Artificial Intelligence at SMBtech

AI Agents Are Already In Your Business. The real Question Is Control

Surprisingly Useful AI Article Enhancements

AI adoption progress is phenomenal.  Control isn’t keeping up.

Across Australian organisations, AI has moved beyond experimentation into real-world use. AI agents have been deployed everywhere to automate workflows, support customers and improve operational efficiency.

But as adoption accelerates, the next challenge has emerged, not whether organisations are using AI, but whether they can control it.

New data from Okta’s Businesses at Work 2026 report highlights the scale of the shift. Non-human identities, including AI agents, bots and service accounts, are expanding rapidly and can outnumber human users by as much as 45 to 1 in modern environments. Yet only a small proportion of organisations feel fully equipped to manage and secure them.

AI doesn’t introduce a new security problem. It amplifies an existing one: identity, now the primary perimeter of defence.

Every AI agent operates through an identity. It needs access to systems, applications and data to do its job. As these agents become more embedded in operations, they are effectively acting as a new workforce, one that operates at speed and scale.

And that’s where the risk lies.

If you automate anything at scale, any issue scales with it, much faster than in a human-driven environment.

Take a simple example. An AI agent is deployed to support customer interactions or automate internal processes. To do its job, it may have access to multiple systems and datasets. If that access is overly permissive, or not continuously governed, it can expose sensitive information or trigger actions across systems very quickly.

This isn’t a theoretical risk. It’s a natural consequence of how these systems operate.

The organisations that are getting ahead of this are not slowing down adoption. They are focusing on control.

There are three areas that matter.

First, visibility. Organisations need to know where AI agents and non-human identities exist across their environment.

Second, access control. Those identities should only have access to what they need — no more.

Third, governance. Organisations need the ability to monitor activity and act quickly if something behaves unexpectedly.

These are not new principles. But they need to be applied consistently across both human and non-human identities.

As AI adoption scales, identity becomes the layer that enables control.

It provides the visibility, access control and governance needed to manage this new digital workforce safely and at scale.

The organisations that get this right will be able to move faster, with confidence. Those that don’t risk introducing complexity and exposure at the same pace as innovation.

AI readiness is ultimately identity readiness.

Mike Reddie is Vice President and General Manager, ANZ at Okta

Last Updated on May 22, 2026 by Mike Reddie

Surprisingly Useful AI Article Enhancements

Sign-up to the SMBtech Daily Newsletter

We will not spam you. You can easily unsubscribe any time. Read our privacy policy.