“AI is moving out of emerging status into production,” Reddie says.“The incredibly rapid acceleration of the adoption of these capabilities is creating what’s now being tracked as an acknowledged and concerning governance and control problem.”Organisations across government, education and enterprise sectors are using AI to improve customer experiences, reduce administrative burden and increase productivity. AI capabilities are appearing across front-office and back-office functions alike.Yet as AI becomes more deeply embedded, organisations are confronting new questions around visibility and control.Mike Reddie, vice president and general manager ANZ at Okta. “Most organisations are telling us they are now running AI agents addressing many different use cases,” Reddie says.“What are the agents doing? Which data do they have access to? Which systems do they have access to? Do we have visibility and control?”Non-human playersAs the number of non-human identities grows, organisations are being forced to rethink how they manage access and oversight.According to Reddie, organisations have traditionally built identity and security strategies around people. Employees are recruited, onboarded, trained and granted access to specific systems and information needed to perform their roles.AI agents operate differently.“An important factor here is just the sheer scale of it,” he says.“We’re currently at a point where non-human identities are outnumbering human identities at 45 to one.”While the exact ratio may vary between organisations, businesses are increasingly managing growing numbers of non-human identities alongside their human workforce.The issue extends beyond the number of identities involved. AI agents can also operate at a speed and scale beyond what is possible for human workers.“Beyond just the sheer number of non-human identities, they can operate at a far greater scale, and they can also operate at a far greater pace than humans,” Reddie says.As a result, organisations are being forced to consider what happens when AI agents gain access to sensitive information, enterprise systems and business processes.“If something goes wrong with one of these AI agents, or it’s compromised or controlled by a bad actor, then what is the blast radius of that problem?” he says.“Do I have controls to shut it down? Do I have a kill switch?”Oversight and controlFor many organisations, identity is becoming the control layer that helps govern how AI systems access data, applications and business processes.For many organisations, identity is becoming the control layer that helps govern how AI systems access data, applications and business processes.The goal is not simply determining who can log into a system. It is understanding which AI agents exist, what permissions they have, what information they can access and what actions they are authorised to perform.Reddie says this becomes particularly important as organisations grapple with the rise of unsanctioned AI usage.“We know from our surveys and our interactions with the industry and market that approximately 52 per cent of employees that we’ve surveyed are also using non-endorsed shadow IT AI tools,” he says.“Platforms like Okta help organisations get a proper understanding of which AI agents are in use, what the agents can do, and then bring the necessary governance and controls into place,” Reddie says.South Australia’s Department for Education has made identity management a cornerstone of its AI strategy, using it to support personalised learning experiences, manage user permissions and maintain oversight of how students and educators interact with its EdChat platform.The department supports more than 179,000 students and almost 33,000 teachers and staff, creating a highly diverse technology environment spanning hundreds of sites, devices and applications.Daniel Hughes, chief information officer at the Department for Education South Australia, says the department recognised early that AI had the potential to reduce administrative workload while also supporting student learning outcomes.“We wanted to explore the benefits in terms of using AI as a tool to help transform how students learn,” Hughes says.The department’s EdChat is an AI platform designed specifically for educational use.Daniel Hughes, chief information officer at the Department for Education South Australia. “We wanted EdChat to respond differently to a Year 7 student as compared to a Year 12 student,” Hughes says.“Having the ability to manage identity was fundamental to our success.”The department’s existing Okta environment enabled it to build identity into the platform, allowing different users to receive different experiences based on their role and context.Identity also supported the implementation of governance controls and guardrails.“Having those guardrails in place was fundamental to protecting the data, but also to protecting the student,” Hughes says.The department uses data from interactions within the platform to better understand how students and educators use AI and where additional support may be needed.For Hughes, visibility is not only about risk management. It is also about understanding how students engage with AI and how educators can help guide that process.“We wanted to understand the role of an educator,” says Hughes.“We wanted to see that interaction to understand what the role of an educator then was.”As organisations deploy more AI agents and non-human identities, the ability to understand what those systems can access, what actions they can perform and how they are governed is becoming increasingly important.Reddie says businesses that establish strong identity foundations early are likely to be better positioned as AI becomes more deeply embedded in operations.“The organisations that build their strategy with identity security at the forefront of their strategy and then build out their technology and AI capabilities in line with that are much better equipped to scale AI,” Reddie says.Questions around oversight, access and accountability are likely to become increasingly important. For many organisations, securing AI may depend less on the technology itself and more on understanding who, or what, is accessing systems in the first place.To find out more about securing non-human identities, visit Okta.
Why identity is becoming AI’s control layer
Organisations are operating with AI agents capable of accessing information, interacting with applications and performing tasks across enterprise environments.







