Navigating the EU AI Act with identity

EU regulators demand accountability. It's time to treat AI agents as first-class identities.

About the Author

Matt Ellard

General Manager, EMEA

Matt Ellard is the Senior Vice President and General Manager at Okta, where he leads regional strategy, sales, and partnerships, helping organizations strengthen security through identity-led approaches. Prior to joining Okta, Matt led the cybersecurity consulting practice at Ernst & Young (EY), advising global enterprises on security strategy, risk management, and digital transformation. He brings more than 25 years of experience in enterprise technology and cybersecurity, and has held senior leadership roles at Tanium, Veritas Technologies, and Symantec.

20 agosto 2026 Time to read: ~

A €35 million fine or 7% of global annual turnover. That’s how high penalties can reach for non-compliance under the EU AI Act, the world’s first comprehensive AI framework.

While full enforcement won’t arrive until 2027, business leaders are feeling the pressure. This month, the act’s transparency rules went into effect, mandating that organizations disclose when users interact with AI systems. Other significant rules now in force include requiring that companies design AI systems that humans manage, giving those humans-in-the-loop the ability to “monitor, interpret, and override the system,” and that businesses must be able to explain how deployed AI systems reach decisions

Identity is one of the methods for meeting these requirements.

The act sets a firm expectation: Businesses must show they have the protocols and frameworks in place for their AI deployments. These regulations aren’t just about business confidence. Consumer confidence also depends on strong guardrails that protect people and their data.

Bridging the AI accountability gap with identity

By 2027, the EU AI Act will enforce a strict standard of accountability for “high risk” AI systems, with requirements that apply to companies that develop these systems and to companies that deploy these systems. This includes provisions requiring continuous monitoring of AI systems, logging requirements, and human oversight, many of which include an identity component.  

While enterprises have spent years standardizing identity governance for human employees, AI agents have changed the game. Today, anyone can spin up an AI agent—often outside security controls—creating shadow AI with no official owners. 

It turns out many companies aren’t currently set up to see how many AI agents are in their systems, let alone hold someone accountable for them. According to Okta’s Global CISO Insights 2026 report, 81% of CISOs are concerned about excessive AI access. Less than half can identify all the AI agents in their systems, much less control or authorize their access. Only 31% said they are aligned with their boards on AI risk. 

This data reflects conversations happening across Europe’s business community. For many leaders, the immediate challenge isn’t the nuance of compliance, but the reality of shadow AI, rising costs, and unclear returns from isolated AI trials. Instead, they are looking for a clear framework that helps them safely deploy AI. 

The solution to many of these gaps also happens to be one of the keys to compliance: identity.

Securing agentic AI: A practical framework

A secure agentic enterprise establishes clear accountability and visibility before agents scale.

Okta's blueprint for the secure agentic enterprise outlines the identity and access controls needed to safely adopt agentic AI while maintaining visibility and accountability.

EU AI Act: Securing high-risk AI with human oversight

Some EU AI Act mandates that go into effect December 2027 demand tangible human oversight and audit-ready governance over high-risk AI systems. Identity plays an important role in helping satisfy those requirements. 

To answer regulators' questions about high-risk AI deployment, organizations using AI agents as part of those deployments must treat AI agents as first-class identities, governed with the same rigor as their human workforce. Bringing AI agents into the fold, begins with three identity-related questions: Where are my agents? What can they connect to? What can they do? The answers can provide the baseline visibility needed to help meet regulators’ demands.

How forward-thinking organizations can adapt

The EU AI Act isn’t the only framework reshaping the European regulatory landscape. It joins a complex wave of EMEA regulations such as DORA, NIS2, and eIDAS 2.0, which interact with a nuanced web of national-level laws. Yet, despite targeting different sectors, these region-wide regulations share a common thread: You cannot secure, audit, or govern what you cannot reliably identify.

For enterprises, meeting EU AI Acts regulations shouldn’t be viewed as a technical hurdle to clear. Instead, they should see it as an impetus for knowing how digital systems work and who is responsible for them.

To build this foundation, leadership teams can start with these four practical steps:

Establish baseline visibility first: You can’t secure or audit what you cannot see. A step toward compliance is a comprehensive audit of your active AI footprint: map the tools in use, the data they can reach, and the blind spots they create.

Manage AI with the same rigor as the workforce: The same identity principles organizations apply to human employees, such as least-privilege access, time-limited entitlements, and regular recertification, should be extended to AI agents.

Keep humans in the loop: High-risk autonomous systems shouldn’t operate entirely unchecked. Organizations can mitigate risk by establishing clear separation of duties and requiring human approval before AI agents can perform sensitive or high-risk actions.

Align AI with existing business goals: Running unmonitored shadow AI or disconnected trials increases danger without proving value. Companies that actively question whether their AI programs are driving business metrics reduce exposure to AI-related security risks and ensure their technology investments are actually delivering real value.

Image Image

Exactly who is behind your AI?

The EU AI Act is bringing identity to the forefront.

Download your readiness guide today.

While full enforcement is set for late 2027, global businesses must begin laying the groundwork for compliance today.

Much like GDPR, the EU AI Act holds any business serving European customers accountable, regardless of where they are based. Securing the digital identities behind every automated action is one part of satisfying the compliance requirements.

By treating AI governance as an identity challenge, organizations around the world can step out of the shadow AI phase, safely put the technology to work, and clear the way for continued growth.

These materials are for general informational purposes only and do not constitute legal, privacy, security, compliance, or business advice.

The content may not reflect the most current security, legal and/or privacy developments. You are solely responsible for obtaining advice from your own legal and/or professional advisor and should not rely on these materials for compliance, implementation, or purchasing decisions .

Okta makes no representations or warranties regarding this content and is not liable for any loss or damages resulting from your implementation of these recommendations. Information on Okta’s contractual assurances to its customers may be found at okta.com/agreements.

 

About the Author

Matt Ellard

General Manager, EMEA

Matt Ellard is the Senior Vice President and General Manager at Okta, where he leads regional strategy, sales, and partnerships, helping organizations strengthen security through identity-led approaches. Prior to joining Okta, Matt led the cybersecurity consulting practice at Ernst & Young (EY), advising global enterprises on security strategy, risk management, and digital transformation. He brings more than 25 years of experience in enterprise technology and cybersecurity, and has held senior leadership roles at Tanium, Veritas Technologies, and Symantec.

Get our Identity newsletter

Okta newsletter image