RSA has introduced the RSA Agent ID, a cutting-edge identity security platform aimed at enhancing the security of AI agents within regulated sectors. This new solution is designed to assist financial institutions, government bodies, and critical infrastructure providers in managing AI agent access and validating authorization for sensitive tasks.
Enhancing Security for AI Agents
The RSA Agent ID platform emerges in response to the challenges faced by organizations in managing AI agents, which often operate without the stringent controls applied to human users. These agents, capable of accessing internal systems and executing automated functions, require robust identity management like any other credentialed entity.
With AI adoption on the rise, RSA highlights a significant gap in current security protocols. According to Gartner, by 2028, major enterprises could deploy up to 150,000 AI agents, a stark increase from just a few in 2025. This growth underscores the urgent need for comprehensive governance frameworks.
Tackling Shadow AI and Security Risks
RSA’s platform aims to mitigate risks associated with ‘shadow AI’—unauthorized AI tools that operate outside approved security processes. Research shows that a mere 13% of organizations feel equipped with proper governance for AI agents, posing potential risks of data breaches and operational disruptions.
The financial implications are notable, with security incidents involving shadow AI costing approximately $5.39 million on average, surpassing conventional data breach costs by $400,000. Given these stakes, robust controls are critical, especially for sectors handling sensitive data and operations.
Modular Approach to AI Agent Governance
The RSA Agent ID is available as three distinct modules: Discover, Secure, and Govern. Each module addresses different aspects of AI agent management, from identification and risk assessment to policy enforcement and lifecycle controls.
RSA Agent ID Discover is tasked with identifying AI agents and MCP servers, assigning human ownership, and determining risk levels. The Secure module enforces policy checks and human approval for high-risk actions, while Govern focuses on lifecycle management and compliance support.
The platform ensures that organizations maintain sovereign control over policy enforcement and evidence generation, crucial for compliance with frameworks like NIST AI RMF 1.0 and ISO/IEC 42001.
Future Availability and Strategic Impact
RSA Agent ID Discover and Secure are slated for release on November 16, 2026, with the Govern module following in the first half of 2027. This rollout aims to provide organizations with the tools needed to secure AI deployments effectively.
As AI continues to integrate into enterprise operations, RSA’s platform offers a strategic solution to manage the complexities and risks associated with AI agents, reinforcing organizational security and compliance.
