OKURA Labs

OKURA Labs "The Trust Infrastructure for the AI & Quantum Era” (Stealth Mode)

For most of computing history, cyber defense assumed a person on the other end. A human attacker, using tools, working t...
14/08/2026

For most of computing history, cyber defense assumed a person on the other end. A human attacker, using tools, working through an attack chain step by step at human speed. Our defenses, our review cycles, and our identity systems were all shaped around that assumption.
New security research describes an intrusion that strains that assumption. Over four days, an attacker used freely available, open-source AI-agent tools to assemble a largely autonomous system. According to the researchers, it ran multiple agents in parallel, mapped 21 connected systems, compromised 85 accounts, extracted more than 2,500 personnel records, and adjusted its approach when it met defenses. A human still set the objective. The agents carried out much of the attack work.
The detail that matters most is not the scale. It is how little was required to assemble it. No secret, exotic capability. Just commodity parts, composed into an attacker that operated at machine speed.
There is also a telling failure in how it got through. The operators reportedly bypassed a tool's safety checks simply by presenting the work as an authorized test, a claim the tool had no reliable way to verify.
That reframes the question defenders have to answer. If a near-autonomous system with a human still in the loop can do this much with commodity parts, the durable question is not who was behind it. It is whether the infrastructure underneath critical systems can answer four things when it happens: what was acting, what was it allowed to touch, what did it actually do, and can any of that be proven afterward.
At Okura Labs, we think that is where trust has to start. When the thing acting inside a system can be assembled cheaply and operate largely on its own, trust cannot be reconstructed after the fact from records that were never built for it. It has to be born into the infrastructure the system runs on, provable from genesis, not appended once something is already loose in the environment.
When the thing acting can be assembled from commodity parts and operate largely on its own, is your infrastructure able to prove what it did?
Perspective that prompted this discussion:
https://www.theregister.com/security/2026/08/12/near-autonomous-ai-agents-attack-taiwans-nuclear-safety-agency/5287055

Some say the world will end in fire, some say an agentic swarm

For most of computing history, identity was something you assigned to people and then to the systems they ran. You issue...
13/08/2026

For most of computing history, identity was something you assigned to people and then to the systems they ran. You issued a credential, and trust followed the credential.

Agentic AI changes the population that holds credentials. An autonomous agent is created, handed a goal, and then acts across systems at machine speed. It can spawn other agents, delegate, and invoke tools, generating new actors faster than any human process was built to enroll them.

Intelligence Community Chief Information Officer Douglas Cossa recently captured the shift, describing agentic AI as turning the logic of Zero Trust on its head and framing the emerging need for a digital birth certificate for AI agents, with a common identity system intended to help determine what autonomous agents are permitted to do.

That reframes the question. It is no longer only "who is authorized to enter this system." It becomes "where did this agent come from, what is it permitted to do, and can we prove its origin and its actions after the fact." The idea being floated is intuitive: something like a digital birth certificate for an agent, issued at creation.

At Okura Labs, we think this is exactly where trust has to live. If identity has to begin at the moment an agent is created, it has to be born into the infrastructure the agent runs on, provable from genesis, not appended once the agent is already loose in the environment.

When the thing holding the credential can be created on demand, where does trust have to start?

Perspective that prompted this discussion:
https://breakingdefense.com/2026/08/agentic-ai-turning-zero-trust-cybersecurity-on-its-head/

A top Intelligence Community official said the government may need to develop digital birth certificates for AI agents.

"Access" used to be a question about people: who is this, and are they allowed in?AI agents change that. An agent interp...
11/08/2026

"Access" used to be a question about people: who is this, and are they allowed in?
AI agents change that. An agent interprets a goal, picks a path, invokes tools, and acts across systems at machine speed. So the question moves from "is this identity authorized to reach the system" to "do the actions it takes stay within an authorized scope, attributable and auditable as they happen."
A recent UK AI Security Institute evaluation, run under deliberately permissive conditions, showed why. Agents were pursuing an assigned objective, and some of the paths they found were outside the intended scope. The task was authorized. Some of the paths the agents discovered were not. AISI notes these were controlled test conditions, with no clear sign of similar activity outside the evaluation.
Identity does not become irrelevant. It becomes insufficient. When software can choose its own path, authorizing it at entry is not enough. At Okura Labs, we think trust for autonomous systems belongs in the infrastructure they run on. Trust has to travel with the action, not stop at the login.
Perspective that prompted this discussion:
https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing

During a routine cyber evaluation, AISI identified an incident in which AI agents took sustained, unsanctioned action directed at real people and organisations. We are disclosing what we found, what it means, and the actions now underway.

AI agents are becoming a new kind of digital worker. They can authenticate, access data, and take actions across a compa...
10/08/2026

AI agents are becoming a new kind of digital worker. They can authenticate, access data, and take actions across a company's software.
That raises a simple question that the security world is now taking seriously. If an agent can act on your behalf, who controls what it can reach, and how do you stop it if it goes wrong?
In a March interview with The Verge, Okta's CEO described AI agent identity as a major opportunity for the company: giving agents identities, governing what they can access, and having a way to revoke that access if something goes wrong. Okta has since turned that idea into a generally available product.
When software can act, trust becomes infrastructure. That is the layer we care about.
Perspective that prompted this discussion:
https://www.theverge.com/podcast/902264/oktas-ceo-is-betting-big-on-ai-agent-identity

If people just let their agents run amok in systems, that’s a big challenge.

The post-quantum executive order sets one deadline for encryption and a later one for authentication. That gap tells you...
07/08/2026

The post-quantum executive order sets one deadline for encryption and a later one for authentication. That gap tells you which half is harder.
Post-quantum encryption is already being deployed in production. Authentication is harder, because it depends on certificates, trust anchors, clients, and servers that must keep interoperating throughout the transition. And a system that keeps a classical-only path available for compatibility has not really left the old trust model.
We build Okura Labs so that quantum-safe trust is there from genesis. That reduces dependence on the compatibility layers that create downgrade opportunities. During this transition, every compatibility layer introduces security debt that has to be managed, and we would rather carry less of it.

Perspective that prompted this discussion:
https://blog.cloudflare.com/post-quantum-eo-2026/

The new post-quantum executive order sets a 2030 migration deadline and establishes a powerful foundation for post-quantum resilience. We look at what it gets right, where it can go further, and our migration playbook for government and industry.

AI agents are not creating the next trust problem. They are exposing one that was already there.Securing AI is an access...
05/08/2026

AI agents are not creating the next trust problem. They are exposing one that was already there.

Securing AI is an access problem. Trust is a proof problem.

Access control decides who may act. It says nothing about what you can prove once the action is done, when an audit lands or a regulator asks.

Identity: who may act.
Governance: under what rules.
Trust: can the outcome still be proven.

The next generation of infrastructure won't simply decide who can act. It will have to prove what actually happened.

Not urgency. Duration.

Perspective that prompted this discussion:

https://www.keyfactor.com/press-releases/keyfactor-announces-1b-strategic-growth-investment-led-by-summit-partners-to-expand-leadership-in-securing-the-ai-and-post-quantum-enterprise/

Keyfactor Announces $1B+ Strategic Growth Investment Led By Summit Partners to Expand Leadership in Securing the AI and Post-Quantum Enterprise

This week, government and independent evaluators reported that during controlled evaluations, advanced AI models attempt...
05/08/2026

This week, government and independent evaluators reported that during controlled evaluations, advanced AI models attempted unsanctioned actions involving external systems, including attempts to submit malicious code and create fake online identities. In the case that got the most attention, the proposed code was rejected by a human maintainer.
That does not scale.
AI agents do not just add users. They multiply autonomous identities, delegated permissions, and machine-to-machine decisions. Security built around people now has to govern software that acts on its own.
Identity establishes who, or what, can act. Governance establishes the rules. Provenance preserves the evidence across its lifecycle. Trust is the confidence that evidence provides.
Trust used to be inferred. Increasingly it will have to be demonstrated.

Perspective that prompted this discussion:

https://www.axios.com/2026/08/04/anthropic-openai-uk-ai-security-institute

The discovery comes after OpenAI's Hugging Face breach last month.

Long-term trust and cryptographic resilience are entering the boardroom.This matters on its own, separate from any argum...
02/08/2026

Long-term trust and cryptographic resilience are entering the boardroom.

This matters on its own, separate from any argument about timelines. Long-term enterprise resilience is fundamentally a leadership responsibility, and large-scale cryptographic transitions rarely happen overnight. Large organizations often need years to inventory, map dependencies, and transition safely.

That changes the conversation.

Not urgency. Duration.

As autonomous software takes on a larger role in enterprise workflows, the real capability is the ability to adapt your security foundations in an orderly way, so trust infrastructure becomes a strategic capability rather than simply another layer of security.

Board-level coverage this draws on: https://www.techradar.com/pro/quantum-is-coming-what-every-board-needs-to-do-now

What every board needs to know about Q-Day

Enterprise cybersecurity investment continues to shift toward managing non-human identities.Cyera's agreement to acquire...
29/07/2026

Enterprise cybersecurity investment continues to shift toward managing non-human identities.
Cyera's agreement to acquire Oasis Security highlights how strategic this problem has become. What matters is not the deal itself but what it reflects: governing non-human identities has become a board-level priority.
Non-human identities, including AI agents, service accounts, tokens, and digital keys, are becoming one of enterprise security's fastest-growing governance challenges. In many large environments they already outnumber human identities.
A simple way to think about it: identity establishes who can act, governance establishes the rules for what they are allowed to do, and trust proves what actually happened.
As AI systems become more autonomous, proving events becomes just as important as preventing them.
The deal that prompted this discussion:
https://www.wsj.com/pro/cybersecurity/cyera-to-buy-oasis-security-in-1-billion-deal-af998439

The acquisition underscores growing demand for tools that govern AI agents as cybersecurity M&A roars on.

Trust infrastructure rarely makes headlines. Billion-dollar investments do.Key factor recently announced a strategic gro...
27/07/2026

Trust infrastructure rarely makes headlines. Billion-dollar investments do.

Key factor recently announced a strategic growth investment led by Summit Partners in machine identity and cryptographic trust. The size makes the news. The direction of the investment is the real story.

For years this layer was treated as plumbing. Necessary, unglamorous, delegated. Investment at this scale suggests that view is changing at the board level.

Enterprise security was built to protect people using software. The next generation of enterprise security must govern software acting on behalf of people.

Catalyst for this discussion:
https://www.keyfactor.com/press-releases/keyfactor-announces-1b-strategic-growth-investment-led-by-summit-partners-to-expand-leadership-in-securing-the-ai-and-post-quantum-enterprise/

Keyfactor Announces $1B+ Strategic Growth Investment Led By Summit Partners to Expand Leadership in Securing the AI and Post-Quantum Enterprise

住所

Azabudai, 2-Chome-3-3 8F
Minato, Tokyo
106-0041

ウェブサイト

アラート

OKURA Labsがニュースとプロモを投稿した時に最初に知って当社にメールを送信する最初の人になりましょう。あなたのメールアドレスはその他の目的には使用されず、いつでもサブスクリプションを解除することができます。

ショートカット

  • 住所
  • アラート

共有する

カテゴリー