Governing AI agents: Four questions every government agency needs to answer

About the Author

09 10월 2026 Time to read: ~

BLUF

Legacy constraints: 68% of surveyed government employees report intense pressure to deploy agentic AI, yet legacy access controls can’t secure non-human identities at mission speed.

Zero Trust modernization: Implementing Zero Trust governance allows federal agencies to meet modernization directives while eliminating the visibility gaps that lead to compliance failures and security incidents.

Visibility gap: 80% of respondents can’t fully account for AI agents accessing their systems, demonstrating an urgent visibility gap.

Unified identity control plane: Securing agentic AI in government requires a unified identity and access management control plane governing non-human identities across four core operational phases: continuous discovery, least-privilege permissions, real-time runtime monitoring, and centralized containment (kill switches).

AI agents are taking on more work across government, from internal processes to constituent-facing services and mission-critical operations. In partnership with GovExec, Okta commissioned a survey of 300 government employees to explore the state of identity security and control as it relates to agentic AI adoption across government agencies. The findings reveal clear security and identity concerns across the identity control plane that are keeping many agencies in the pilot phase: 

  • The visibility gap: Only 16% of surveyed employees are confident they maintain a complete inventory of their AI agents.
  • The behavioral gap: Only 9% are confident they know what those agents are actually doing.

Securing AI agents from pilot to production in state and local government

State and local agency respondents reported they are deploying agentic AI to streamline services, but unmanaged agents and security risks often stall progress. Download the full infographic summarizing survey findings from state and local agencies to learn more.

Infographic highlights the challenge of AI blind spots threatening public trust

Navigating the agentic AI security challenges in the federal boundary 

As AI agents take on more work across civilian and defense missions, federal agencies must balance the need for greater security with mission speed. Download the full infographic for insights from senior federal and defense leaders on keeping identity systems secure and controlled.

Infographic highlights how fragmented tools stall AI projects due to security challenges

Four critical questions for securing agentic AI in the public sector

For agencies looking to move AI from pilot projects to production, fragmented identity systems leave them with limited visibility. To establish a scalable identity foundation across government assets and citizen-facing services, agencies must be able to answer four critical questions:

  1. Where are my agents?
  2. What can they do?
  3. What are they doing?
  4. How do I respond?

1. Discovery and visibility: Where are my agents? 

How do government agencies discover and inventory unmanaged AI agents?

Agentic AI introduces an evolving ecosystem of non-human identities, making discovery a lifecycle challenge rather than a one-time exercise. According to the survey, 80% of federal agency respondents cannot fully account for all AI agents accessing their systems. 

2. Access governance and permissions: What can they do?

How do you apply least-privilege access controls to AI agents?

Like human identities, agents need defined roles, owners, and permissions governed by the principle of least privilege. Unfortunately, fragmentation makes this difficult: 85% of surveyed employees find integrating security data across tools challenging, and only 19% manage identity through a single unified platform. Tightly scoping access ensures that even if agents go off the rails, they cannot perform unauthorized actions. 

“You can’t secure what you don’t manage.”
- Greg Hall, Federal Field CTO and Distinguished Strategic Advisor, Okta

3. Detection, monitoring, and accountability: What are they doing? 

How can federal agencies monitor and detect unauthorized AI agent actions in real time?

Permissions define what an agent can do, but agencies must continuously monitor to verify what it is actually doing at runtime. The survey found that 53% of agencies have detected AI tools or agents accessing their systems without prior approval, and 26% have experienced security incidents or compliance gaps traced to unmanaged identities. Delayed detection of rogue agents significantly increases the risk and scale of organizational impact.

4. Control, compliance, and recovery: How do I respond? 

What’s the best way to contain rogue AI agents and enforce Zero Trust recovery?

Agencies are feeling the pressure to move fast, with 68% reporting pressure to deploy AI, and nearly two-thirds delaying or scaling back initiatives because security controls cannot keep pace. A centralized identity control plane provides a crucial kill switch, allowing agencies to instantly sever a rogue agent’s connections and feed that telemetry into their security information and event management (SIEM) and security orchestration, automation, and response (SOAR) systems.

Building a unified identity foundation

Managing humans, non-human identities, and agents through a unified platform simplifies AI governance. Okta for AI Agents extends your existing identity and access management foundation into regulated boundaries, giving agents unique identities, scoped access, and lifecycle controls.

Whether modernizing constituent service portals or securing federal agency workflows, Okta delivers the compliance-ready identity framework the public sector needs to deploy AI at scale while maintaining continuous auditability and Zero Trust enforcement. Agencies facing urgent directives to modernize can maintain a robust risk posture while adopting innovative agent workflows with real-time containment, agent registries, and full auditability for automated pipelines.

Secure your AI transformation

Download our guide to Governing AI Agents to explore the complete survey findings and get more insight into the four questions every agency needs to answer to bridge the AI visibility gap. 

To help your organization address unmanaged AI risk and secure your digital services, explore the blueprint for the secure agentic enterprise for a step-by-step implementation framework to establish identity controls, manage agent lifecycles, and enforce least privilege across your AI agents.

About the Author

Amy Johanek

Vice President of Federal

Amy Johanek is Vice President of Okta's Federal business. She has over 25 years experience working with US government agencies in a variety of roles at major software and services vendors, including IBM, Gartner, and Splunk.  

Daniel Watts

Product Marketing Manager

Daniel Watts is a Product Marketing Manager at Okta covering State, Local, and Education (SLED). He writes and speaks about how identity underpins public sector modernization, AI agent governance, and trusted resident and student experiences. Connect with Daniel on LinkedIn at linkedin.com/in/danielwatts3.

Anthony Johnson

Staff Product Marketing Manager

Anthony Johnson leads global product and GTM strategy initiatives at Okta, focusing on the critical role of identity in modern federal government cybersecurity and critical national infrastructure. Anthony’s publishing work explores key commercial and public sector themes, including Zero Trust maturity, cloud identity modernization, FedRAMP alignment, and the role of identity in securing critical federal workforces and citizen-facing services worldwide. Drawing on his background across technology, management consulting, and public sector verticals, Anthony is committed to delivering strategic insights and industry guidance that helps organizations build resilient, identity-centric architectures that support mission success.

Jason Maass

Vice President, SLED

Jason Maass is Vice President of Okta's SLED (State, Local Government, and Education) business. He brings deep expertise in serving public sector customers within the technology and cybersecurity domains. His background includes driving substantial growth and building high-performing teams during nearly a decade in leadership roles.

Continue your Identity journey