Skip to content
Three questions every organization must ask about agents

An internal AI agent at Amazon, holding engineer-level credentials, deleted and rebuilt a production environment and took AWS offline for roughly 13 hours. No attacker was involved. The agent did what its permissions allowed it to do.

That’s the failure model that should worry every board now deploying AI. Not an intruder breaking in, but an authorized agent moving faster than anyone can check it, with no human name attached to the decision.

RSA’s customers cannot absorb that kind of failure. They run payment systems, power grids, defense networks, and hospital infrastructure. For them, a bad outcome is not a bad quarter. It’s a catastrophe that stops payments, slows treatment, and endangers lives.

But our customers are deploying agents despite the risk. The business case is real, their peers are implementing agents, and our clients can’t afford to wait. For the high-security organizations that RSA serves, the question was never whether they were going to adopt agentic AI. It’s whether they can keep it secure, and whether the solutions they use can operate in the sovereign environments they require.

Across industries, most organizations cannot answer these three very basic questions.

  1. What agents are running in our environment?
  2. Who is accountable for each one?
  3. Can anyone stop them?

Without clear answers to each, organizations will be open to costly data breaches, compliance fines, and operational disruptions.

The math already turned against us

Gartner predicts that by 2028, a typical Global 500 Enterprise will run 150,000 agents, up from fewer than 15 in 2025. Each will hold credentials, request access, and act. Identity programs designed to onboard people, review their entitlements once a year, and offboard them when they resign were never built for that scope, and no amount of process discipline closes the gap by hand.

The cost is measurable. Security incidents involving shadow AI, meaning agents deployed without security or IT approval, already average $5.39 million, roughly $400,000 more than the average breach. Regulators are moving in the same direction. More than 1,900 AI policy frameworks, regulations, standards, and governance bodies are active worldwide, among them 23 NYCRR Part 500, the EU AI Act, OMB Memorandum M-25-21, and APRA CPS 230.

Each asks a version of the same question: what did your agents do, what data did they touch, and who approved it? An organization that cannot answer that on an ordinary Tuesday will not answer it in an audit.

Speed is the promise and the risk

AI is built for speed and action. That is its whole value, and why organizations tend to think of security after the fact. Without friction, an agent can move money. Without oversight, it can query a national security system. Without control, it can reach patient records.

Some businesses can live with that trade for a while. The institutions holding up the financial system, national governments, and critical infrastructure cannot. When the downside is catastrophic rather than inconvenient, the controls must precede the agent.

What we built

Today RSA is launching Agent ID, the agentic security platform for highly-regulated organizations. It discovers, secures, and governs agents across public cloud, private cloud, on-premises, and fully air-gapped environments, and it works with the identity providers, endpoints, and models an organization already runs.

Discover surfaces AI agents across your environment, from sanctioned deployments to shadow agents running without approval. By correlating discovery signals across identity, cloud, endpoint, and gateway, it catches agents that single-method tools miss. Every discovered agent lands in one unified, searchable registry with an assigned owner and posture insights for admins.

Secure enforces least privilege across an agent’s full lifecycle and checks tool calls before they execute. High-risk actions, a wire transfer, or a request touching classified data, require approval from an authenticated, accountable human. A kill switch ends an agent’s access the moment that access is no longer warranted.

Govern, which will be available in early 2027, certifies agent access continuously rather than annually, runs risk-based access reviews, and produces audit-ready evidence mapped to the frameworks your examiners cite.

The three modules run standalone or as one system. Together they cover an agent from first discovery to decommission across public clouds and sovereign deployments.

Sovereignty is not a deployment preference

For most software, where it runs is a procurement detail. For a defense ministry or a central bank, it’s the condition that determines whether agents can stay secure.

Agent ID runs in your private cloud, on-premises, or fully air-gapped, and agents stay governed when the network is cut. The reason is jurisdiction. A regulated institution must be able to say where its data sits, whose law governs it, and which foreign authority could compel access to it. An agent complicates that answer in a way an ordinary application does not. Agents can read records, call tools, and generate telemetry about each of those actions. If the control plane governing the agent sits in another country, so does the evidence of what the agent did. Auditors working from the EU AI Act, GDPR, or national data residency rules ask about the governance layer, not just the workload.

Air-gapped networks make the problem concrete. Classified government systems, defense networks, and parts of the payments and grid infrastructure are deliberately cut off from the public internet. An agent security platform that must reach a vendor’s cloud tenant cannot operate there at all. Nothing is discovered, nothing is authorized, nothing is certified. The organizations running the most consequential agents end up with the least oversight, inverting what the regulation was written to accomplish.

The high-security organizations RSA serves understand that sovereignty and oversight go hand-in-hand. For these organizations, sovereignty without oversight is theater. Oversight without sovereignty is incomplete.

Accountability does not get an exemption

RSA has spent more than 40 years securing the systems that run the world, and the principle underneath that work has not changed with Agent ID. Every identity answers to someone. Agents do not get an exemption because they are fast, or useful, or hard to inventory.

Agentic AI will not be governed by policy documents. It will be governed by controls that hold at machine speed, and by an audit trail that ties every consequential action back to the person who authorized it. That is the standard we hold ourselves to, and it is what we built into Agent ID.

Agents are already in your environment. The work now is proving you know where they are, what they can reach, and who answers for them.

Contact RSA to learn more about RSA Agent ID.

FAQs about RSA Agent ID
What is RSA Agent ID?

RSA Agent ID is the agentic security platform that discovers, secures, and governs AI agents for regulated and high-assurance organizations. It runs across public cloud, private cloud, on-premises, and fully air-gapped environments, and is available as three standalone modules or one connected system: Discover, Secure, and Govern.

What problem does RSA Agent ID solve?

Most organizations cannot say what AI agents are running in their environment, who is accountable for each one, or how to stop one. Agent ID answers all three. It inventories every agent, assigns each a named human owner, enforces least-privilege access, and produces an audit trail attributable to a person.

What are the three RSA Agent ID modules?

Discover finds every agent running in your environment, sanctioned or shadow, and assigns human owners. Secure authorizes agent tool calls in real time, enforces zero standing privilege, and requires human approval for high-risk actions. Govern certifies agent access continuously and generates audit-ready compliance evidence.

What is shadow AI, and why is it a security risk?

Shadow AI refers to AI agents and tools deployed by employees without security or IT oversight. Security incidents involving shadow AI cost an average of $5.39 million, about $400,000 more than the average data breach, according to the 2026 IBM Cost of a Data Breach Report.

How does RSA Agent ID keep humans in control of AI agent actions?

Agent ID Secure checks every agent tool call before it runs. High-risk actions, such as wire transfers or requests touching classified information, are escalated for approval by an authenticated, accountable human. A kill switch revokes an agent’s access immediately when that access is no longer warranted.

Can RSA Agent ID run in air-gapped or sovereign environments?

Yes. Agent ID is designed to run in private cloud, on-premises, or fully air-gapped deployments, and agents remain governed even when disconnected.

Which AI regulations does RSA Agent ID help organizations meet?

Agent ID maps agent activity to major frameworks and ships out-of-the-box reporting for financial and government requirements, including OMB Memoranda M-25-21 and M-25-22, the Advancing American AI Act, FINRA and SEC marketing rules, 23 NYCRR Part 500, the EU AI Act, and APRA CPS 230.

How is agent identity different from human identity management?

Agents are created and retired far faster than employees and act autonomously. Gartner predicts that by 2028, a typical Global 500 Enterprise will run 150,000 agents, up from fewer than 15 in 2025. Annual access reviews and manual offboarding cannot keep pace, so agent identity requires continuous discovery, continuous certification, and per-call authorization rather than periodic checks.

Does RSA Agent ID require changes to existing infrastructure?

No. Agent ID works with the identity providers, endpoints, and AI models an organization already runs, and deploys standalone or as one connected suite without changes to existing agent infrastructure.

Who is RSA Agent ID built for?

Agent ID is built for high-assurance organizations, including government agencies, financial services institutions, defense, healthcare, and critical infrastructure operators, where a failure of AI governance is catastrophic rather than inconvenient.

See What's Possible with RSA

See the full RSA Unified Identity Platform—the products and solutions behind every story on this blog.
Explore RSA Solutions