1 min readfrom TechCrunch

Okta buys AI security startup Permiso; source says for about $200M

Our take

Okta has acquired Permiso, an AI security startup, bolstering its identity threat detection capabilities in a rapidly evolving landscape. Sources estimate the acquisition price at approximately $200 million. This strategic move directly addresses the increasing need for enterprises to secure AI agents and other non-human identities across cloud environments. As organizations increasingly rely on AI, securing these new identities becomes paramount. For further insights into the burgeoning synthetic user space, explore our coverage of Simile’s recent $200 million funding round.
Okta buys AI security startup Permiso; source says for about $200M

Okta’s acquisition of Permiso for approximately $200 million signals a significant and accelerating trend: the imperative to secure non-human identities in an increasingly AI-driven enterprise. The move gives Okta crucial identity threat detection capabilities precisely as organizations grapple with the expanding footprint of AI agents, bots, and other automated systems accessing sensitive data and resources. This isn't simply about securing human users anymore; it’s about building a robust security framework that accounts for the unique risks posed by these increasingly sophisticated, and often autonomous, entities. The emergence of companies like Simile, which recently raised $200 million at a $2 billion valuation [Synthetic-user startup Simile raises $200M at $2B valuation 5 months after $100M Series A], underscores the rapid growth and investment in synthetic user technologies, further amplifying the need for tailored security solutions. The landscape is shifting rapidly, and Okta’s action reflects a proactive approach to addressing this emerging challenge.

The growing complexity of AI deployments also necessitates a re-evaluation of traditional identity and access management (IAM) strategies. Meta’s CEO, Mark Zuckerberg, recently highlighted the expansive enterprise AI opportunity beyond just agents [Zuckerberg says Meta’s enterprise AI opportunity extends beyond agents], suggesting a future where AI permeates various business functions. Securing these diverse AI interactions requires a more granular level of control and monitoring than previously imagined. Think about Waymo's rigorous evaluation process before deploying AI in autonomous vehicles [At Waymo, an AI project isn't ready until its evals are — not when the model performs well]; a similar level of scrutiny and security needs to be applied to AI systems accessing enterprise data. Permiso’s technology, integrated within Okta’s existing platform, promises to provide that crucial layer of assurance, allowing organizations to confidently embrace AI without exposing themselves to undue risk. The focus will be on identifying anomalous behavior from AI agents, preventing unauthorized access, and ensuring compliance with evolving data governance policies.

This acquisition isn’t an isolated incident; it’s a harbinger of more to come. We anticipate that other major players in the identity and security space will follow suit, either through strategic acquisitions or by developing their own AI-specific security capabilities. The challenge lies not just in detecting threats but also in adapting to the constantly evolving nature of AI itself. AI models are constantly learning and changing, which can make it difficult to establish a baseline for “normal” behavior and identify anomalies. Furthermore, the potential for malicious actors to exploit AI systems—through techniques like adversarial attacks—adds another layer of complexity to the security equation. Building a truly resilient security posture in the age of AI requires a proactive, adaptive approach that can keep pace with the rapid advances in technology.

Ultimately, the Okta-Permiso deal highlights a critical shift in the security paradigm. The focus is no longer solely on protecting human identities, but on securing the entire ecosystem of digital entities, including AI agents. The real test will be how effectively Okta can integrate Permiso’s technology, and how quickly they can adapt their platform to address the evolving threats posed by increasingly sophisticated AI systems. A key question to watch is whether this acquisition will spur a broader standardization of AI identity security, or if we’ll see a fragmented landscape of proprietary solutions – and which approach will ultimately provide the most robust and scalable protection for enterprises navigating this new era of data management.

The deal gives Okta identity threat detection capabilities as enterprises seek to secure AI agents and other non-human identities across cloud environments.

Read on the original site

Open the publisher's page for the full experience

View original article