Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Okta: Balancing AI Innovation with Security in Payments

Okta
04/25/2026
0
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


TL;DR

  • AI tools are designed to encourage data sharing, making it critical for financial services companies to implement rigorous approval processes and employee education frameworks before allowing AI integration with sensitive systems.
  • Equals Money uses Auth0 to capture identity and device signals at login, then feeds this data into risk platforms to enable intelligent security decisions throughout the customer journey rather than relying solely on front-door authentication.
  • The rise of agentic AI in payments creates significant security risks as consumers may share credentials with unvetted DIY agents, highlighting the urgent need for industry standardization and regulatory frameworks.
  • Account takeover attempts have evolved from simple phishing to sophisticated, orchestrated campaigns that use fake websites and paid advertising, requiring professional security approaches that detect patterns across multiple customers.
  • Okta's Identity Security Posture Management helps Equals Money monitor non-human identities and AI tool integrations in real-time, preventing employees from inadvertently granting excessive permissions to AI agents in production environments.

AI Adoption Challenges in Financial Services

James Simcox, COO and CPO at Equals Money, discusses the dual pressures facing financial services companies as they navigate AI adoption. While teams are eager to leverage AI tools for efficiency gains, the ease of integration creates significant security risks. AI platforms are designed to encourage data sharing, making it simple to connect Slack, email, and other systems with a single click. Equals Money addresses this by treating AI tool procurement like traditional software purchases, conducting thorough security reviews that examine training data practices and privacy policies. The company has established clear frameworks that define acceptable AI use cases while educating employees on data handling boundaries. This approach recognizes that security ownership extends across the entire organization, with AI representing an extension of existing security responsibilities rather than a separate domain.

Identity-Driven Security Across the Customer Journey

Rather than concentrating security measures solely at the login stage, Equals Money implements a distributed security model that monitors risk throughout the entire customer journey. The company uses Auth0 to capture device information, location data, and authentication patterns at login, then feeds these signals into downstream risk platforms. This approach allows the security team to build a comprehensive risk profile that informs decisions at critical moments, such as when customers initiate payments. By correlating login behavior with transaction patterns, the system can identify anomalies that might indicate account takeover attempts without adding friction for legitimate users. The strategy acknowledges that customers have varying technical capabilities and preferences, supporting traditional authentication methods for vulnerable populations while encouraging more secure options like passkeys for corporate clients. This balanced approach protects customers without creating barriers that could exclude those less comfortable with newer security technologies.

Agentic AI and the Future of Payment Security

The emergence of agentic AI presents both opportunities and significant security challenges for the payments industry. Simcox notes that the first agentic AI payment occurred recently at a conference, signaling the beginning of a major shift in how customers will interact with financial services. However, the industry faces a critical standardization problem, with multiple competing protocols like X402 and agentic commerce protocol creating fragmentation. The proliferation of DIY agent builders enables consumers to create custom agents for tasks like booking and paying for holidays, but these tools often lack proper security frameworks. This creates scenarios where users might unknowingly share login credentials with unvetted third-party agents, similar to the screen scraping practices that preceded open banking regulations. Without clear regulatory frameworks and industry standards, consumers seeking convenience may inadvertently expose themselves to sophisticated account takeover schemes. The payments industry must rapidly establish security standards and consumer protections before widespread agentic AI adoption creates systemic vulnerabilities.

Chapters

0:00 - Introduction
1:03 - AI Adoption Pressures
2:14 - Invisible Security Strategy
4:14 - Account Takeover Threats
6:33 - Agentic AI Transformation
9:48 - Employee AI Security
11:38 - Closing

Key Quotes

1:32 "AI tools are designed sometimes to make you want to overshare with them. It's so easy just to click a button and link up your Slack or link up your email."
3:25 "We get from Auth0 that we then feed into other systems. So a customer signs in, great, it's a new device, it's a new location, but they use their usual 2FA method, so it's probably fine, right? And we'll let them in the platform there, but we feed all that information about the device, where it came from, everything else into our risk platforms."
5:55 "Actually AI's not helping us, right? Because with AI agents, you can actually behave like a human in that login journey. And so what used to be really obvious, because it's a bot, and they're just attacking the thing, and you go, well, you're a bot, come on, go away. Now it actually can look like a real human login journey, because agents behave like humans."
7:14 "There's a whole bunch of standards that everyone's creating right now, right? There's X402, there's agentic commerce protocol, there's others out there. And until we standardize on one of those things, it's going to be very hard for us to build our products to make it work for the customers the right way."
9:39 "You wouldn't just email your bank password to someone, but you'll happily give an AI agent your bank password potentially. And that is a concerning place for us to be."
10:52 "That's why I bought Okta's Identity Security Posture Management tool to help us secure those non-human identities in the platform. And that's how Okta helps us secure AI."
Categories:
  • » Cybersecurity » Cloud Security
  • » AI & Machine Learning
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Identity & Access
  • AI & Machine Learning
  • Cloud Security
  • Executive Briefing
  • Customer Story
  • AI security
  • Identity and access management
  • Account takeover prevention
  • Agentic AI
  • Payment security
  • Shadow AI
  • Non-human identity management
  • Customer journey security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Okta: Balancing AI Innovation with Security in Payments

              Upcoming Webinar Calendar

              • 05/12/2026
                11:30 PM
                05/12/2026
                Implementing Effective Strategies for Active Directory Security and Data Protection
                https://www.truthinit.com/index.php/channel/1888/implementing-effective-strategies-for-active-directory-security-and-data-protection/
              • 05/13/2026
                01:00 AM
                05/13/2026
                Transforming the Black Box: Reveal Hidden Threats and AI Risks through Data Lineage
                https://www.truthinit.com/index.php/channel/1890/transforming-the-black-box-reveal-hidden-threats-and-ai-risks-through-data-lineage/
              • 05/13/2026
                05:00 AM
                05/13/2026
                Transforming the Black Box: Revealing AI Risks and Hidden Threats through Data Lineage
                https://www.truthinit.com/index.php/channel/1894/transforming-the-black-box-revealing-ai-risks-and-hidden-threats-through-data-lineage/
              • 05/19/2026
                01:00 PM
                05/19/2026
                Establishing a Robust AI Governance Framework for GenAI Throughout Deployment Phases
                https://www.truthinit.com/index.php/channel/1936/establishing-a-robust-ai-governance-framework-for-genai-throughout-deployment-phases/
              • 05/20/2026
                08:00 AM
                05/20/2026
                Establishing a Robust AI Governance Framework for GenAI Throughout Its Lifecycle
                https://www.truthinit.com/index.php/channel/1937/establishing-a-robust-ai-governance-framework-for-genai-throughout-its-lifecycle/
              • 05/20/2026
                10:00 PM
                05/20/2026
                Establishing a Robust AI Governance Framework for GenAI Throughout Its Lifecycle
                https://www.truthinit.com/index.php/channel/1953/establishing-a-robust-ai-governance-framework-for-genai-throughout-its-lifecycle/
              • 05/21/2026
                11:00 AM
                05/21/2026
                The Autonomous Era: Orchestrating a Resilient Enterprise
                https://www.truthinit.com/index.php/channel/1372/the-autonomous-era-orchestrating-a-resilient-enterprise/
              • 05/27/2026
                04:00 AM
                05/27/2026
                Rivoluziona i rischi dell'AI in opportunità con Netskope AI Security
                https://www.truthinit.com/index.php/channel/1925/rivoluziona-i-rischi-dellai-in-opportunità-con-netskope-ai-security/
              • 05/27/2026
                10:00 AM
                05/27/2026
                Harnessing AI: Transitioning from Illusion to Purposeful Mastery
                https://www.truthinit.com/index.php/channel/1924/harnessing-ai-transitioning-from-illusion-to-purposeful-mastery/
              • 05/28/2026
                01:00 PM
                05/28/2026
                Harnessing AI for Smaller Teams: Strategies for Secure Implementation
                https://www.truthinit.com/index.php/channel/1951/harnessing-ai-for-smaller-teams-strategies-for-secure-implementation/
              • 06/02/2026
                01:00 PM
                06/02/2026
                Spring of Satori: Delving into Recent Findings and the 2026 Threat Landscape
                https://www.truthinit.com/index.php/channel/1930/spring-of-satori-delving-into-recent-findings-and-the-2026-threat-landscape/
              • 06/04/2026
                02:00 AM
                06/04/2026
                Mastering the Unseen: Managing Shadow AI and Agentic MCP Traffic
                https://www.truthinit.com/index.php/channel/1948/mastering-the-unseen-managing-shadow-ai-and-agentic-mcp-traffic/
              • 06/16/2026
                07:00 AM
                06/16/2026
                Transforming Data Risk into Actionable Priorities: Essential Fixes First
                https://www.truthinit.com/index.php/channel/1952/transforming-data-risk-into-actionable-priorities-essential-fixes-first/

              Upcoming Events

              • May
                12

                Implementing Effective Strategies for Active Directory Security and Data Protection

                05/12/202611:30 PM ET
                • May
                  13

                  Transforming the Black Box: Reveal Hidden Threats and AI Risks through Data Lineage

                  05/13/202601:00 AM ET
                  • May
                    13

                    Transforming the Black Box: Revealing AI Risks and Hidden Threats through Data Lineage

                    05/13/202605:00 AM ET
                    • May
                      19

                      Establishing a Robust AI Governance Framework for GenAI Throughout Deployment Phases

                      05/19/202601:00 PM ET
                      • May
                        20

                        Establishing a Robust AI Governance Framework for GenAI Throughout Its Lifecycle

                        05/20/202608:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version