Skip to content
theCUBE

UPDATED 13:25 EDT / SEPTEMBER 24 2026

Krista Case, principal analyst at theCUBE Research, and Rebecca Knight, theCUBE host, talk about AI agent security during the keynote analysis at Okta Oktane 2026. SECURITY

AI agents creating a new insider security risk: theCUBE’s Oktane keynote analysis

AI agent security now depends on knowing what agents can do after they gain access.

Agents can act across applications, pass work to other agents and make changes faster than security teams can review them. That makes visibility and permission limits necessary, but it also raises a harder question: How does a company recover from actions an agent has already taken? Okta is addressing discovery, authorization and runtime controls, according to Krista Case (pictured, left), principal analyst at theCUBE Research, who sees agents themselves as a source of insider risk.

“What’s interesting here is that as enterprises are adopting AI, they’re creating this whole new form of insider risk in the form of these AI agents,” Case said. “In some ways, that might even be a bigger long-term threat to the organizations than what these adversaries are doing with AI.”

Case spoke with fellow host Rebecca Knight (right) at Okta’s Oktane event, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed how companies can control AI agents and respond when their actions cause harm. (* Disclosure below.)

AI agent security needs a recovery plan

Okta frames its approach around finding agents, determining what they can do, observing their actions and responding when needed. Those steps cover more than the initial grant of access, Case explained. Still, stopping an agent may leave changes in place or set off work elsewhere in a connected system.

“The kill switch, it revokes the authority and it stops the AI agent from taking any future actions,” she said. “It doesn’t necessarily account for what the agent may have already changed, what other downstream actions it might have triggered.”

That gap grows as agents delegate tasks to other agents. A response may need to identify every affected system and restore a trusted state, not simply revoke one identity. Agents also need clear human ownership and permissions tailored to their tasks, rather than permissions inherited wholesale from their users, Case pointed out.

“Who is the human that’s responsible for this AI agent at the end of the day,” she asked, “We need to make sure that the AI agent doesn’t just automatically inherit all of the access and permissions that the human does.”

Thousands of agents expose gaps in oversight

The scale of discovery is already testing those controls. A financial asset management company found about 13,000 agents in its environment but considered only 1,000 valid, Case noted. The finding suggests agents are being created outside established IT processes, leaving companies to trace how authority passes between people, agents and applications.

“This company, in their environment, they discovered approximately 13,000 agents, and they considered only 1,000 of those valid,” she said. “It kind of shows that upfront discovery piece of the conversation. It really reflected, I think, especially in some of these larger environments, the scale of the problem that we’re dealing with.”

Discovery gives security teams a starting point, but an agent’s activity can cross several vendors’ platforms. Okta’s Blueprint Alliance aims to establish a shared architecture for access, delegation and monitoring. Shared signals could help clarify an agent’s intent; companies will also need to settle who has authority when platforms recommend conflicting actions, Case emphasized.

“I do think that this sharing of telemetry, this interoperability, I do think that it matters,” she said. “I think it’s a really important initiative. What I am interested to see as it gets rolled out and as we start to talk with customers about it is if there … conflicting insights across these platforms about an action that needs to be taken. For example, who is going to have the authority at the end of the day and where is that authority going to live in this tech stack?”

Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of Okta’s Oktane event:

(* Disclosure: TheCUBE is a paid media partner for Okta’s Oktane event. Sponsors of theCUBE’s event coverage do not have editorial control over content on theCUBE or SiliconANGLE.)

Photo: SiliconANGLE

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network

Are you an AWS customer?  Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/

 

About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Send us a news tip

Send us a News Tip

  • This field is for validation purposes and should be left unchanged.
  • Max. file size: 244 MB.

Sign in

SIGN IN

Bio

Ethics statement

Extract the signal from the noise

Get SiliconANGLE updates and analysis.

Contact us

Partner with us

Contact us

Guest inquiry