AI Agents Already Have Access. Who’s Governing It?

Learn How to Govern AI Agents Before Excessive Access Goes Unchecked

Sign Up Now
Join the Webinar
loader
About this webinar

AI agents are gaining access faster than security teams can govern them: fewer than half of CISOs are confident they can identify, control, and authorize every agent in their environment. Matt Immler, Regional CSO at Okta, breaks down findings from Okta's newly released Global CISO Insights 2026 report—a survey of over 300 CISOs and security executives across six countries—revealing just how far most organizations are from actually controlling the AI agents already running inside their environments. 

We’ll dive into how AI agents fit into your overall identity governance strategy and share best practices for getting AI governance right: treating AI agents as first-class identities, closing the gap between agent visibility and authorization, and governing shadow AI instead of just blocking it. 

Key Takeaways 

  • The Visibility Illusion: Only 47% of CISOs are confident they can identify every AI agent in their environment—and even among the confident, roughly 80% still worry about excessive access going unreviewed. Seeing an agent isn't the same as controlling it. 
  • Legacy Controls, New Risks: Just one in four organizations have adopted a purpose-built framework for securing AI agents, and, worryingly, 21% still govern access through shared credentials or broad-permission service accounts. Most organizations are securing agents with yesterday’s tools. 
  • Governance Maturity Determines Security Outcomes: Risk isn’t evenly distributed. Companies with more mature identity governance are less likely to experience shadow AI, can stop rogue agents faster, and are less worried about AI-enabled breaches.
  • AI agents aren't waiting for your governance model to catch up—join us for practical guidance on how to govern AI agents securely.