Five AI Agent Identity Products Launch in Five Weeks, Interoperability Standard Still Missing
Baca dalam 60 detik
- Okta, Cymphony, AIUC, Baselayer, serta Beeline-Insygna merilis solusi identitas agen AI secara terpisah tanpa protokol bersama.
- Ketidakcocokan definisi verifikasi memicu risiko utang teknis dan kesulitan audit saat perusahaan bermigrasi ke standar NIST yang baru diproyeksikan rampung kuartal IV 2026.
- Survei Cloud Security Alliance mencatat identitas non-manusia melampaui karyawan hingga 144 banding 1, sementara 78 persen organisasi belum memiliki kebijakan tertulis.

Five identity product launches for AI agents within five weeks — Okta Agent SSO, Cymphony's funding, AIUC, Baselayer, and the Beeline-Insygna partnership — mark a new chapter in artificial intelligence governance that runs without a shared language. Each targets a real operational gap, but none closes the same gap, so cross-platform integration may instead become a new burden for companies.
This pattern is not a one-off. Throughout August and September, the first wave appeared at the governance layer: Okta, IBM, Broadcom, and Dataiku released agent control tools from different infrastructure layers. The second wave moved into measurement: Salesforce counted agentic work units, Gartner projected a project cancellation gap, McKinsey highlighted budget overruns — and those numbers do not talk to each other. Now the identity layer is repeating a similar pattern: five vendors, five definitions of verification, no bridge.
Okta Agent SSO, which reached general availability on August 24, registers AI agents as first-class workload identities in Universal Directory. The approach replaces static API keys with short-lived tokens based on the Cross App Access (XAA) standard, and is included at no extra cost for more than 20,000 core Okta SSO customers. Meanwhile, Cymphony builds a workforce graph that unifies identity, data, and activity signals across employees, AI agents, and non-human identities. Its $25 million Series A was co-led by Sequoia and SMBC Fin Atlas Beyond Fund — with Sequoia itself using the product internally, a strong signal when the lead investor is also an early customer.
On the compliance side, AIUC offers the AIUC-1 standard developed with more than 250 security and risk leaders. The standard runs about 5,000 tests — covering jailbreaks, hallucinations, and data leaks — and produces a safety report of roughly 100 pages. A $40 million funding round led by Ribbit Capital finances a SOC 2-style model that ties insurance coverage directly to audit results. Cursor and ElevenLabs are listed as certified.
Baselayer is extending its business identity network — already trusted by more than 2,300 financial institutions — to AI agents. Its Know Your Agent framework traces agents cryptographically back to the deploying platform and the authorizing business. The company claims its infrastructure helps customers prevent more than $1 billion in fraud losses, though this self-reported figure should be read with caution. Meanwhile, Beeline and Insygna take a workforce management angle: Beeline customers can issue verified identities for every agent before deployment, manage the full lifecycle from request to retirement, and apply rates and budget caps so agent costs are controlled from the start rather than discovered at the end of the quarter.
"Agents don't carry identity, and the infrastructure built to verify humans and businesses doesn't recognize them," said Timothy Hyde, co-founder and CTO of Baselayer.
The problem is not the quality of each product. The issue is that each tool measures something different: Okta measures enterprise SSO compliance, Cymphony measures identity security and visibility, AIUC measures safety certification, Baselayer measures financial KYA and fraud risk, Beeline-Insygna measures workforce lifecycle and cost. Without a shared standard, companies cannot reconcile what one tool knows with what another tool knows about the same agent.
This fragmentation is costly. When companies register agents in proprietary identity systems today, those agent credentials are locked into a particular vendor ecosystem. If they later need to be reconciled with other systems — or migrated when a new standard emerges — switching costs become real. An agent carrying five incompatible credentials from five vendors is harder to govern, audit, and shut down cleanly.
For Indonesia, the implications intersect directly with accelerating AI adoption in financial services and public services. Otoritas Jasa Keuangan and Bank Indonesia are drafting AI governance frameworks, while national banks and local technology companies are beginning to deploy AI agents for customer service, credit scoring, and claims processing. Without a mature agent identity standard, domestic institutions risk locking themselves into a single global vendor before domestic regulation is complete — or delaying adoption and losing efficiency momentum.
The NIST interoperability profile, if published on schedule, could provide the shared vocabulary that is currently absent. The question is whether companies can wait until Q4 2026, or whether the identity layer will have hardened into vendor silos before the standard arrives. The same pattern has happened twice — in governance, then measurement. Identity is the third layer forming on its own; whether it is the last will be determined by how fast the standard arrives and how much technical debt accumulates in the gaps.



