Okta CEO Argues AI Agents Need Distinct Identity Controls

Todd McKinnon suggests that artificial intelligence is evolving into a new category of digital user, requiring security frameworks that go beyond traditional human logins.
Todd McKinnon, co-founder and CEO of Okta, has proposed a significant shift in how enterprises view digital access. He argues that AI agents are no longer just tools but are emerging as a powerful new type of identity. This perspective moves the conversation from simple software permissions to treating autonomous programs as distinct actors within a corporate network.
The core of this argument is that current security models are insufficient for the scale of AI deployment. As companies integrate these agents into daily operations, the risk profile changes because these entities can act without direct human supervision at every step. McKinnon’s view implies that identity management must evolve to govern these non-human actors with the same rigor applied to employees.
Defining the AI agent identity
In the context discussed by GN technics/ai (en-US), an identity type refers to the unique digital fingerprint that allows a system to verify who or what is requesting access. Traditionally, this has been reserved for humans using passwords or biometrics. McKinnon suggests that AI agents require their own standardized identity frameworks to ensure accountability and traceability in complex digital environments.
Security risks in autonomous workflows
The primary trade-off here involves the balance between autonomy and control. While AI agents offer speed and efficiency, they can also execute actions at a scale that outpaces human oversight. Without distinct identity controls, it becomes difficult to audit which specific agent performed a particular task, creating a blind spot that malicious actors could potentially exploit.
Impact on enterprise infrastructure
For organizations, this means rethinking their infrastructure to support non-human identities. It is not merely a software update but a structural change in how access is granted, monitored, and revoked. The catch is that this transition requires significant investment in new security architectures, which may be complex to implement across legacy systems.






