The Blueprint Alliance brings together 12 founding members—AWS, CrowdStrike, Databricks, Docker, Google Cloud, Lovable, Okta, Proofpoint, Salesforce, ServiceNow, Wiz and Zscaler—to develop a shared security framework for AI agents that operate within business systems, data platforms, networks and infrastructure.
The alliance has expanded an existing blueprint into an open reference architecture that helps organisations govern AI agents, focusing on identity, access, execution and runtime monitoring rather than on model security or supply‑chain integrity alone.
Central to the proposed approach is treating each AI agent as a distinct identity with task‑specific privileges, enabling traceable delegation, continuous runtime behaviour monitoring and rapid containment or restoration when risks arise.
Industry analysts warn that the need for such governance is urgent: Gartner predicts that by 2028 the average Fortune 500 company will deploy more than 150,000 AI agents, yet only 13 % of organisations say they have adequate governance in place.
Dan Mountstephen, Senior Vice President and General Manager for APJ at Okta, said the region’s complex regulatory and multi‑cloud environment makes a collaborative architecture essential for answering four core questions: where agents are, what they can do, what they are doing and how to respond when something goes wrong.
GE Appliances and World Central Kitchen have joined the alliance as strategic advisers, offering real‑world testing in manufacturing and disaster‑response settings. Mandar Deo of GE Appliances highlighted the need for strong governance to unlock AI‑driven value at scale, while World Central Kitchen’s CTO Brian Stoll emphasized the importance of dynamic oversight for mission‑critical agentic tools.
Members are also working on deeper interoperability, using open standards such as MCP, OCSF, SSF and CAEP to share threat and activity signals across products, and plan to publish reference integrations that let companies stitch together solutions from multiple vendors.
Okta’s Steven Tamm said the blueprint was born from customer demand for a consistent, cross‑stack security model that protects AI agents without stifling their autonomy, and expressed confidence that the industry will build on and test the architecture to secure the future of AI.