Okta unveils Blueprint Alliance reference architecture for AI agent runtime security as analysts urge layered defenses
At its Oktane event, Okta introduced a multivendor reference architecture for securing AI agents in production, combining identity, endpoint and network signals. Omdia analysts say layered defenses, not a single platform, will be required.
Eric Kelleher, Okta's president and chief operating officer, said the biggest obstacle for customers is the volume of competing vendor claims. "One of the challenges companies have in navigating this is [that] every technology vendor they talk to from every component of the stack is telling them that they're the one-stop shop that's going to fix everything," Kelleher told theCUBE Research's Krista Case and co-host Rebecca Knight in an interview at Oktane broadcast on theCUBE, SiliconANGLE Media's livestreaming studio. "So, the biggest challenge that we have in talking to our customers is helping them navigate the confusion of understanding how to think about the problem, how to secure AI in a way that's simple."
The Blueprint Alliance architecture reduces agent security to four questions: where agents are, what they can do, what they are doing and how to respond. Okta layers its identity signals on top of endpoint and network telemetry, Kelleher said. "We'll look at what agents are connecting to and we'll compare that against the systems that it's been authorized to connect to, to see if there's a disparity," he said. "That real-time data all flows back into a system to help us identify, 'Does something look suspicious?'"
Okta can deactivate a flagged agent to block new sessions, and it plans to expand kill switch capabilities at its Agent Gateway to revoke active tokens and sessions, according to Kelleher. He said the appropriate response depends on the agent's behavior and the risk it poses. "There are going to be cases where agents, as they're exploring their intended work, end up stepping over boundaries that were not intended, where you'll want to redirect them and bound them back in," he said. SiliconANGLE reported that Okta formed the Blueprint Alliance with Amazon Web Services and CrowdStrike, and that the company recently added an AI agent runtime gateway.
In a separate interview at Oktane, Todd Thiemann, principal analyst for identity and access management and data security at Omdia, a division of Informa TechTarget, said confusion is the top blocker for buyers. "I asked about 400 people, 'What's the primary inhibitor for you implementing identity security for AI agents?' The number one answer that came back was basically confusion and also an uncertainty about where the attacks are going to come from," Thiemann told theCUBE's Case and Knight.
Respondents to Omdia's survey also disagreed about which type of platform should lead agent identity security, Thiemann said. The most common answer was the data security platform, followed by the identity platform. He pointed to Palo Alto Networks' acquisition of CyberArk Software as one sign of consolidation in the identity security market.
The Blueprint Alliance defines gateway capabilities including authentication, authorization and visibility. Data security and other risks may still require controls from multiple providers, which Thiemann said increases the number of policies enterprises must coordinate and the potential for gaps, pointing toward defense in depth rather than one dominant platform. "With AI agents, [it is] a bit of the Wild West — a lot of change happening," he said. "That's one of the issues … that's going to have to work itself out."
TheCUBE is a paid media partner for Okta's Oktane event; neither Okta nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.