Okta moves AI agent control into the runtime, but key features are not shipped yet
Agent security is shifting from log review to in-path enforcement, but the gateway and kill switch slip to quarter-end; real-world effect unproven.
Original event 2026-09-22
At its Oktane conference, Okta announced Agent Gateway, which sits in the execution path between an agent and the tools it calls, enforcing policy and logging each interaction as it happens. Today's visibility comes only from agent events reviewed after the fact in the System Log.
Three features are generally available now: Agent SSO, Agent-to-Agent Connections and Resource Access Certifications. Agent Gateway and Shadow AI Agent Discovery for Endpoints are planned for GA in the third quarter; the gateway kill switch, which would revoke every active token and shut down sessions in flight, waits until the fourth.
Okta also joined AWS, CrowdStrike, Google Cloud and nine other vendors in a Blueprint Alliance that reworks its March agent security framework into an open, multivendor reference architecture, adding containment and recovery steps for a compromised agent. Members are testing interoperability across MCP and other open standards, with joint test results to be published regularly. All of this remains vendor-side; nothing here is independently verified.