Five products for agent identity shipped in five weeks. Between late August and late September, Okta launched Agent SSO, Cymphony raised $25 million, AIUC closed $40 million, Baselayer secured $35 million, and Beeline partnered with Insygna. Each addresses a genuine gap. None addresses the same gap. And the shared vocabulary that would make them interoperable does not exist yet.
This is the third instance of a pattern we have been tracking. First, governance formed without measurement — Okta, IBM, Broadcom, and Dataiku each shipped standalone agent control tools between late August and early September, each from a different infrastructure layer. Then, measurement formed without a standard — Salesforce counts agentic work units, Gartner predicts cancellation cliffs, McKinsey flags budget overruns, and none of those numbers talk to each other. Now identity is forming without interoperability. Five vendors, five definitions of what it means to verify an agent, no bridge between them.
What Each Product Actually Does
Okta Agent SSO, which reached general availability August 24, registers AI agents as first-class workload identities inside its Universal Directory. It replaces static API keys with short-lived, identity-governed tokens built on the Cross App Access (XAA) standard. It is bundled into core Okta SSO at no additional cost for 20,000-plus customers.
Cymphony is building a workforce graph that unifies identity, data, and activity signals across employees, AI agents, and non-human identities. The $25 million Series A was co-led by Sequoia and SMBC Fin Atlas Beyond Fund. Sequoia is using Cymphony internally to manage its own exposure — a notable signal when the lead investor becomes an early customer.
AIUC approaches from the compliance side. Its AIUC-1 standard, built with input from 250-plus security and risk leaders, runs approximately 5,000 tests covering jailbreaks, hallucinations, and data leaks, producing a roughly 100-page safety report. The $40 million Series A, led by Ribbit Capital, funds a model modeled on SOC 2 that ties insurance coverage directly to audit results. Cursor and ElevenLabs are already certified.
Baselayer extends its existing business-identity network — already trusted by 2,300-plus financial institutions — to AI agents. Its Know Your Agent framework cryptographically traces each agent back to the deploying platform and the authorizing business. The company claims its infrastructure has helped customers prevent more than $1 billion in fraud losses, a figure that carries the usual self-report caveat.
Beeline and Insygna take the workforce management angle. Through the partnership, Beeline customers can issue every AI agent a verifiable identity before deployment, manage the full agent lifecycle from requisition through retirement, and apply rate cards and budget ceilings so agent cost is controlled rather than discovered at quarter end.
The Gap Underneath
The problem is not that any of these products is wrong. Timothy Hyde, Baselayer’s co-founder and CTO, put it plainly: “Agents don’t carry ID, and the infrastructure built to verify humans and businesses simply doesn’t recognize them.” Each vendor is solving a real operational gap.
The problem is that each product measures something different. Okta measures enterprise SSO compliance. Cymphony measures identity security and visibility. AIUC measures safety certification. Baselayer measures financial KYA and fraud risk. Beeline and Insygna measure workforce lifecycle and cost. There is no shared standard that lets an enterprise reconcile what one tool knows about an agent with what another tool knows.
That fragmentation matters because the scale of the identity problem is accelerating. A January 2026 survey by the Cloud Security Alliance found that non-human identities already outnumber human employees by up to 144-to-1 in many organizations, yet 78 percent of organizations have no documented policy for creating or removing AI agent identities. Only 28 percent can trace agent actions back to a human sponsor.
The NIST AI Agent Standards Initiative, launched in February, is targeting an AI Agent Interoperability Profile for Q4 2026. That profile aims to establish a three-pillar model covering interoperability, security, and open-protocol standards. But it is not released yet. Until it is, enterprises are building on vendor-specific foundations.
What Enterprises Should Understand
The practical risk is technical debt. When an enterprise registers an agent in a proprietary identity system today, it locks that agent’s credential into a specific vendor’s ecosystem. If the enterprise later needs to reconcile that identity with a different system — or migrate when a standard emerges — the switching cost is real.
Gartner projects that more than 40 percent of agentic AI projects will be canceled by 2027 due to costs and unclear value. At the same time, the firm expects 40 percent of enterprise applications to embed task-specific AI agents by the end of 2026. The tension between those two numbers — rapid deployment and rapid abandonment — is exactly where fragmented identity infrastructure creates the most friction. An agent that carries five incompatible credentials from five vendors is harder to govern, harder to audit, and harder to decommission cleanly.
The NIST interoperability profile, if it lands on schedule, could provide the shared vocabulary the market is missing. The question is whether enterprises can afford to wait that long, or whether the identity layer will have already hardened into vendor-specific silos by the time the standard arrives.
We have seen this pattern twice before — in governance, then in measurement. Identity is the third layer to form in isolation. Whether it is the last depends on how fast the standard arrives and how much technical debt accumulates in the meantime.
