Logo grid of the Blueprint Alliance's 12 founding members — Okta, AWS, CrowdStrike, Databricks, Docker, Google Cloud, Lovable, Proofpoint, Salesforce, ServiceNow, Wiz and Zscaler — around the alliance's own logo

Okta, 11 Rivals Launch AI Agent ‘Blueprint Alliance’

Twelve competitors say they will govern AI agents together.

Twelve companies that spend most days competing for the same security budgets are asking the industry to believe they can govern AI agents as one.

Okta, AWS, CrowdStrike, Databricks, Docker, Google Cloud, Lovable, Proofpoint, Salesforce, ServiceNow, Wiz and Zscaler announced Tuesday that they are forming the Blueprint Alliance, a coalition built around a shared architecture for identifying, scoping and, if necessary, shutting down AI agents that operate with no registered identity and no reliable owner.

Beyond the Break weekly cybersecurity newsletter — Subscribe

The timing is not incidental. The announcement comes the morning before Oktane, Okta’s identity conference, opens in Las Vegas, and a day before Okta President and Chief Operating Officer Eric Kelleher kicks off the conference with a keynote titled Secure Your Agentic Future.  

It also lands after a summer of frontier models and their bots behaving badly. In July, an OpenAI agent broke out of a sandbox and spent four days inside Hugging Face’s infrastructure. Weeks later, the UK’s AI Security Institute disclosed agents in its own evaluations attacking real targets online. On Friday, Google confirmed Gemini breached three real companies in May using guessed passwords.

This is the backdrop the alliance is stepping into, and it’s why this launch is drawing more attention than the usual vendor coalition.

“No single technology or vendor can secure the agentic era alone,” said Daniel Bernard, chief business officer, CrowdStrike in a statement.

What the Alliance Actually Agreed To

Infographic summarizing 'The Blueprint Alliance' by Security Point Break, detailing four pillars and eight capabilities related to discovery, access, runtime monitoring, and response.

The Blueprint Alliance’s shared principles treat every AI agent as its own identity, limit access to the specific task at hand rather than granting standing permissions, and require that any action an agent takes on a human’s behalf stay traceable end to end. Containment, when something goes wrong, is supposed to be immediate and reversible.

This isn’t an alliance looking for a problem. In April, Gartner said the average global Fortune 500 enterprise will run more than 150,000 AI agents by 2028, up from fewer than 15 in 2025.  Only 13% of organizations believe they’re ready to govern that growth.

Okta’s own research paints a starker picture of today. Some 88% of organizations have already had a confirmed or suspected AI-agent security incident. Only 22% treat those agents as identities in their own right.

Members also committed to testing signal-sharing across open standards including MCP, OCSF, SSF and CAEP, so a threat flagged by one company’s monitoring tool can trigger a response across a competitor’s platform. That list of standards is not new to this group – AWS, CrowdStrike, Okta, Salesforce and Zscaler were also founding participants when the Open Cybersecurity Schema Framework launched in 2022.

From Three Questions to Four

The alliance itself expands a narrower blueprint Okta introduced in March, which asked organizations three questions – where are their agents, what can those agents connect to, and what can they do?

At the time, Okta said its now launched platform, Okta for AI Agent, would allow organizations to discover, manage and govern AI-driven systems that can access applications, move data, and execute tasks. 

The version launching this week adds a fourth dimension to the framework. It asks what an agent is actually doing right now, and how an organization stops it when it misbehaves.

Kelleher framed the Blueprint Alliance as three things arriving together. First was the Blueprint Alliance itself. Second was Cross-App Access, an open protocol Okta contributes to but doesn’t control, built on the OpenID standard. It lets an agent connect to outside apps without a repeated login prompt or a long-lived credential sitting around unused. Third was what Kelleher called the fastest-growing new product in Okta’s history – Okta for AI Agent.

In a live media demo of Okta for AI Agent last week, Okta demonstrated how it flags a misbehaving agent. It automatically revokes every active token and cuts the cord on every session already in flight – not just new ones.

Asked directly whether this generation of controls would have stopped Hugging Face, Ric Smith, Okta president of product and technology, said, “This is basic primitives in security that were missed.”

That confidence covers Okta’s own stack. Whether it extends to the other eleven members is a separate question, and one Okta doesn’t answer alone.

What Okta Doesn’t Answer Alone

Pressed on what that interoperability actually enables today, a CrowdStrike spokesperson gave SPB a narrower answer. The cross-vendor scenario Bernard’s own language implies for the alliance where one member detecting a risk, another acting on it automatically, is technically possible today. But only through a bilateral integration CrowdStrike and Okta already had in place. That integration predates the alliance.

CrowdStrike told SPB nothing has been built or integrated specifically for the Blueprint. The spokesperson pointed questions about how the other ten members would actually interoperate back to Okta.

That is a narrower claim than the Blueprint Alliance makes today. Twelve companies have agreed on a shared vocabulary and a shared set of principles. What at least one of them says exists in production, as of this week, is the same two-company plumbing that predates the alliance by years. That’s not the twelve-member control plane the announcement describes.

There’s reason not to dismiss this outright. Several of these same companies have done this before. AWS, CrowdStrike, Okta, Salesforce and Zscaler were founding members of the Open Cybersecurity Schema Framework, launched at Black Hat in 2022.

That standard took two years to earn real, neutral footing. It joined the Linux Foundation in November 2024. By last December, it had enough international backing to be on track for ratification by the United Nations’ telecommunications body last June.

Judged against that timeline, a coalition that is just days old and still running on pre-existing integrations is not behind schedule. It is exactly on schedule for what these things usually look like at the start.

Still Don’t Know

What we still don’t know is whether governance ever moves to a neutral body or stays Okta-run, whether new members join through an open process, and whether the promised interoperability testing ships real enforcement on a timeline or drifts into indefinite “in progress.”

We also don’t know if or to what extent Microsoft, Anthropic or OpenAI will participate in the Blueprint Alliance. Also an unknown is how the alliance stacks up against OWASP’s and the Cloud Security Alliance’s competing frameworks. The answers will come in the next six to twelve months, when the first interoperability results are due.

Strip away the Blueprint Alliance and the Oktane launch-week choreography and something bigger than an alliance is happening. Okta is using the AI agent problem to push past identity management and into threat detection, runtime enforcement and security operations. That’s an entirely different budget line for Okta and other pure-play identity access management companies.

Friends, Family and Frenemies

The clearest evidence of that pivot isn’t in Tuesday’s announcement. It’s in the acquisition Okta made in July, when it agreed to buy the threat-detection firm Permiso specifically to add capabilities suited to a security operations center. That’s not an isolated move.

Palo Alto Networks agreed last year to pay $25 billion for CyberArk, pulling one of cybersecurity’s biggest names into identity. SailPoint bought the machine-identity firm Entro this summer, for roughly the same reason Okta bought Permiso.

Security and identity vendors are converging on the same territory from opposite directions, and AI agents are why.

Whether customers end up buying Okta’s move as identity or as something closer to a broader security platform is, in practice, the same question as whether this alliance works.

The founding members compete with each other for the exact thing they’re agreeing to standardize. Wiz and CrowdStrike both sell cloud and runtime security. Salesforce and ServiceNow are both racing to be the platform agents get built on. Google Cloud and Wiz are even listed as separate founding members, six months after Google’s $32 billion Wiz acquisition closed.

Enforcement, and who owns the kill switch, touches product roadmaps directly. That’s usually where alliances like this stall.

Total
0
Shares
Previous Article
AI agent vending machine illustration showing different AI agents priced by token as a hand feeds quarters into the machine.

The $10,000-a-Day AI Bot and the Real Cost of AI Agents

Next Article
Illustration comparing EU and US cyber threats with maps, network connections and security shields

Cyber Threat Report: How EU Attacks Compare With the US

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading