The week ending June 20, 2026, delivered a wave of cybersecurity developments that signal a fundamental shift in how enterprises are approaching AI-driven threats. From real-time identity controls for autonomous agents to a landmark courtroom battle over software licensing rights, the industry is navigating complexity at a pace that is testing the limits of traditional security frameworks.
Artificial intelligence is no longer just a tool for defenders. It is increasingly the attack surface itself. AI agents now operate inside enterprise networks with system-level privileges, moving at machine speed and accessing sensitive data across cloud, SaaS, and on-premises environments. That reality is forcing cybersecurity vendors, telecoms operators, and corporate legal teams to adapt, and fast.
The stories below cover the five most consequential developments from this week in enterprise security, AI risk, and digital infrastructure. Together, they paint a picture of an industry scrambling to secure a new era of computing before bad actors get there first.
CrowdStrike Targets AI Agent Risk with Continuous Identity Launch
What the New Capability Does and Why It Matters
CrowdStrike announced Continuous Identity for AI Agents at Identiverse 2026 in Las Vegas, a new capability within its Falcon Next-Gen Identity Security portfolio that reinforces the Falcon platform as the identity security control plane for the agentic enterprise.
The core problem the product addresses is one that has been building quietly inside corporate IT environments. AI agents invoke tools, access sensitive data, call APIs, and delegate to sub-agents at machine speed with system-level privilege. Legacy access models were never built to control this.
The new offering moves beyond traditional access controls that rely on static policies and standing privileges. Instead, every action performed by an AI agent is evaluated in real time based on who owns the agent, who initiated the request, and the security posture of the associated device.
How the Technology Works
The offering uses cryptographically verifiable identities based on the SPIFFE standard, evaluates access by who owns an agent, who is calling it, and device risk posture, and removes standing privileges entirely. The release also links the capability to technology from CrowdStrike’s acquisition of SGNL.
CrowdStrike Chief Technology Officer Elia Zaitsev framed the shift in stark terms. “AI agents are transforming how work gets done, and how identities must be secured,” Zaitsev said. “Authorize once and trust indefinitely is not a security model; it’s a liability.”
The feature shifts away from static, long-lived permissions and instead authorizes individual agent actions in real time based on ownership, context and risk signals from across the Falcon platform. CrowdStrike is pitching the feature at identity and access management architects working with agent-based automation in areas like IT support, finance, and software development.
Broader Industry Implications
Continuous Identity for AI Agents extends CrowdStrike’s risk-aware authorization across every identity, including human, non-human, and AI agent, from initial access to privilege escalation and lateral movement spanning on-premises, SaaS, browser, and cloud environments.
Industry observers will be watching whether the performance overhead of continuous, real-time authorization creates friction in latency-sensitive workflows, and how well the technology interoperates with third-party agent platforms outside the Falcon ecosystem.
BT Becomes First UK Company to Join Anthropic’s Project Glasswing
A Major Step for UK Critical Infrastructure Security
BT has become the first UK company to confirm its membership of Anthropic’s Project Glasswing, giving the company access to Claude Mythos Preview, Anthropic’s frontier AI model, and strengthening BT’s protection against cybersecurity threats for its networks and customers.
The announcement was made by BT CEO Allison Kirkby during the UK Government’s first-ever AI Adoption Summit. The event featured the Chancellor of the Exchequer and the Secretary of State for Technology, underscoring the strategic importance the UK government is placing on AI-assisted cyber defense.
BT’s scale makes the partnership significant. BT says it now blocks around four million cyber attacks across its networks every day, illustrating both the volume of malicious activity targeting digital infrastructure and the need for increasingly automated defenses.
What Project Glasswing Has Already Found
Since its launch in early April 2026, Project Glasswing has already uncovered more than 10,000 high- or critical-severity vulnerabilities within the codebases of participating organizations. That number reflects the speed advantage AI-assisted security scanning holds over traditional methods.
The frontier model has proven benefits across identifying previously unknown software vulnerabilities, including a 16-year-old and a 27-year-old vulnerability, generating potential exploit paths and recommending security patches, though it remains unreleased to the general public over concerns that it could be misused by attackers.
On June 2, Anthropic expanded Mythos access to 150 new organizations across more than 15 countries, including Australia, Canada, France, Germany, Italy, Switzerland, the Netherlands, Spain, Belgium, Sweden, India, Japan, New Zealand, and South Korea.
BT’s Strategic Rationale
BT CEO Allison Kirkby stated that AI only works at scale when it is underpinned by future-ready networks that are secure, resilient, and safe. She also emphasized BT’s commitment to working with the government to support the further development and deployment of sovereign British AI capability, so the UK can be an AI maker and not just a taker.
Jon James, BT Business CEO, added that joining Project Glasswing will strengthen the company’s own cybersecurity capability to protect BT’s networks, its customers, and the wider UK.
Okta Expands Google Cloud Partnership to Secure AI Workforce Identities
The Growing Gap in AI Agent Security Controls
The Okta-Google Cloud partnership expansion this week addresses a gap that enterprise security teams are increasingly alarmed about. Okta cited research showing that 92% of executives report moderate or widespread use of AI agents, while only 34% of organizations apply the same security controls to agents that they apply to human workers.
Identity-based attacks such as session hijacking rose 127% year-over-year, as attackers continue to steal post-authentication session tokens stored in the browser. The combination of uncontrolled AI agents and rising session theft creates a compounding risk that neither problem alone captures.
What the Partnership Delivers
The deal pairs Okta’s identity layer with Google Cloud’s Gemini Enterprise Agent Platform and Chrome Enterprise.
The integration includes five features: user authentication that ensures only verified users can activate an agent; a Token Vault that securely stores OAuth tokens so agents can act on behalf of users; human-in-the-loop approval checkpoints for higher-risk actions; fine-grained authorization controls; and authentication support for Model Context Protocol servers.
The browser integration includes support for Device Bound Session Credentials, an open standard that cryptographically links a session to a specific device through the Chrome browser. Okta worked with Google Cloud as a design partner on the standard.
What Google Cloud Said
Vineet Bhan, Director and Global Head of Security and Identity ISV Partnerships at Google Cloud, said securing the AI-powered enterprise requires a layer of identity security that operates seamlessly across the core platforms that power modern work. “Together with Okta, we’re extending that foundation across Google Cloud,” Bhan said.
A second integration, coming soon, will register agents centrally and route requests via the Google Agent Gateway to delegate real-time authentication and authorization back to Okta.
Tesco Sues Broadcom for Over £100 Million in VMware Licensing Dispute
A Lawsuit That Has the Enterprise Tech World Watching
Tesco, the UK’s largest retailer, is migrating approximately 40,000 server workloads away from VMware infrastructure while simultaneously suing Broadcom for what it calls “abusive conduct” in the UK’s High Court.
The lawsuit, seeking damages exceeding £100 million, alleges that Broadcom’s post-acquisition overhaul of VMware’s licensing model effectively destroyed perpetual licenses Tesco had already paid for.
The Contract at the Center of the Dispute
On January 29, 2021, Tesco originally purchased VMware software licenses from Computacenter, which, along with VMware and Broadcom, is a defendant in the legal dispute. The products covered include VMware vSphere Foundation and VMware Cloud Foundation licensed perpetually, and VMware Tanzu Basic and Tanzu Mission Control, which were licensed under an initial contract term up to January 28, 2026.
After Broadcom took over in November 2023, Tesco says it faced price hikes of around 175% and was forced into more expensive subscription bundles. Broadcom refused to continue standalone support for the perpetual licenses Tesco had already paid for.
Tesco’s legal filings sum up the situation bluntly: “Faced with Broadcom’s abusive conduct, and given the criticality of virtualization and mainframe software and services to its business, Tesco has been forced to incur material costs to procure alternative solutions with reduced functionality.”
The Migration and What Comes Next
Tesco is not waiting for the court case to resolve. It has set a deadline of the end of 2027 to complete the migration, choosing to move now rather than depend on a legal outcome.
The matter is due to be heard in the UK’s High Court during a window that opens on November 1, 2027, and closes on February 25, 2028. Broadcom has fought other high-profile cases over its licensing changes, most notably with AT&T and Siemens. The AT&T case reached a confidential settlement, but the Siemens case is ongoing.
Tesco’s case has caught the attention of enterprise procurement teams because it exposes the risk of perpetual license agreements with vendors that can be acquired and restructured overnight.



