RSA Launches Agent ID To Secure And Govern Enterprise AI Agents

By Amit Chowdhry ● Yesterday at 2:12 PM

RSA announced RSA Agent ID, a new agentic identity security platform designed to help highly regulated organizations discover, secure, and govern AI agents across their lifecycle.

The platform was unveiled at World Summit AI in Amsterdam and is aimed at organizations including financial institutions, government agencies, utilities, and other high-assurance environments where security, data sovereignty, and regulatory oversight are major considerations for AI deployment.

RSA Agent ID is designed to address both officially sanctioned AI agents and so-called shadow agents that may be created or deployed by employees without centralized oversight.

The company’s approach treats AI agents as identities that can hold credentials, receive permissions, access sensitive systems, and take actions on behalf of an organization.

RSA said many enterprises currently lack a complete inventory of the AI agents operating within their environments or clear visibility into who owns those agents and what permissions they have.

The company cited Gartner estimates that a typical Global Fortune 500 company could operate approximately 150,000 AI agents by 2028, compared with fewer than 15 in 2025.

RSA Agent ID is organized around three primary capabilities: Discover, Secure, and Govern.

RSA Agent ID Discover identifies agents and Model Context Protocol servers across identity, cloud, endpoint, and gateway systems.

The platform can identify both known and unknown agents and register each one as an identity with a designated owner, risk classification, and lifecycle status.

RSA Agent ID Secure applies organizational policies each time an AI agent attempts to access a tool or system through an AI or MCP gateway.

For higher-risk actions, organizations can require approval from a named and authenticated human using phishing-resistant credentials.

The platform can also revoke access when an agent is decommissioned.

RSA Agent ID Govern is designed to apply identity governance processes to AI agents in a similar way organizations already manage employee identities.

Capabilities include continuous certification, risk-based access reviews, and lifecycle automation.

RSA is also emphasizing deployment flexibility and sovereign control as part of the platform.

Organizations can operate the AI/MCP Gateway in the cloud, in hybrid environments, or on-premises.

When customers host the gateway themselves, policy decisions can remain inside their own infrastructure rather than being routed through a third-party cloud environment.

Organizations can also choose whether tenant data remains within U.S. or European regions.

RSA plans to introduce a fully air-gapped, self-managed version of the platform in 2027.

The platform is also designed to operate independently of a specific identity provider, allowing organizations to continue using their existing identity infrastructure.

RSA said governed agent actions can be recorded and mapped to 10 industry frameworks, with evidence generated where the gateway operates and streamed into security information and event management systems.

RSA Agent ID Discover and Secure are scheduled to become generally available on November 16, 2026.

RSA Agent ID Govern is expected to become generally available during the first half of 2027.

The company said the broader goal is to bring AI agents under the same identity, access, governance, and accountability frameworks that enterprises already use to secure human users.

KEY QUOTES:

“Three forces are converging on our customers at once: AI that moves faster than the teams meant to watch it, a hard requirement to keep control of data and decisions at home, and boards that now own security outcomes directly. For government, financial services, and critical infrastructure, getting agentic security wrong is not inconvenient, it is catastrophic. Hope won’t control agents, but RSA Agent ID will. RSA Agent ID brings agents under the same identity discipline RSA has applied to human access for decades, and it maintains control where it belongs: with the customer, in the customer’s own environment.”

Greg Nelson, CEO of RSA

“Agents skipped every process built for people: no registration, no owner, no accountability. To secure agents, organizations must secure their identities. RSA Agent ID finds agents across your environment, known and unknown, gives each a first-class identity with a named owner, proves the authority behind every consequential action, and hands examiners evidence they already know how to read. It is the same exacting identity standard that secures the most demanding organizations in the world, applied to a new kind of actor.”

Jim Taylor, President and Chief Product and Strategy Officer at RSA

“AI holds enormous potential to improve productivity and create value in regulated institutions, but it has to be deployed responsibly. Organizations cannot simply outsource agent governance and authorization to a cloud provider; they need to retain control over what their agents are allowed to do. Those decisions should be made within the organization’s own environment, with a named person accountable for actions that carry real consequences.”

Roy Singh, RSA AI Advisor and CEO of Korza

Exit mobile version