How Okta Secures AI Workforce by Leveraging Google Cloud

As AI agents are increasingly working alongside human employees, organisations must treat digital identities with the same security rigour as the traditional workforce.
However, the automated ecosystems of the new world are pushing traditional boundaries of identity security to their limits.
In a significant move to address these emerging challenges, Okta is expanding its strategic collaboration with Google Cloud.
By combining their identity, cloud and productivity solutions, the two organisations are working to strengthen resilience across the modern workforce.
Vineet Bhan, Director and Global Head of Security and Identity ISV Partnerships at Google Cloud, notes that in order to secure AI-powered enterprise, a layer of identity security operating seamlessly across core platforms, is required.
He says: āTogether with Okta, we're extending that foundation across Google Cloud ā so customers can confidently deploy AI agents in production, govern how they interact with critical systems and maintain strong protection across the browser.ā
Browser-based workflows at risk
The integration of automated tools into daily enterprise workflows increases efficiency but also creates a distinct set of operational and security challenges.
Modern work is evolving quickly as automation becomes a routine part of the workplace. According to Okta's AI Agents at Work market report, 92% of executives report moderate or widespread use of AI agents within their organisations.
Despite this widespread adoption, only 34% of organisations apply the same security controls to these digital workers as they do to human employees. This discrepancy leaves a massive governance vacuum, opening a door for malicious actors to exploit.
Identity-based exploits are rising sharply as a result of this security gap. Session hijacking has seen a 127% year-over-year increase as threat actors focus on stealing post-auth session tokens stored directly in the browser.
Flexibility and platform interoperability also remain top priorities for technology leaders. Approximately 62% of IT executives view vendor lock-in as a strategic risk, highlighting the critical need for open, interoperable security ecosystems.
Ely Kahn, CPO at Okta, says: āOrganisations shouldnāt have to choose between the AI and productivity tools their teams want and the security their business requires. Okta and Google are a natural fit because we pair Googleās leading product suite with an identity layer that can work across the entire modern, AI-powered work stack.
Identity governance for autonomous agents
To eliminate identity blind spots as enterprises scale their automated systems, the collaboration delivers a structured identity framework. This framework is divided into immediate deployment capabilities and upcoming pipeline features.
Auth0 for AI Agents now integrates directly with the Agent Runtime on the Gemini Enterprise Agent Platform. This integration provides a secure identity layer that accelerates the transition from pilot projects to live production by mitigating the need for custom coding.
Developers can embed enterprise-grade identity and access controls into their workflows using several core features:
- User authentication: Verifies that only authenticated users can invoke an agent
- Token Vault: Stores, manages and refreshes OAuth tokens to safely connect agents to downstream services
- Human-in-the-loop workflows: Trigger human approval checkpoints for high-risk actions while agents work in the background
- Fine-Grained Authorisation (FGA): Ensures that agents perform only the specific actions a user is permitted to take
- Auth for MCP: Adds authentication and authorisation to any Model Context Protocol server.
As enterprise agent fleets expand, answering fundamental questions about agent visibility and policy enforcement becomes vital.
Okta for AI Agents will soon also integrate with the wider Gemini Enterprise Agent Platform to ensure all automated tools possess a verified identity.
The upcoming capabilities will continuously import agents into a centralised directory to maintain human accountability while routing external requests through a real-time policy enforcement point.
Strengthening security across the modern work stack
Since modern enterprise activity increasingly takes place within a web browser, securing this layer is just as crucial as governing the automated tools running inside it.
Organisations face continuous threats from credential theft and malicious extensions, which create visibility gaps.
To address these vulnerabilities, Okta and Chrome Enterprise are turning the browser into a policy-enforced work environment. This configuration protects applications, data and gen AI use on both managed and unmanaged devices without disrupting daily workflows.
The Chrome Enterprise Universal Enrollment feature enables IT teams to enforce enterprise-grade policies through managed Chrome profiles on any device. This is available through the Okta Integration Network and functions without requiring identity synchronisation to Google.
Device trust enhancements will integrate Okta Device Assurance with the Chrome Device Trust Connector to evaluate browser and device posture in real time.
Meanwhile, new antivirus signals allow Chrome to block logins at the browser level if a device has out-of-date protection.




