Attestation
Okta Data: AI Agents Still Log In as Humans, Breaking the Audit Trail
A new dataset published this month gives the clearest look yet at a problem the industry has been talking around for two years: most AI agents in production still don't have their own identity.
The Okta Enterprise AI Index, cited in a July 21 analysis, draws on anonymized sign-on activity from more than 20,000 organizations and spans June 2022 through June 2026 across more than 100 distinct AI products, consolidated into 74 vendor suites for analysis. The finding is blunt: enterprises have spent the last four years bolting AI agents onto identity infrastructure that was never designed to recognize them as distinct actors, and that mismatch is now visible in the data, not just in incident postmortems. AI agents operating inside enterprise environments largely work the same way they did when generative AI first arrived: authenticated as, or through, a human.
That matters more than it sounds. Anthropic, OpenAI, and Cursor more than quadrupled their enterprise customer base over the study period, and Anthropic passed OpenAI in total enterprise accounts in March 2026, then overtook it in monthly active users the following month — real evidence agentic AI has moved from experimentation to standard tooling. But the report's more consequential point sits underneath that growth curve: identity and access practices for AI agents have not kept pace with how fast those agents are being deployed.
Practically, this means an agent acting under a human's login, a shared service account, or a static API key leaves no distinct entry in the audit log. When something goes wrong — a bad transaction, an over-broad data pull, a policy violation — the log shows a person's name, not the agent's. That's the exact failure mode regulators are now writing rules against: the EU AI Act's high-risk obligations reach full enforcement on August 2, 2026, and its Article 12 requires systems to support automatic recording of events over their lifetime, a requirement that's hard to satisfy if the 'who' in the log is wrong.
The industry response so far has been protocol proposals — agent identity tokens, signed agent cards, verifiable credentials — but this data point is different: it's not a vendor pitch, it's a measurement of what's actually deployed. Four years into the agentic AI era, most organizations still can't tell you, from their logs alone, which actions were taken by a person and which by code acting in that person's name. Closing that gap is now a compliance deadline, not just a best practice.