What happens when an AI system can act, but no one can say who's accountable when it acts wrong?
That's the question at the center of my conversation with Matthew Hansen Regional Chief Security Officer and Head of Customer Audit at Okta who spends his days inside the security programs of some of the largest enterprises in the world. He's not theorizing about agentic AI risk from a conference stage. He's watching it unfold in real environments, in real time, and what he's seeing should change how you think about identity, permissions, and control.
We get into some of the hardest unsolved problems in this space: why identity accountability breaks down when the systems permissions don't think in permissions the way humans do, why "human-in-the-loop" is only as strong as the human actually paying attention, and the specific scenario that keeps security leaders awake at night. Matthew makes the case that identity needs to be the control plane, not just another layer bolted onto the stack, and he's honest about where the gaps still are. That honesty is rarer than it should be in this industry.
If your organization is deploying agentic AI, or about to, this is worth 15 minutes before something goes wrong, not after. Watch the full conversation below.
Also, to learn more read Okta’s “Business at Work Report” that discusses how to secure AI agents . I’ll put the link in the comments.