RSA Agent ID Helps Close the Agentic Identity Gap for Highly Regulated Industries

RSA Launches Agent ID to Strengthen AI Security in Highly Regulated Industries

RSA has introduced RSA Agent ID, a new agentic identity security platform designed to help highly regulated organizations discover, secure, and govern artificial intelligence agents throughout their lifecycle. The announcement was made at World Summit AI in the Netherlands as organizations across government, financial services, and critical infrastructure face growing challenges associated with the rapid adoption of AI agents.

The new platform is designed to help organizations identify AI agents operating across their environments, establish clear ownership and accountability, control what those agents are authorized to do, and maintain auditable records of consequential actions.

As AI moves from experimentation into production environments, autonomous and semi-autonomous agents are increasingly being given access to business applications, sensitive information, and critical systems. RSA argues that these agents should be treated as identities because they possess credentials, receive permissions, and can take actions on behalf of people and organizations.

“For government, financial services, and critical infrastructure, getting agentic security wrong is not inconvenient, it is catastrophic. Hope won’t control agents, but RSA Agent ID will,” said Greg Nelson, CEO of RSA.

AI Agents Create a New Identity Challenge

The rapid expansion of AI is creating a new security challenge for organizations that were traditionally designed to manage human identities. AI agents can now perform tasks, access applications, interact with data, and make decisions with limited human intervention.

However, many organizations lack a complete picture of which agents are operating in their environments, who owns them, what permissions they have, and how those permissions can be revoked.

RSA said this challenge is being intensified by three major trends. AI is accelerating the deployment of autonomous agents while making cyberattacks faster and potentially more difficult to detect. At the same time, organizations and governments are seeking greater control over their data and technology infrastructure. Security has also become a board-level concern, increasing pressure on organizations to demonstrate that their systems are properly governed.

RSA believes identity sits at the center of all three trends because identity determines what an agent can access, which actions it can perform, and who is ultimately responsible for those actions.

Research cited by RSA indicates that the number of AI agents deployed by large enterprises could increase dramatically in the coming years. Gartner expects a typical Global Fortune 500 enterprise to operate roughly 150,000 AI agents by 2028, compared with fewer than 15 in 2025. At the same time, only 13% of organizations reportedly believe they have adequate agent governance in place.

The financial consequences of weak governance can also be significant. IBM has found that incidents involving “shadow AI” cost an average of $670,000 more than standard security incidents.

RSA

RSA Agent ID Brings AI Agents Under Identity Governance

RSA Agent ID is designed to address these challenges by applying identity security principles to AI agents. The platform is available through standalone modules or as an interconnected system covering agent discovery, security, and governance.

RSA Agent ID Discover is designed to identify AI agents and Model Context Protocol (MCP) servers across identity, cloud, endpoint, and gateway environments. The system can identify both sanctioned and unauthorized or “shadow” agents.

Once discovered, agents can be registered as first-class identities with a named owner, risk classification, and defined lifecycle state. The system also connects agents to the identity provider an organization already uses, helping security teams incorporate AI agents into existing identity management processes.

RSA Agent ID Secure focuses on controlling the actions agents are allowed to perform. It uses an AI/MCP Gateway to enforce policies on individual calls. The gateway can operate through RSA-hosted infrastructure or within an organization’s own environment, depending on the organization’s requirements.

For high-risk actions, the platform can require approval from a named and authenticated human operator using a phishing-resistant credential. This creates a direct link between an AI agent’s consequential action and the human authorized to approve it.

RSA Agent ID Govern extends these capabilities by applying continuous certification, risk-based access reviews, and lifecycle automation to AI agents. The goal is to ensure that agents are reviewed and governed in a manner similar to human users.

Sovereign Control for Regulated Organizations

A major focus of RSA Agent ID is giving highly regulated organizations greater control over where their AI security infrastructure operates and where policy decisions are made.

The AI/MCP Gateway can operate in cloud, hybrid, or on-premises environments, with organizations able to choose the deployment model for each gateway. When customers host the gateway themselves, policy decisions can be made within their own environment.

RSA also said tenant data can remain in a customer-selected U.S. or European region, while enforcement evidence is generated where the gateway operates and can be streamed to an organization’s security information and event management system.

This approach is intended to address the needs of organizations subject to strict data sovereignty, regulatory, and operational requirements.

RSA said a fully air-gapped, self-managed version of the platform is planned for 2027.

The company’s focus on sovereign control also builds on its existing identity security portfolio. Earlier this year, RSA introduced RSA ID Plus Sovereign Deployment, designed to allow organizations to deploy identity infrastructure across private cloud, multi-cloud, on-premises, and air-gapped environments while maintaining control over security and compliance requirements.

Keeping Humans Accountable for High-Risk AI Actions

RSA executives emphasized that AI agents should not operate without clear accountability.

“Agents skipped every process built for people: no registration, no owner, no accountability,” said Jim Taylor, President and Chief Product and Strategy Officer at RSA. “To secure agents, organizations must secure their

Source Link: https://www.businesswire.com/

Share your love