AI agent identity security demands layered defenses, Omdia says

The rapid deployment of automated machine entities across enterprise environments has ignited a critical debate over how organizations manage machine access. According to insights shared by research firm Omdia, AI agent identity security demands layered defenses rather than reliance on a single consolidated platform. As businesses race to integrate advanced automation, security teams are grappling with architectural unknowns, platform consolidation trends, and strategic uncertainty regarding where vulnerabilities lie.

What Changed in the Identity Security Landscape

The technology ecosystem has experienced a significant shift toward platform consolidation, highlighted by major market moves. Notably, Palo Alto Networks Inc.’s acquisition of CyberArk Software Ltd. reflects broader industry consolidation within the identity security sector. Simultaneously, platform vendors are aggressively expanding their capabilities to address machine users. Okta Inc. recently introduced an AI agent runtime gateway and joined forces with Amazon Web Services Inc. and CrowdStrike Holdings Inc. to form the Blueprint Alliance. This alliance defines essential gateway capabilities, including authentication, authorization, and visibility, designed to help organizations manage the influx of autonomous machine actors.

Context and Market Confusion

Despite these platform developments, enterprise readiness remains uneven. Todd Thiemann, principal analyst for identity and access management and data security at Omdia, discussed these industry dynamics during exclusive coverage with theCUBE Research’s Krista Case and co-host Rebecca Knight at Oktane.

Thiemann highlighted survey findings gathered from approximately 400 security leaders. When asked about the primary inhibitors to implementing identity security for AI agents, the number one answer returned was confusion and uncertainty regarding the origin of potential attacks.

“I asked about 400 people, ‘What’s the primary inhibitor for you implementing identity security for agents?’ The number one answer that came back was basically confusion and also an uncertainty about where the attacks are going to come from,” Thiemann stated during the interview.

This lack of clarity has created a fragmented approach to platform leadership. When Omdia surveyed security leaders about which type of platform should take the lead on AI agent identity security, responses varied. The top answer pointed toward data security platforms—such as Palo Alto Networks paired with CyberArk, or Microsoft—while the next most common preference favored traditional identity platforms.

Technical and Business Implications

The ambiguity surrounding attack vectors and platform ownership creates substantial architectural challenges for enterprise technology teams. Because AI agents operate across multiple layers of the technology stack, securing them requires coordinated controls that span infrastructure, data repositories, and runtime environments.

However, relying on disparate security controls introduces operational friction. According to Thiemann, data security and other inherent operational risks may require controls from multiple providers. This multi-vendor requirement naturally increases the volume of policies enterprises must coordinate, which in turn raises the potential for security gaps.

Risks, Limitations, and Sector Impact

The complexity of managing multiple overlapping controls points toward a defense-in-depth posture rather than the adoption of one dominant, all-encompassing platform. With AI agents operating in what Thiemann described as “a bit of the Wild West — a lot of change happening,” organizations face distinct limitations in automated governance.

The absence of a standardized security blueprint means that enterprises must navigate a transitional phase where market standards are still maturing. Security leaders disagree on foundational architecture, and the rapid pace of software development often outstrips formal policy frameworks. This friction means that organizations risk deploying autonomous agents without adequate visibility or runtime guardrails.

What to Watch Next

As the identity security market continues to evolve, enterprise stakeholders will need to monitor how alliances like the Blueprint Alliance shape gateway standards. The ongoing integration between data security leaders and identity management providers will also dictate whether consolidated platforms can eventually alleviate enterprise confusion. For now, security architects must design resilient architectures that accommodate multi-layered controls, anticipating that the operational parameters for machine identities will remain fluid for the foreseeable future.