Interestana
Home/News/Okta Report: CISOs Struggle to Govern AI Agents
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Okta Report: CISOs Struggle to Govern AI Agents

Okta Report: CISOs Struggle to Govern AI Agents

Organizations are deploying AI agents into production environments at a pace that outstrips the ability of security teams to implement effective governance, according to a recent analysis. These AI agents are increasingly integrated with business applications, accessing sensitive data, initiating API calls, and executing actions across various enterprise systems. Crucially, they often operate without the same stringent access controls and oversight that are applied to human users. This disparity creates significant security and compliance risks.

Okta's Global CISO Insights 2026 report underscores this challenge, revealing that a mere 47% of Chief Information Security Officers (CISOs) express confidence in their organization's ability to identify every AI agent operating within their environment. This statistic suggests a substantial blind spot for many security leaders, making it difficult to manage potential threats and ensure compliance. Even among the CISOs who believe they have a handle on AI agent identification, a significant portion still harbors doubts about their comprehensive understanding and control.

The rapid proliferation of AI agents, often referred to as "shadow AI" when their use is unmanaged or unknown, presents a complex governance problem. These agents can inadvertently expose sensitive data, execute unauthorized transactions, or create new attack vectors if not properly secured and monitored. The lack of visibility and control means that organizations may not be aware of the full scope of AI activity, making it challenging to enforce security policies, manage access privileges, and conduct audits. This situation is exacerbated by the fact that AI agents can mimic human behavior, making them harder to distinguish from legitimate user activity.

Addressing this governance gap requires a multi-faceted approach. Security teams need to develop strategies for discovering, authenticating, authorizing, and monitoring AI agents, similar to how they manage human access. This includes implementing robust identity and access management (IAM) solutions that can differentiate between human and AI identities, enforce least-privilege principles, and provide detailed audit trails of AI agent actions. Furthermore, organizations must establish clear policies and procedures for the development, deployment, and use of AI agents, ensuring that security and compliance are considered from the outset. The Okta report serves as a critical reminder that proactive measures are essential to mitigate the risks associated with the accelerating adoption of AI agents in the enterprise.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next