited to the specific assigned task, with no standing privilege. Authority delegation must be traceable so that the entity authorizing an action is known. Runtime behavior must be continuously monitored. Agent containment must be instant and reversible. Finally, governance must adapt to the speed at which AI evolves.

Framework evolution since March 2026

VersionDateQuestions coveredKey evolutions
Initial blueprintMarch 2026Location, capabilities, actionsThree-dimension framework, Okta-only publication
Blueprint AllianceSeptember 2026+ Response to incidentsAdds containment dimension, cross-industry coalition

New tools integrated into the Okta for AI Agents platform

In parallel with the alliance launch, Okta unveiled several enhancements to its Okta for AI Agents platform. The Agent Gateway acts as an intermediary that enforces policies and logs interactions in real time, ensuring rules are applied at the point of execution. Shadow AI Agent Discovery for Endpoints detects unmanaged agents installed on employee devices, closing the blind spot left by agents created outside official processes. Finally, the kill switch allows security teams to instantly revoke active tokens and terminate sessions when an agent is deactivated.

These features address two recurring concerns: agents that accumulate excessive privileges by default, and agents that remain active after an employee departure or a scope change, without persistent oversight.

Interoperability: open standards as the alliance backbone

The Blueprint Alliance bets on interoperability between members products through a set of open standards, presented as the technical foundation of the reference architecture:

  • Model Context Protocol (MCP) — standard for context exchange between agents and tools
  • Open Cybersecurity Schema Framework (OCSF) — common schema for security events
  • Shared Signals Framework (SSF) — signal sharing between control planes
  • Continuous Access Evaluation Profile (CAEP) — continuous access rights evaluation

The goal is that a threat signal detected by one runtime monitor automatically triggers corrective actions across all connected control planes, without manual intervention. Members plan to publish interoperability test results and reference integrations on a regular basis to ease adoption across multi-vendor environments.

Leadership reactions and remaining blind spots

The announcement was accompanied by several statements from Okta executives and partners. Charlotte Wylie, senior vice president and deputy chief security officer at Okta, summarized the alliance logic by highlighting the need to galvanize the industry rather than chase a proprietary solution.

“Rather than trying to solve this problem alone, there is a growing realization that we must galvanize the industry to meet the demand of our customers at the speed they are striving to run.”

Charlotte Wylie, SVP and Deputy CSO, Okta

Among strategic advisors, Mandar Deo, chief digital technology officer at GE Appliances, stressed the importance of governance suited to complex industrial environments where agents act on physical value chains. Brian Stoll, CTO at World Central Kitchen, noted that governance must be as dynamic as the agents themselves, or risk becoming an operational bottleneck during emergency response missions.

Yet several notable absences remain. The consortium does not include the main AI model creators such as OpenAI or Anthropic, nor Microsoft (Entra), although Okta maintains active partnerships with these players. Eric Kelleher, president and COO of Okta, acknowledged that the current phase focuses on enterprise-side governance and that the alliance may evolve to bring in additional participants. For channel partners and managed service providers, the challenge now is to translate these shared standards into operational controls deployable across heterogeneous environments.


Conclusion: a promising framework, an adoption curve to build

The Blueprint Alliance asks the right questions and gathers the right profiles to tackle AI agent governance at enterprise scale. Moving from blueprint to effective standard will depend on the rapid release of interoperability tests, on extending the coalition to AI model creators, and on the buy-in of security teams often overwhelmed by the pace of agent deployment. The optimistic scenario sees these norms become a common layer, much like SAML or OAuth did for identity federation. The pessimistic scenario points to lasting fragmentation between each cloud vendor proprietary frameworks, in the absence of shared governance.

Sources

This article is published for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

Disclaimer: this content is for information purposes only and is not financial advice. Cryptocurrencies are highly volatile: you may lose all of your capital. Always do your own research. Legal notice
Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Read More

Items