CrowdStrike, Okta Warn AI Is Turning Cybersecurity Into an Enterprise Imperative Following “Mythos Moment”

The security and identity firms' quarterly earnings indicate AI agents are pushing cybersecurity, identity governance and enterprise readiness up the boardroom agenda now

5
Security, Privacy & ComplianceNews

Published: August 27, 2026

Nicole Willing

The cybersecurity market is entering a new phase as enterprises move from securing AI infrastructure to securing autonomous agents that can act on their behalf.

Cybersecurity technology vendors CrowdStrike and Okta indicated in their quarterly earnings results that strong enterprise demand is increasingly being linked to the security implications of AI agents.

The “Mythos Moment” Has Become an Enterprise Security Issue

CrowdStrike Chief Executive Officer (CEO) George Kurtz framed the quarter around what he called the “Mythos moment, an inflection point in cybersecurity,” referring to the launch of Anthropic’s Mythos frontier AI model, which has exposed the ability of advanced AI systems to carry out deceptive and potentially harmful actions.

“The world came to understand that cybersecurity is a necessity for AI adoption. New models created a new risk environment with no turning back.”

Kurtz then linked that realization to the emergence of autonomous AI agents.

“Recently, this realization became even clearer with the market’s newest adversary, AI agents themselves. We told you this was the future, and this future is now a reality.”

This week, the results of an investigation into OpenAI’s breach of AI platform Hugging Face found that approximately 700 autonomous agents had escaped their evaluation environment and conducted a coordinated attack. OpenAI said the agents accessed connected systems, stole credentials and altered infrastructure, while the independent researchers found evidence of coordination and attempts to conceal their activity.

The issue for enterprise security teams is now less about whether an AI model can generate malicious code and more about what happens when an autonomous system has credentials, access to enterprise tools, persistent connectivity and the ability to act without waiting for a human decision.

“We are seeing agents go rogue, swarming to attack and moving beyond their guardrails to autonomously harm,” Kurtz said. “Agents are proving capable of data theft, permission alteration, and full-on command and control at scale, leading to organizational compromise.”

Protecting enterprise systems from infiltration by autonomous agents is a materially different security proposition from protecting a conventional software application.

CrowdStrike’s second-quarter revenue increased by 26 percent year over year to $1.47BN, while annual recurring revenue (ARR) increased 25 percent to $5.84BN. Net new ARR reached a record for the company at $333MN, climbing by 51 percent year over year and prompting the company to raise its full-year guidance for net new ARR growth to 34 percent at the midpoint.

Okta’s second-quarter results point to a similar enterprise spending environment from the identity side. Revenue reached $805MN, with new products accounting for approximately 30 percent of bookings and deals incorporating those products generating an average 40 percent ACV uplift. The company also reported more than 600 customers with annual contract value above $1MN, up by more than 20 percent year over year.

Okta Sees the Same Shift Through Identity

Okta’s results point to the same trend. CEO and Co-Founder Todd McKinnon said on the company’s earnings call that AI is changing the role of identity management in an enterprise.

“The emerging use of AI by organizations and threat actors alike has further elevated the role identity plays within a company’s security posture.”

More importantly, Okta is seeing AI conversations trigger broader infrastructure and identity-modernization projects.

“Organizations are accelerating their infrastructure modernization timelines to address this heightened threat environment,” McKinnon said. “We are seeing conversations that begin with securing AI broaden into identity modernization initiatives.”

A company may initially approach a security vendor because it wants to control AI agents, but once that discussion begins, it can expose weaknesses in identity governance, access management, privileged permissions and legacy infrastructure.

McKinnon described identity as “the primary control plane for securing AI.”

Okta’s customer base indicates how quickly the problem can emerge. McKinnon described one organization where Okta initially detected 50 Claude agents, but a few weeks later the figure had reached 1,500.

“These customers are really tangible, the risk that they’re seeing and the way this is coming into their organization,” McKinnon said.

Enterprise buyers are responding before the next breach

One of the more important signals from Okta’s results is that customers are beginning to address the problem proactively.

“I do not want a big breach to knock this all down, the industry,” McKinnon said. “I want customers to proactively put these no regrets investments in place and then have the right foundation to be successful.”

Okta said 81 percent of Chief Information Security Officers (CISOs) it surveyed were aware that agents were deployed within their organizations without an adequate security platform in place.

The security market is beginning to move from a model in which an incident creates demand for security technology toward one in which the deployment of AI itself creates a security requirement.

CrowdStrike is seeing a similar effect, Kurtz said.

“Ever since Mythos, we have seen growth in our business, not measured by meetings or calls, but measured by ARR, and we don’t see the threat landscape subsiding.”

CrowdStrike said Claude usage on endpoints had increased by more than 400 percent in recent months, while custom agent usage had grown by more than 100 percent.

Security Becomes Part of the AI Business Case

The emerging enterprise pattern is broader than a new category of AI security products. Security is becoming part of the business case for deploying autonomous systems.

As Kurtz explained:

“The world’s adoption of AI is rapidly expanding the attack surface. More models, more agents, more agentic applications, more data, and with that, more identities, more permissions, more policies, more cyber attacks, and more risk.”

That also helps explain why cybersecurity spending can benefit from AI adoption even when the security products themselves are not directly responsible for delivering an AI use case.

There is still an important distinction between the two companies.

CrowdStrike is already seeing AI-related security demand translate into substantial financial momentum. Okta’s management remains more cautious about the direct revenue contribution from AI security, saying the opportunity is still early and is unlikely to be material to fiscal 2027 results, although it could become significant from 2028 onward.

The common thread is enterprise readiness.

The Mythos findings established a more concrete understanding of what advanced AI systems could do when they encounter weak controls. The subsequent agent incidents have made the risk easier to imagine in an operational environment.

In a recent interview with CX Today, Frances Zelazny, General Manager of New Market Innovations at identity verification firm Prove, said that the latest incidents should be seen less as isolated failures and more as evidence of unresolved enterprise security fundamentals.

“None of this is surprising, or should be surprising, to anybody who’s been following the state of our cybersecurity frameworks.”

Zelazny added that the security issues emerging around AI agents are an outgrowth from “a lot of the foundational issues around identity security and data governance, and it’s exposing the problems and the weaknesses that were never addressed.”

CrowdStrike’s earnings suggest enterprises are responding with more cybersecurity spending. Okta’s results suggest they are also reconsidering the identity foundations beneath their AI deployments.

As Kurtz put it: “Inflection has become acceleration.”

Security and Compliance
Featured

Share This Post