Okta CEO Todd McKinnon talks earnings beat ahead of investors call

CNBC TelevisionAbout 3 min readMay 29, 2026Watch original
THE SUMMARYAI-generated

Key Concepts

  • Identity-First Security: The practice of managing and verifying the identity of users, devices, and now AI agents as the primary perimeter for security.
  • Agentic Security: A framework for securing autonomous AI agents, ensuring they are authenticated, authorized, and monitored.
  • First-Class Identities: Treating AI agents with the same security protocols and identity management standards as human employees.
  • Prompt Injection: A security vulnerability where an attacker manipulates an AI model's input to bypass safety filters or execute unauthorized commands.
  • Identity Infrastructure: The foundational systems (like Okta) that manage access, authentication, and authorization across an enterprise.

1. Financial Performance and Market Context

Okta reported strong quarterly results, beating analyst expectations on both top and bottom lines. The company saw positive momentum in subscription revenue and provided guidance that aligned with market estimates. Despite market volatility and concerns regarding the impact of AI on security, Okta’s CEO, Todd McKinnon, noted that customers are increasingly turning to "trusted vendors" with proven track records for reliability and secure infrastructure.

2. The Role of AI Agents in the Enterprise

McKinnon highlighted a shift in how large enterprises (e.g., Dell, FedEx) are deploying AI. Rather than displacing security, the proliferation of AI agents has created a new, complex security requirement.

  • The "Agentic" Shift: Companies are deploying fleets of AI agents to automate workflows and improve productivity.
  • The Three Core Questions: To manage these agents, enterprises must answer:
    1. Visibility: Where are the agents coming from (Salesforce, Microsoft, custom-built)?
    2. Connectivity: What resources are these agents connected to? (Agents are only as powerful as the systems they access).
    3. Governance: What actions are these agents authorized to perform?

3. Framework for Agentic Security

Okta has introduced an "Industry Blueprint" for Agentic Security to address the risks associated with the rapid deployment of AI. The framework emphasizes a "secure fabric" approach, acknowledging that no single tool can solve all security challenges.

  • Methodology: The blueprint integrates identity controls with other defensive layers, including:
    • Prompt Injection Defense: Protecting against malicious inputs designed to hijack agent behavior.
    • Malicious Control Prevention: Ensuring agents cannot be manipulated to perform unauthorized tasks.
    • Software Patching: Managing vulnerabilities within the agent ecosystem.

4. Key Arguments and Perspectives

  • Identity as the Weakest Link: McKinnon argues that as AI agents become more integrated into enterprise systems, identity management becomes the most critical security layer. If an agent is not treated as a "first-class identity," it becomes a potential entry point for attackers.
  • The Evolution of Co-pilots: The first wave of AI co-pilots was largely isolated (web-based data only). The current wave involves deep integration into internal enterprise systems (source code, databases, vulnerability logs), which necessitates strict identity-based access controls.
  • Vendor Consolidation: In a time of "technology news and hype," enterprises are prioritizing established, reliable infrastructure providers over unproven, fragmented solutions.

5. Notable Quotes

  • "They’re going to have to know where their agents are and where they’re coming from, and they’re going to have to treat them as first-class identities." — Todd McKinnon, on the necessity of managing AI agents like human users.
  • "Agents are only as powerful as the systems they are connected to." — Todd McKinnon, emphasizing the risk of granting AI agents access to sensitive enterprise resources.

6. Synthesis and Conclusion

The core takeaway is that the rise of AI agents is not a threat to the security industry but a catalyst for its evolution. Okta is positioning itself as the "identity layer" for this new AI-driven enterprise architecture. By providing visibility, connectivity management, and a standardized security blueprint, Okta aims to help organizations navigate the transition from simple AI co-pilots to complex, autonomous agent fleets without compromising their security posture. The company’s financial success is directly linked to its ability to provide this "tried and true" identity framework in an increasingly volatile technological landscape.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.