← News

Omada buys EmpowerID to govern AI agents at runtime

Omada A/S, an identity governance and administration company, said it acquired EmpowerID and will fold that company’s runtime agent checks into Omada, so an enterprise can decide in real time what each AI agent may do and stop it the moment it steps outside those boundaries.

SOFTWARE desk — agents already act at machine speed inside corporate systems; folding a real-time stop into the identity platform is how a security team tries to catch up without banning agents outright.

Who the wire says bought whom, and the words it uses for each company. Omada A/S, which the release calls a global leader in identity governance and administration, shortened to IGA, announced it has acquired EmpowerID, which the release calls a pioneer in AI agent governance. A/S is the legal name on the wire. IGA, in plain words, is software that decides who, or what, may reach which systems, and that keeps a record of that decision. Global leader, and pioneer, are the company’s labels. This desk did not rank the market. The acquisition, the release says, brings EmpowerID’s runtime agent governance into Omada and strengthens Omada’s security controls for human, non-human, and agent identities. A human identity is a person. A non-human identity is a machine or a piece of software that has its own login. An agent identity is the login for an AI agent, software that can take a series of steps on its own. Runtime, here, means while the agent is acting, not in a review next week. These lines are the release’s. The page does not print a price. This desk did not read a purchase agreement.

The problem the release is selling into, in its own sentences. Every enterprise, it says, now runs software that acts entirely on its own: making decisions, touching sensitive systems, and executing tasks thousands of times a day. In most cases, no one in the enterprise is fully certain what that software is allowed to do. AI agents have become the fastest-growing identity population inside the enterprise, and also the least governed. The access controls built for human employees were not designed for something that moves, and can go wrong, at machine speed. Together, the release says, Omada and EmpowerID change that. Their combined platform lets organizations decide in real time what each agent is permitted to do, and lets them stop it the instant it steps outside those boundaries, instead of finding out what happened at the next audit. Thousands of times a day, fastest-growing, and least governed are the release’s claims. This desk did not count an enterprise’s agents, and it did not watch an agent get stopped.

What the release says the combined platform will deliver, and the June line it hangs on. The acquisition follows Omada’s June announcement of its Agent Governance solution. That sentence is the release’s context. This desk did not open the June page, and this filing does not describe that earlier product. With this new investment, the release says, Omada will deliver five things. New investment is the release’s phrase. The page does not print a dollar figure beside it. First, governance for every identity: human users, applications, workloads, and AI agents are managed through the same lifecycle, access, and certification services. A lifecycle is the path from when an identity is created to when it is removed. A workload, here, is a job the software runs, such as an application service. Certification is a review of the access an identity still holds. The release says that creates one record of what an identity is and one decision about what it may do. Second, a single view of all identities and access: a continuously maintained view of identities, entitlements, and relationships across every connected system feeds governance, authorization, and risk evaluation from a single source rather than three separate copies. An entitlement is a permission already granted. Three copies is the release’s contrast. This desk did not count a customer’s databases. Third, runtime authorization: access decisions are made at the moment of the request, for people and for agents, using live risk and governance context, so a change made in review takes effect on the next call rather than the next sync. A sync is a later copy of the permission list. The next call is the next time a person, or an agent, asks to do something. Fourth, agentic governance from discovery to control: discovery of AI agents, their identities, tools, and reach; ownership and lifecycle management; certification of what they hold; and runtime control of what they may do, all inside the same fabric that governs human access. Fabric is the release’s word for that one system of rules. Fifth, continuous compliance evidence: every grant, decision, and review is recorded as evidence at the time it happens, so proof of control is a by-product of the fabric rather than a project assembled before each audit. These five are the release’s list. They are not a demo this desk ran.

The chief executive, as a quote, not as a study. Jakob H. Kraglund, identified as CEO of Omada, said AI agents are already acting inside enterprise systems faster than most security teams can track. He said the acquisition means Omada can tell customers not just what their agents have access to, but can also stop those agents the moment they step outside the lines, in real time, not after the fact. He called that the difference between governing AI and just monitoring it. That is his sentence on the wire. A quote is not a stop this desk timed. This desk did not interview him.

Who moves, and what he says the product was built to do. EmpowerID’s CEO and co-founder Patrick Parker will join Omada as chief innovation officer, to drive innovation and development of next-generation identity security capabilities and to support the integration of EmpowerID’s agent governance technology into Omada’s platform. Chief innovation officer is the title on the wire. The page does not print a start date. Parker, identified in the quote line as CEO of EmpowerID, said they built EmpowerID to govern identity as one platform that manages every human and AI agent and proves in real time what each one is allowed to do. He said that with Omada they continue building on that foundation and bring it to enterprises at a scale they could not reach alone. He said it is what the AI era demands, and that together they can deliver it faster than anyone. Faster than anyone is his claim. This desk did not survey other vendors, and it did not interview him.

The analyst quote, and only that sentence. Martin Kuppinger, identified as Distinguished Analyst and Co-Founder of KuppingerCole Analysts, said AI agents act at machine speed, and governing them after the fact is not enough. He said that with EmpowerID, Omada adds runtime authorization and security for AI agents to its IGA foundation, extending governance from who is entitled to access to what agents are actually permitted to do, as they do it. Entitled to access is the permission on the books. Permitted to do, as they do it, is the check at the moment of the action. That distinction is his sentence. It is not a test this desk ran. This desk did not interview him.

Who advised, and what the about box says the company is. Investment banking company Stephens provided strategic advice to Omada and its shareholders on the transaction. Strategic advice is the release’s phrase. The page does not print a fee, a fairness opinion, or a second adviser. The about box says Omada helps organizations govern access across every human, non-human, and AI identity. It says the IGA platform is highly configurable, deployable in weeks rather than years, and designed to reduce risk while providing clear, audit-ready evidence. Weeks rather than years is the company’s claim. This desk did not time an install. Danish-built, it says, and customers control how and where the platform runs, with a range of cloud and managed infrastructure options, and who can reach their data. The site it names is https://www.omadaidentity.com. SOURCE Omada is the wire’s last line. The media contact is parked in the source note. These lines are the about box, except the Stephens sentence, which is the release’s. This desk did not read a banker’s memo.

Plain English for the rest of the card. IGA, identity governance and administration, is the software that decides which person, application, or agent may reach which system, and that keeps the record. An AI agent is software that can take steps on its own, not only answer one question. Runtime authorization is the permission check on each action as it happens, instead of a report after the fact. A stop, in this release, is that check saying no when the agent steps outside the lines it was given. An entitlement is a permission already on the books. Certification is a review of what an identity still holds. A sync is a later copy of that list. The next call is the next request. A fabric, here, is the one set of rules the release says will cover people and agents. 09:00 ET is 9:00 a.m. Eastern and 1:00 p.m. UTC. Copenhagen is the dateline city, and the wire does not print a Copenhagen clock. Patrick Parker is the EmpowerID chief executive who the wire says will join as chief innovation officer. Jakob H. Kraglund is Omada’s chief executive. Martin Kuppinger is the KuppingerCole analyst on the quote line. Stephens is the investment bank the wire says advised Omada and its shareholders. This filing is the 24 Sep announcement. It is not a product this desk installed.

PRIMARY here: Omada’s 24 Sep 2026 PR Newswire release, stamped Sep 24, 2026, 09:00 ET and datelined Copenhagen — Tier A PRIMARY, the company’s own announcement. The has-acquired sentence, the pioneer and global-leader labels, the runtime agent governance line, the human, non-human, and agent identity line, the thousands-of-times-a-day sentence, the fastest-growing and least-governed claims, the real-time stop versus the next audit, the June Agent Governance sentence, the five deliverables, the Kraglund quote, Parker’s move to chief innovation officer, the Parker quote including faster than anyone, the Kuppinger quote, the Stephens sentence, and the about box are that release’s. NOT claimed: a purchase price, a headcount, a customer count, a Stephens fee, a start date for Parker, that global leader, pioneer, fastest-growing, least governed, weeks rather than years, or faster than anyone was surveyed, that this desk opened the June announcement or read a contract, that this desk installed either product or watched an agent get stopped, a stock tip, or investment advice. The card image is omitted. Distinct from the already-filed lumos-mcp-governance, collibra-maestro, salt-security-aidr, and cisco-talos-cairn.

RELATED

ONLINE

article thread

guidelines

warming…

warming…

On 24 Sep 2026 Omada said it had acquired EmpowerID. The record is the company’s PR Newswire release, “Omada Acquires EmpowerID to Close the AI Agent Security Gap.” The visible stamp is Sep 24, 2026, 09:00 ET, which is 9:00 a.m. Eastern and 1:00 p.m. UTC. The dateline is Copenhagen, Denmark, Sept. 24, 2026. The dateline does not print a second hour. The page’s schema.org datePublished is 2026-09-24T09:00:00-04:00, the same minute as the stamp. dateModified on that schema is 2026-09-24T09:00:42-04:00, forty-two seconds later. This desk read the page as it stood. It did not diff those forty-two seconds. The source line is Omada. The subhead says Omada doubles down on agent governance, helping organizations bring ungoverned AI agent identities under control. Doubles down is the subhead’s phrase. It is not a second product. These lines are the wire’s. This desk did not sit in a signing room.

Sources