NewsStocksOkta's AI Boom Just Created a New Security Problem

Okta's AI Boom Just Created a New Security Problem

Author: Yahoo Finance·

Key Takeaways

  • Fiscal second-quarter revenue was $805 million, while subscription revenue reached $793 million.
  • Remaining performance obligations rose 17% to nearly $4.86 billion, and current remaining performance obligations increased 14% to $2.585 billion.
  • Okta lifted its full-year revenue outlook to roughly $3.22 billion to $3.23 billion.
  • Okta for AI Agents is generally available and is designed to find AI agents, enforce least-privilege access, and manage their permissions centrally.
  • The company generated $234 million of operating cash flow and $227 million of free cash flow during the quarter.
Okta's AI Boom Just Created a New Security Problem

For years, companies worried about whether an employee's password had been stolen. Now they have to worry about AI "workers," too — and Okta sees a growing business in keeping those digital workers in check.

Okta (OKTA) reported fiscal second-quarter results showing revenue of $805 million, up 11%, while subscription revenue reached $793 million, up 12%. Remaining performance obligations increased 17% to nearly $4.86 billion. Alongside the results, the company boosted its full-year revenue outlook to roughly $3.22 billion to $3.23 billion, as organizations increasingly face a category of identity that was virtually nonexistent in mainstream commercial IT only a few years ago: autonomous AI agents.

"Every agent needs a trusted identity and clear controls over what it can access and do," CEO Todd McKinnon said.

For the average worker, the future is not science fiction. Allowing artificial intelligence to read emails, update customer records, query databases, and trigger corporate processes is becoming more common. The more power these systems have, the more dangerous a compromised agent can become, especially because companies have to govern not just who can log in, but what software is allowed to act on their behalf.

Okta moves to govern a rising number of digital workers

This issue was a problem businesses were tackling long before autonomous AI took off. A CyberArk study found that 79% of firms anticipate machine identities growing in the coming year. Almost two-thirds expected growth of up to 50%, with another 16% expecting increases of between 50% and 150%.

AI agents only accelerate that tendency, because each autonomous system may need its own authentication credentials, permissions, and audit trail — multiplying the number of identities a security team must govern. If a corporation has an employee in accounting, that company may prohibit them from downloading a complete engineering database. AI agents should be restricted in the same way.

Earlier this year, Okta released Okta for AI Agents, which is now generally available. The software is designed to find AI agents, enforce least-privilege access, and centrally manage what agents may do. That matters because the more widely companies deploy automation, the more important it becomes to have one place to review permissions, track activity, and limit access before a mistake or compromise spreads across systems. That creates an entirely new potential security category: companies may no longer merely pay Okta to help manage every human employee. They may eventually pay to govern armies of digital workers as well.

AI agents turn convenience into risk

The promise of an agent is that users stop doing every step themselves. An AI agent might read a client complaint, go into the CRM, issue a refund, change inventory, and send a reply. That is enormously valuable if the agent is allowed to take each step.

The same autonomy becomes harmful if the agent influences, compromises, or simply makes a mistake. Verizon's 2026 breach research indicated that shadow AI usage had risen to 45%, increasing the risk of data loss. Software vulnerability exploitation was the cause of 31% of first access in breaches, and AI automation was speeding up the attacks. IBM says the average hack today costs more than $5 million globally, and some attacks on AI models are far more costly. Those economics help explain the resonance of Okta's pitch.

The company produced $234 million of operating cash flow and $227 million of free cash flow during the quarter, while current remaining performance obligations grew 14% to $2.585 billion.

Okta's AI-security setup:

  • Q2 revenue: $805 million
  • Subscription revenue: $793 million
  • Subscription backlog (RPO): about $4.86 billion
  • Current RPO (cRPO): $2.585 billion
  • Operating cash flow: $234 million
  • Free cash flow: $227 million
  • Full-year revenue outlook: roughly $3.22 billion to $3.23 billion
  • Emerging growth category: AI-agent identity security

Why Okta's new security problem reaches Main Street

Most individuals do not know they are buying identity-security software. They are always talking to it. An identity-management system can house all of these: the login verification when an employee accesses payroll, the authentication request before customer data opens, and the security rule that bans anomalous access.

That unseen layer becomes even more critical with AI agents. Feed an AI assistant customer credit-card details or medical records, and it can cause serious problems through bad permissions. For ordinary consumers, that means the security question shifts from "Who has access to my data?" to "What has access to my data?"

Wall Street saw the possibilities, pushing Okta shares substantially higher after the company's performance and forecast topped expectations, the Wall Street Journal reported.

The issue is that AI-agent security is still in its infancy. Companies may take longer than providers anticipate to implement agents, or huge software platforms may package identity controls right into their offerings. But for agents to become true digital employees, they need what every employee already has: an identity, a badge, and restrictions on which doors they can open.

Okta wants to sell all three.

This story was originally published by TheStreet on Aug. 28, 2026, where it first appeared in the Investing section.