RSA Agent ID: Securing Enterprise AI Agents
RSA launched RSA Agent ID at The AI Conference in San Francisco to discover, secure, and govern AI agents and shadow AI in regulated industries.

Stock photo for illustration only, not from the actual event
- RSA launched the Agent ID security platform at The AI Conference in San Francisco
- A medium bank audit revealed over 4,000 hidden shadow AI agents
- The platform is built on three modules: Discover, Secure, and Govern
- Discover and Secure will be generally available on November 16, 2026
At The AI Conference in San Francisco, RSA announced the launch of RSA Agent ID, an agentic identity security platform designed specifically for regulated industries such as finance, healthcare, government, and critical infrastructure. We sat down with Jim Taylor, President and Chief Product and Strategy Officer at RSA, to explore how the new platform operates.
Taylor emphasized that AI agents fundamentally change security dynamics because they are not static service accounts. When given a task with poorly worded prompts, agents will execute whatever steps they deem necessary to finish the job without ever getting tired. Furthermore, agents accumulate permissions, data, and access over time without any subsequent review from human operators.

Stock photo for illustration only, not from the actual event
The scale of the issue often shocks even highly regulated organizations. A medium-sized global bank informed RSA that company policy strictly prohibited AI agents. However, an enterprise-wide audit conducted by the security team uncovered more than 4,000 active shadow AI agents running inside their infrastructure. According to IBM data, security incidents involving shadow AI cost an average of $670,000 more than standard incidents.
Taylor highlighted a failure scenario that involved zero malicious attackers. A customer success employee asked an AI agent to pull all customer records from Salesforce to build health charts. The agent began downloading the entire database rapidly, which Salesforce defense systems flagged as a denial-of-service attack, instantly shutting down the corporate instance and issuing a severe warning.
"One operator on the customer service desk took the whole company’s Salesforce instance down by essentially having an agent perform a denial-of-service attack. He didn’t do anything wrong."
Jim Taylor, RSA
RSA Agent ID is delivered through three modular components available individually or as a unified system on the RSA Unified Identity Platform. The Discover module scans endpoints and applications in real-time, Secure acts as an inline gateway checking every tool call against policy, and Govern logs actions to stream evidence directly into customer security information and event management (SIEM) systems.
The rapid proliferation of agentic artificial intelligence in modern enterprises introduces unprecedented identity management challenges. Because agents can dynamically acquire permissions and execute workflows autonomously, traditional perimeter security controls are no longer sufficient. Establishing dedicated identity governance for non-human workers represents a crucial milestone for organizations seeking to prevent accidental operational outages caused by routine prompt execution.
The platform relies on a risk-based engine that evaluates user context, action sensitivity, and target endpoints, escalating high-risk operations to human owners through out-of-band authenticated channels. RSA Agent ID Discover and Secure are scheduled for general availability on November 16, 2026, with the Govern module following in the first half of 2027.
Source: MarkTechPost
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment