Oct 29, 2025 · 30m · big-technology

AI Agents: Hype or Hope

Eric Kelleher · 22m spoken Alex Kantrowitz · 6m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this interview, Okta President and COO Eric Kelleher joins host Alex Kantrowitz to examine the rapid enterprise adoption of autonomous AI agents, addressing the critical security and governance deficit facing organizations and outlining how standardized agentic identity management can safeguard corporate data.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. Alex holds 21.2% of the talking time here. How this is scored →

Alex as informed peer 3.3 Guest teaching 5.3 Guest disagreement 0.5 Alex pushing back 2.1
05100:0010:0020:0030:002:43–6:23 · Alex as informed peer 4/10 Defining AI Agents: Autonomous Judgment and Action Execution Alex challenges Eric with audience skepticism comparing agents to old API promises and highlights the contradiction between autonomy and human-in-the-loop requirements. Eric clarifies by defining agentic autonomy as asynchronous execution with independent judgment.6:24–9:03 · Alex as informed peer 1/10 The Evolution of Identity: From SaaS to Agentic Identity Alex asks an open-ended question about risk, allowing Eric to give an extended technical overview of identity evolution from SaaS human credentials to non-human machine APIs and now agentic identity.9:05–13:20 · Alex as informed peer 2/10 Innovation Pressure and Security Pitfalls: The Restaurant Case Study Eric educates Alex on the severe security fallout of rushed agent prototyping, citing a major restaurant chain that leaked 60 million applicant records due to default passwords.13:21–15:35 · Alex as informed peer 3/10 Comparing the AI Wave to Prior Generational Tech Shifts Alex probes whether the high deployment stat reflects true enthusiasm or executive pressure. Eric draws on his multi-decade perspective across mainframe, cloud, and mobile shifts to explain why AI feels larger than prior waves.15:36–20:16 · Alex as informed peer 4/10 Standardizing Agent Identity Management Through Cross-App Access Alex presses on how companies justify deploying insecure agents and asks for concrete differences cross-app access makes. Eric details shadow agent data access in personal accounts and how open standards resolve credential rotation.20:17–23:00 · Alex as informed peer 3/10 AI Data Governance and Protecting Proprietary Corporate Information Alex brings up fears around agent actions in enterprise data, prompting Eric to differentiate data visibility from cross-query LLM data harvesting risks.23:01–26:02 · Alex as informed peer 3/10 The Velocity of AI Innovation and Measuring Real Business ROI Alex asks about innovation velocity and planning horizons. Eric explains enterprise ROI struggles, citing internal Okta experimentation and the MIT study indicating 95 percent of AI projects lack tangible return.26:02–28:13 · Alex as informed peer 6/10 Assessing AI Infrastructure Overbuild Risks and Cybersecurity Priorities Alex challenges Eric on potential trillion-dollar infrastructure overbuilds and backs up the security discussion by citing Wiz and recent cybersecurity acquisitions. Eric deflects macroeconomic questions to refocus strictly on enterprise vulnerability.2:43–6:23 · Guest teaching 5/10 Defining AI Agents: Autonomous Judgment and Action Execution Alex challenges Eric with audience skepticism comparing agents to old API promises and highlights the contradiction between autonomy and human-in-the-loop requirements. Eric clarifies by defining agentic autonomy as asynchronous execution with independent judgment.6:24–9:03 · Guest teaching 6/10 The Evolution of Identity: From SaaS to Agentic Identity Alex asks an open-ended question about risk, allowing Eric to give an extended technical overview of identity evolution from SaaS human credentials to non-human machine APIs and now agentic identity.9:05–13:20 · Guest teaching 6/10 Innovation Pressure and Security Pitfalls: The Restaurant Case Study Eric educates Alex on the severe security fallout of rushed agent prototyping, citing a major restaurant chain that leaked 60 million applicant records due to default passwords.13:21–15:35 · Guest teaching 5/10 Comparing the AI Wave to Prior Generational Tech Shifts Alex probes whether the high deployment stat reflects true enthusiasm or executive pressure. Eric draws on his multi-decade perspective across mainframe, cloud, and mobile shifts to explain why AI feels larger than prior waves.15:36–20:16 · Guest teaching 6/10 Standardizing Agent Identity Management Through Cross-App Access Alex presses on how companies justify deploying insecure agents and asks for concrete differences cross-app access makes. Eric details shadow agent data access in personal accounts and how open standards resolve credential rotation.20:17–23:00 · Guest teaching 5/10 AI Data Governance and Protecting Proprietary Corporate Information Alex brings up fears around agent actions in enterprise data, prompting Eric to differentiate data visibility from cross-query LLM data harvesting risks.23:01–26:02 · Guest teaching 6/10 The Velocity of AI Innovation and Measuring Real Business ROI Alex asks about innovation velocity and planning horizons. Eric explains enterprise ROI struggles, citing internal Okta experimentation and the MIT study indicating 95 percent of AI projects lack tangible return.26:02–28:13 · Guest teaching 3/10 Assessing AI Infrastructure Overbuild Risks and Cybersecurity Priorities Alex challenges Eric on potential trillion-dollar infrastructure overbuilds and backs up the security discussion by citing Wiz and recent cybersecurity acquisitions. Eric deflects macroeconomic questions to refocus strictly on enterprise vulnerability.2:43–6:23 · Guest disagreement 1/10 Defining AI Agents: Autonomous Judgment and Action Execution Alex challenges Eric with audience skepticism comparing agents to old API promises and highlights the contradiction between autonomy and human-in-the-loop requirements. Eric clarifies by defining agentic autonomy as asynchronous execution with independent judgment.6:24–9:03 · Guest disagreement 0/10 The Evolution of Identity: From SaaS to Agentic Identity Alex asks an open-ended question about risk, allowing Eric to give an extended technical overview of identity evolution from SaaS human credentials to non-human machine APIs and now agentic identity.9:05–13:20 · Guest disagreement 0/10 Innovation Pressure and Security Pitfalls: The Restaurant Case Study Eric educates Alex on the severe security fallout of rushed agent prototyping, citing a major restaurant chain that leaked 60 million applicant records due to default passwords.13:21–15:35 · Guest disagreement 1/10 Comparing the AI Wave to Prior Generational Tech Shifts Alex probes whether the high deployment stat reflects true enthusiasm or executive pressure. Eric draws on his multi-decade perspective across mainframe, cloud, and mobile shifts to explain why AI feels larger than prior waves.15:36–20:16 · Guest disagreement 0/10 Standardizing Agent Identity Management Through Cross-App Access Alex presses on how companies justify deploying insecure agents and asks for concrete differences cross-app access makes. Eric details shadow agent data access in personal accounts and how open standards resolve credential rotation.20:17–23:00 · Guest disagreement 0/10 AI Data Governance and Protecting Proprietary Corporate Information Alex brings up fears around agent actions in enterprise data, prompting Eric to differentiate data visibility from cross-query LLM data harvesting risks.23:01–26:02 · Guest disagreement 0/10 The Velocity of AI Innovation and Measuring Real Business ROI Alex asks about innovation velocity and planning horizons. Eric explains enterprise ROI struggles, citing internal Okta experimentation and the MIT study indicating 95 percent of AI projects lack tangible return.26:02–28:13 · Guest disagreement 2/10 Assessing AI Infrastructure Overbuild Risks and Cybersecurity Priorities Alex challenges Eric on potential trillion-dollar infrastructure overbuilds and backs up the security discussion by citing Wiz and recent cybersecurity acquisitions. Eric deflects macroeconomic questions to refocus strictly on enterprise vulnerability.2:43–6:23 · Alex pushing back 4/10 Defining AI Agents: Autonomous Judgment and Action Execution Alex challenges Eric with audience skepticism comparing agents to old API promises and highlights the contradiction between autonomy and human-in-the-loop requirements. Eric clarifies by defining agentic autonomy as asynchronous execution with independent judgment.6:24–9:03 · Alex pushing back 0/10 The Evolution of Identity: From SaaS to Agentic Identity Alex asks an open-ended question about risk, allowing Eric to give an extended technical overview of identity evolution from SaaS human credentials to non-human machine APIs and now agentic identity.9:05–13:20 · Alex pushing back 1/10 Innovation Pressure and Security Pitfalls: The Restaurant Case Study Eric educates Alex on the severe security fallout of rushed agent prototyping, citing a major restaurant chain that leaked 60 million applicant records due to default passwords.13:21–15:35 · Alex pushing back 2/10 Comparing the AI Wave to Prior Generational Tech Shifts Alex probes whether the high deployment stat reflects true enthusiasm or executive pressure. Eric draws on his multi-decade perspective across mainframe, cloud, and mobile shifts to explain why AI feels larger than prior waves.15:36–20:16 · Alex pushing back 3/10 Standardizing Agent Identity Management Through Cross-App Access Alex presses on how companies justify deploying insecure agents and asks for concrete differences cross-app access makes. Eric details shadow agent data access in personal accounts and how open standards resolve credential rotation.20:17–23:00 · Alex pushing back 1/10 AI Data Governance and Protecting Proprietary Corporate Information Alex brings up fears around agent actions in enterprise data, prompting Eric to differentiate data visibility from cross-query LLM data harvesting risks.23:01–26:02 · Alex pushing back 1/10 The Velocity of AI Innovation and Measuring Real Business ROI Alex asks about innovation velocity and planning horizons. Eric explains enterprise ROI struggles, citing internal Okta experimentation and the MIT study indicating 95 percent of AI projects lack tangible return.26:02–28:13 · Alex pushing back 5/10 Assessing AI Infrastructure Overbuild Risks and Cybersecurity Priorities Alex challenges Eric on potential trillion-dollar infrastructure overbuilds and backs up the security discussion by citing Wiz and recent cybersecurity acquisitions. Eric deflects macroeconomic questions to refocus strictly on enterprise vulnerability.

speaking balance: gold is Alex, purple is the guest (3 minute bins)

0:00 · Alex 33.3% · guest 66.7%0:00 · Alex 33.3% · guest 66.7%3:00 · Alex 36.6% · guest 63.4%3:00 · Alex 36.6% · guest 63.4%6:00 · Alex 1.8% · guest 98.2%6:00 · Alex 1.8% · guest 98.2%9:00 · Alex 3% · guest 97%9:00 · Alex 3% · guest 97%12:00 · Alex 21.8% · guest 78.2%12:00 · Alex 21.8% · guest 78.2%15:00 · Alex 13.6% · guest 86.4%15:00 · Alex 13.6% · guest 86.4%18:00 · Alex 26.7% · guest 73.3%18:00 · Alex 26.7% · guest 73.3%21:00 · Alex 11.7% · guest 88.3%21:00 · Alex 11.7% · guest 88.3%24:00 · Alex 17% · guest 83%24:00 · Alex 17% · guest 83%27:00 · Alex 45.9% · guest 54.1%27:00 · Alex 45.9% · guest 54.1%30:00 · Alex 50.1% · guest 49.9%30:00 · Alex 50.1% · guest 49.9%
Sharpest disagreement ▶ 26:34 Guest deflects macroeconomic overbuild question

Eric explicitly rejects engaging with Alex's premise regarding macro infrastructure overbuild, redirecting the focus entirely back to Okta's enterprise security lens.

Hardest push from Alex ▶ 26:02 Host questions whether AI infrastructure is being overbuilt

Alex refuses to stay purely on the optimistic adoption framing and directly confronts the guest with the risk of a massive capital expenditure overbuild.

Biggest teaching moment ▶ 10:50 Guest explains default password vulnerability in recruiting agent breach

Eric provides a concrete, revealing case study of a major restaurant chain exposing 60 million applicant records due to rushing a prototype with a default password into production.

Alex holds their own ▶ 27:31 Host cites Wiz and market acquisitions to reinforce security thesis

Alex demonstrates his domain grasp by connecting the conversation to industry insider interviews and major cybersecurity M&A deals like Google's bid for Wiz.

the scores for every segment, with the reasoning behind each
ChapterTopicAlex as informed peerGuest teachingGuest disagreementAlex pushing backWhy
Defining AI Agents: Autonomous Judgment and Action Execution 4514 Alex challenges Eric with audience skepticism comparing agents to old API promises and highlights the contradiction between autonomy and human-in-the-loop requirements. Eric clarifies by defining agentic autonomy as asynchronous execution with independent judgment.
The Evolution of Identity: From SaaS to Agentic Identity 1600 Alex asks an open-ended question about risk, allowing Eric to give an extended technical overview of identity evolution from SaaS human credentials to non-human machine APIs and now agentic identity.
Innovation Pressure and Security Pitfalls: The Restaurant Case Study 2601 Eric educates Alex on the severe security fallout of rushed agent prototyping, citing a major restaurant chain that leaked 60 million applicant records due to default passwords.
Comparing the AI Wave to Prior Generational Tech Shifts 3512 Alex probes whether the high deployment stat reflects true enthusiasm or executive pressure. Eric draws on his multi-decade perspective across mainframe, cloud, and mobile shifts to explain why AI feels larger than prior waves.
Standardizing Agent Identity Management Through Cross-App Access 4603 Alex presses on how companies justify deploying insecure agents and asks for concrete differences cross-app access makes. Eric details shadow agent data access in personal accounts and how open standards resolve credential rotation.
AI Data Governance and Protecting Proprietary Corporate Information 3501 Alex brings up fears around agent actions in enterprise data, prompting Eric to differentiate data visibility from cross-query LLM data harvesting risks.
The Velocity of AI Innovation and Measuring Real Business ROI 3601 Alex asks about innovation velocity and planning horizons. Eric explains enterprise ROI struggles, citing internal Okta experimentation and the MIT study indicating 95 percent of AI projects lack tangible return.
Assessing AI Infrastructure Overbuild Risks and Cybersecurity Priorities 6325 Alex challenges Eric on potential trillion-dollar infrastructure overbuilds and backs up the security discussion by citing Wiz and recent cybersecurity acquisitions. Eric deflects macroeconomic questions to refocus strictly on enterprise vulnerability.

Statements from this episode (12)

Assertion Supported
Kelleher: 90% of Surveyed Okta Clients Deploy Agents, 10% Secure Them
“So our customers that we spoke with told us over 90% of them today have agents that are deployed in production. Yet only 10% of them believe that the agents in production are currently being appropriately managed and secured.”
Eric Kelleher Oct 29, 2025 ▶ 2:16
Insight
Kelleher: Autonomous decision-making sets AI agents apart from past tech shifts
“I think the way that we think about agents that I think about agents is autonomous software that's capable of taking actions on a user's behalf, not synchronously, but asynchronously, and that's capable of applying its own judgment on which actions to execute …”
Eric Kelleher Oct 29, 2025 ▶ 3:30
Insight
Kelleher: Autonomous action distinguishes AI agents from LLMs and brings security risks
“I think when we talk about the distinction between an artificial intelligence, the distinction between a large language model and an agent, I think the ability to take action is a very specific capability of an agent, and it's really the ability to take autono…”
Eric Kelleher Oct 29, 2025 ▶ 5:43
Assertion Partly supported
Kelleher: Major Restaurant Chain's AI Concierge Was Breached, Leaking 60M Records
“Several weeks back, there was a very well publicized incident where one of the world's largest restaurant chains had deployed an agent to help job applicants on its recruiting website. And this is a restaurant that interviews millions of peoples per year. it …”
Eric Kelleher Oct 29, 2025 ▶ 10:44
Assertion Supported
Kelleher: Breached Restaurant AI Agent Used Default Password '123456'
“In fact, they built that agent with a default password of one, two, three, four, five, six.”
Eric Kelleher Oct 29, 2025 ▶ 11:57
Opinion
Kelleher: AI Feels Bigger Than the Internet and Cloud Shifts
“It feels bigger than the introduction of the internet. It feels bigger than the shift to cloud. It is, we expect it to fundamentally transform how businesses operate and how humans operate.”
Eric Kelleher Oct 29, 2025 ▶ 14:38
Disclosure
Okta Mandates Agent Vendors Support Cross-App Access for Internal Use
“At Okta, for example one of the teams I manage is our internal IT organization. We have a policy that we will only support We will only allow agents for our employee use if the vendors of those agents have committed to implementing cross app access support, be…”
Eric Kelleher Oct 29, 2025 ▶ 19:55
Insight
Kelleher: Key AI governance fear is data leaking across queries
“One of the latent concerns people have as they're deploying, deploying third-party agents, is they want to know if that data is going to be used anywhere else. So is it going to be used just for my query to help me do my work, which is usually fine? Or is that…”
Eric Kelleher Oct 29, 2025 ▶ 21:58
Disclosure
Kelleher: Okta has secured and provisioned over 60 AI tools internally
“With Okta internally right now, we have over 60 AI tools that we have secured and provisioned within our enterprise.”
Eric Kelleher Oct 29, 2025 ▶ 25:01
Assertion Supported
Kelleher: MIT study found 95% of AI initiatives lack tangible ROI
“We have, there was a very famous study came out of MIT a couple months ago that said, 95% of AI initiatives have yet to demonstrate a tangible ROI.”
Eric Kelleher Oct 29, 2025 ▶ 25:33
Assertion Supported
Kantrowitz: Google acquired Wiz for $32 billion, its largest deal ever
“I think it's probably the reason why Wiz was acquired by Google for like thirty two billion dollars which is Google's biggest acquisition ever.”
Alex Kantrowitz Oct 29, 2025 ▶ 27:49
Disclosure
Kelleher: Would Only Use Brain AI If It Runs Locally and Privately
“I'd be very curious to have an augmented brain, an AI augmented brain, and the ability to have a co-pilot that can help me navigate my life. So the idea of that's very intriguing, but for me, for that to be something I would actually do, I would need to have c…”
Eric Kelleher Oct 29, 2025 ▶ 28:44
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 300 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.