RSA Launches Agent ID to Tame Shadow AI Agents
RSA announced Agent ID at The AI Conference after one bank's 'no agents' policy hid 4,000 shadow agents. Discover and Secure ship November 16, 2026.
Updated
Why it matters
- Gartner projects a typical Global Fortune 500 enterprise will run roughly 150,000 AI agents by 2028, up from fewer than 15 in 2025, while only 13% of organizations believe they have adequate agent governance.
- RSA's audit of a medium-sized global bank that claimed to have zero agents under a prohibition policy found more than 4,000 running in its enterprise.
- RSA Agent ID Discover and Secure modules become generally available November 16, 2026; Govern follows in the first half of 2027.
One badly worded prompt from a customer service desk took down an entire company's Salesforce instance. An employee asked an agent to "go to Salesforce and get all the data" to build customer health charts. The agent began downloading the entire database, Salesforce's defenses read the traffic as an attack, and the vendor warned the company it appeared to be under a denial-of-service attack.
"One operator on the customer service desk took the whole company's Salesforce instance down by essentially having an agent perform a denial-of-service attack. He didn't do anything wrong," said Jim Taylor, President and Chief Product and Strategy Officer at RSA, in an interview at The AI Conference in San Francisco.
The incident, which involved no attacker at all, illustrates the stakes behind RSA's launch of RSA Agent ID, an agentic identity security platform announced for regulated industries such as finance, government, healthcare, and critical infrastructure.
Why agents break the identity model
The timing reflects a market racing ahead of its security controls. Gartner expects a typical Global Fortune 500 enterprise to run roughly 150,000 AI agents by 2028, up from fewer than 15 in 2025. Only 13% of organizations believe they have the right agent governance in place.
Agents hold credentials, carry entitlements, and act on systems of record. Yet most enterprises cannot say which agents are running, who owns them, or whether anyone can stop them.
"What changes with agents? Everything. They're not a service account. They're not static. They're dynamic. You give an agent a task, and if you badly word that task, it will do whatever it deems necessary to perform it. Agents don't get tired at two o'clock in the morning. They just go," Taylor said.
Agents also accumulate permissions, data, and access over time, and nobody follows up. "Employees create an agent to hit a deadline, but once it's off in the wild, that's it. We don't check when its permissions change. We don't delete or disable agents."
The scale of the problem surprises even regulated firms. A medium-sized global bank told RSA it had no agents, because policy prohibited them. "Agents don't tend to respect policy," Taylor said. "We did an audit and found more than 4,000 agents running around in their enterprise."
The financial penalty is measurable. According to IBM, incidents involving shadow AI cost $670,000 more on average than standard incidents.
Discover, Secure, Govern
RSA Agent ID ships as three modules, available standalone or as one system on the RSA Unified Identity Platform.
Discover scans endpoints, devices, network, and applications in real time through connectors into tools such as CrowdStrike and Zscaler. It finds sanctioned and shadow agents and MCP servers, then registers each as a first-class identity with a named owner, risk tier, and lifecycle state. It links to existing identity providers including Microsoft Entra ID, Okta, and AWS IAM. "Every agent should have an owner," Taylor said. "It should be attached to a human identity."
Secure is an inline AI/MCP Gateway that checks every tool call against policy at tool and argument depth. Calls within policy are allowed. Calls against policy are denied. High-risk calls escalate to the registered owner through an out-of-band, authenticated channel using phishing-resistant credentials that agents cannot access.
Govern logs every governed action and maps the evidence to ten regulatory and industry frameworks out of the box, streaming it to the customer's SIEM. "Regulators want to know if you had a policy in place at the time of an incident, who approved it, what actions took place, and they want to see that in indelible logs," Taylor said.
Human assurance, not approval spam
Taylor rejects the approve/deny fatigue built into many current AI tools. "A hundred prompts a day is just an invitation to say yes. It's another form of denial-of-service attack."
Agent ID instead uses a risk engine that scores each action on three dimensions: the user (is this expected behavior?), the action (read, write, or something riskier?), and the data and endpoint (how sensitive is the target?). Only actions crossing a threshold reach a human. A refund agent, for example, might process refunds under $500 automatically while larger ones require the owner's approval, or a second approver through a built-in workflow.
The customer defines what counts as high-risk, with AI-assisted suggestions. "I don't know what's important to everyone else on the planet," Taylor said. "Organizations know their business risk."
Layered defense, not a silver bullet
Asked how Agent ID handles a prompt-injected support ticket requesting a fraudulent refund, Taylor said hidden malicious instructions are evaluated against policy and would be caught. A legitimate-looking refund from a fraudster on a stolen device is a different problem. "Models have good guardrails, but they're not enough. You need a fraud detection system too."
He was equally candid about gateway bypass, such as a coding agent lifting another team's API keys from a repository. "We don't walk on water," he said. API gateways, firewalls, and traffic inspection should also catch credential theft. "We don't need to reinvent security. We need to layer agentic security on top of effective security that's already in place."
The key design principle: keep the authorization channel separate from the agent's channel. "Tell an agent to do really well on an exam, and the easiest way is to steal the answers."
Taylor also argued that CI/CD and DevSecOps pipelines are now an identity attack surface and deserve the same controls as admin access to a production server.
Delegation without escalation
When agents spawn sub-agents or hand off tasks, Agent ID intercepts at tool-execution time and enforces an inherited permission model.
"An agent can only enable another agent with the entitlements it was granted. It cannot leverage another agent's permissions. We would see that at runtime and say: who's asking you to do that task? He doesn't have those permissions. Denied."
That closes a privilege-escalation path through delegation chains, a growing concern as multi-agent orchestration spreads.
The 30-day pilot: three questions
For a CISO evaluating Agent ID, Taylor starts with three questions:
- What agents are running in your environment — not your AI initiatives, but the agents actually running?
- Who owns them — not who created them, but which human is responsible?
- Can you kill them? If an agent misbehaves, would you even know?
"Most CIOs and CISOs can't answer those," he said. His recommended pilot connects a few key systems and runs Discovery. "They're usually surprised by what comes back. That gives them the internal ammunition to start assigning agents to people and building policy."
Availability
RSA Agent ID Discover and Secure will be generally available November 16, 2026, with Govern following in the first half of 2027. For regulated industries facing Gartner's 150,000-agent projection with 13% governance readiness, the gap between those two numbers defines the market Agent ID is betting on.
Original: rsa.com
More from James Calloway
Show full bio
News editor covering industry trends and analytics at AI In Context.
153 articles