AI-native is not a feature. It's a starting assumption.
A $60M seed round just landed on the claim that identity needs to be rebuilt from scratch for the agent era. The argument is interesting. The question underneath it is harder.
A company called Oak raised $60 million this week to build what they are calling an AI-native Identity Operating System. One control plane for every identity in the enterprise: human, machine, AI agent. Their founding claim is that the tools enterprises currently use to govern identity were not built for this. That to govern AI agents correctly, you have to start over.
I think they are right about the problem. I am less certain about the logic that follows from it.
The word AI-native is getting applied to everything right now. It is becoming a marketing prefix the same way cloud-native was a decade ago, and like cloud-native it is going to mean whatever the speaker needs it to mean in any given conversation. But underneath the noise there is an actual definition worth extracting, because in identity specifically the claim means something precise.
A traditional identity system was built around a human lifecycle. A person joins an organization. They are provisioned. They get certified. They get deprovisioned. The entire governance machinery, the access reviews, the role model, the entitlement catalog, was architected around the assumption that every identity has a human owner who can be asked about it and who will be responsible for it. The compliance rituals we built, the quarterly certifications, the access reviews, the attestations, they all assume a person on the other end of the question. Someone who can be held accountable for what the identity does.
AI agents do not have human owners in any meaningful sense. They act autonomously. They spin up credentials dynamically. They call APIs, write to databases, and sometimes spawn other agents, all without a human in the loop on each decision. The governance question for an AI agent is not whether a manager should approve its access. It is what the agent did, whether the action was in bounds, and whether the credential it used was the one it was supposed to have. Those are different questions and the existing machinery is not built to ask them.
So when Oak says AI-native, what they are actually saying is this: the foundational primitives are wrong. Role-based access control assumes identities are stable things you can assign buckets to. Certification assumes you can snapshot state and have a human verify it on a schedule. Both assumptions break when the identity is an agent that has been alive for three minutes, used a dynamically-generated token, and will not exist in the same form tomorrow. Starting over is not rebuilding the same system with a coat of paint. It means designing primitives that fit the actual object you are governing.
That argument is right. The question that does not follow automatically from it is whether a clean-slate vendor wins, or whether the incumbents who control the identity perimeter in most large enterprises get there first by retrofit.
I am genuinely unsure. The clean-slate argument says you cannot retrofit your way to correct primitives. The incumbent argument says the real moat in enterprise identity is not the product, it is the integration surface and the trust that comes from already being inside the perimeter. SailPoint just paid $200 million for Entro. Cisco bought Astrix. These are not companies who believe you have to start over. They believe they can bolt the new capability onto the existing body. Maybe they are right. Maybe the retrofit is good enough and the integration advantage wins.
What I keep coming back to is a simpler version of the question. If you had to design the access review for an AI agent from scratch, what would it look like? Not the process you would adapt from what you have now. The thing you would actually build if there were no existing machinery to preserve. I do not think it looks like a certification campaign. I do not think it involves a manager clicking approve. I think it looks more like continuous behavioral observation with anomaly flagging and event-derived state. And if that is right, the question is whether you can get there by extending what you have, or whether the extension is doing so much violence to the original design that you would have been better off starting over.
That is the bet Oak is making. Sixty million dollars says they are right that starting over is better. The market is about to find out.
What does the thing you would actually build look like?