Get the whitepaper

Every agent is an identity. Most are not governed.

Agents are arriving from every direction at once. Developers install desktop and IDE assistants. Business teams build copilots on cloud platforms. Vendors embed agents in software you already run. Most hold credentials and reach systems of record. Few are inventoried. Fewer have a named owner. Almost none produce the evidence an examiner would accept.

Some organizations can tolerate AI errors or fix issues in production. Regulated organizations cannot. When an agent releases a payment, reads a record it did not need or changes an entitlement without authority, that is a reportable event. The organization answers for it, not the model vendor.

Two guides. One standard.

The paper has two editions, written for the two groups who have to get this right together.

The leadership guide is for executives and boards. It covers where agents create value, the five challenges to balance against that value, the autonomy ladder, the eight elements that separate organizations that deploy agents safely from those that don’t, and eight questions every board should be able to answer.

The architecture is for CISOs, identity leaders, and security architects. It sets out a six-part operating model, a reference architecture that puts a gateway between every agent and every tool, and the evidence needed to reconstruct a single agent action months after it happened.

What you will learn

  • Why deploying agents is a governance decision, not a technology purchase, and how existing model risk and identity programs give regulated industries a head start.
  • How to expand agent autonomy in stages, with the controls and evidence required before each step up.
  • Why service-account controls fall short for agents that chain dozens of tool calls in seconds and fail plausibly rather than loudly.
  • Six practices that each produce evidence: an agent registry with named owners, traceability, auditability, sovereign data handling, restrictive provisioning and drift monitoring.
  • How to keep the gateway, policy and audit log inside your own perimeter when sovereignty rules demand it.
  • A 30-, 90- and 180-day plan to inventory agents, put a gate in the path and make governance routine.

Built around the question examiners ask first

Every regulated sector asks a version of the same question after an incident. The paper maps the stakes and obligations for each.

  • Finanzdienstleistungen: Which identity released this payment, and who authorized it?
  • Gesundheits-wesen: Which records did the agent access, and was that access necessary for the task?
  • Energy and utilities: Could this agent reach an operational system, and who could stop it?
  • Regierung: Where did the data go, and did it leave the jurisdiction?

Each is an identity question. Organizations that answer from records, rather than from interviews, keep their license, their reputation and their regulator’s confidence.

Autonomy is a ladder, not a switch

Benchmark scores do not prove dependable performance on your work, with your data. The paper sets out three rungs. At the first, the agent recommends and a person takes every action. At the second, the agent acts only where actions can be undone, and consequential calls are held for an authenticated human. At the third, the agent completes defined tasks end to end, within financial and scope limits it cannot exceed. Every promotion is a governed decision, made on evidence from your own environment.

Eight questions for the board

A board that can get a documented answer to each question is governing its use of AI. A board that gets a presentation is not. Three of the eight questions you’ll find in the paper are:

  • How many AI agents operate in our organization today, and who owns each one?
  • For consequential actions, which person approves, and how is that person verified?
  • If a regulator asked us to reconstruct one agent action from last quarter, could we, from records alone?

How RSA Agent ID puts the paper into practice

Both editions close by mapping each recommendation to RSA Agent ID. Discover builds the agent registry, assigns owners and measures blast radius. Secure places an MCP gateway, policy and authenticated human approval in the path of every call, RSA-managed or self-hosted inside your perimeter. The audit log records every decision, including refusals, as a control event mapped to the frameworks your examiner already uses.

Get the whitepaper

Agentic identity for regulated industries, including the leadership guide and the architecture. For executives, board members, CISOs, identity leaders, and risk and compliance teams.

Häufig gestellte Fragen

What is agentic identity?
Agentic identity treats every AI agent as a first-class identity with a named human owner, defined permissions and a record of every action it takes. It applies the accountability rules regulated organizations already use for people to software that plans and executes work.
How should a board govern AI agents?
By setting how much autonomy agents may have and requiring documented answers to basic questions: how many agents exist, who owns each one, who approves consequential actions, and whether any single action can be reconstructed from records alone.
What are the levels of AI agent autonomy?
RSA’s whitepaper describes three: recommend only, act reversibly, and act autonomously within limits. Agents move up one level at a time, and only when evidence from the previous level supports it.
Why aren’t service-account controls enough for AI agents?
Service accounts run fixed jobs and fail loudly. AI agents chain many tool calls across systems in seconds, change behavior when models or prompts change, act on behalf of people and can be redirected by content they read. Authorization has to be decided per action, not per account.
Who is accountable when an AI agent makes a mistake?
The organization that deployed it. In regulated sectors, unauthorized access or data exposure by an agent triggers the same reporting and examination obligations as if a person caused it.