RSA Launches Agent ID Platform to Secure Enterprise AI Agents
RSA introduces RSA Agent ID, a new platform designed to discover, secure, and govern AI agents, addressing the growing risks of 'shadow AI' in regulated industries.

RSA has announced the launch of RSA Agent ID, a new identity security platform aimed at helping regulated organizations discover, secure, and govern their artificial intelligence agents. This move directly addresses the escalating challenge of 'shadow AI' – unauthorized AI tools operating outside of established security and IT protocols – which poses significant risks to data loss, operational disruption, and regulatory non-compliance.
The platform is specifically targeted at sectors like financial services, government agencies, and critical infrastructure operators, where stringent controls are paramount. These organizations must meticulously manage what AI agents can access and maintain auditable proof of who authorized sensitive actions. RSA highlights that AI agents often receive credentials and access internal systems without the same rigorous oversight applied to human employees, creating a critical security gap.
RSA Agent ID is designed to treat AI agents as distinct identities, acknowledging that they possess credentials and entitlements. The company points to Gartner's projections that a typical Global Fortune 500 enterprise could manage approximately 150,000 AI agents by 2028, underscoring the rapid growth and the urgent need for robust governance. Current research indicates a significant gap in preparedness, with only 13% of organizations feeling confident in their AI agent governance.
The solution is modular, offered as three distinct components: Discover, Secure, and Govern. RSA Agent ID Discover focuses on identifying AI agents and Model Context Protocol (MCP) servers across various data sources, assigning ownership, and assessing risk. This provides organizations with much-needed visibility and asset tracking for their AI deployments.
RSA Agent ID Secure enforces policies and requires human approval for high-risk agent actions through an AI/MCP Gateway. This gateway can be deployed in various environments, including the customer's own infrastructure, ensuring that sensitive operations like initiating payments or accessing classified data are subject to human oversight, thereby reducing security risks.
Complementing these modules, RSA Agent ID Govern provides essential lifecycle controls. It supports continuous access reviews, entitlement management, and automated decommissioning of agents once their tasks are complete. This ensures that agents do not retain unnecessary access, bolstering compliance and reducing the attack surface.
RSA emphasizes sovereign control, allowing customers to dictate where the gateway operates and policy decisions are made, keeping enforcement and evidence generation within their controlled environments. The platform generates tamper-evident records of agent actions and access decisions, mapping them to ten compliance frameworks, including NIST AI RMF 1.0 and ISO/IEC 42001, to simplify audits and regulatory adherence.
RSA Agent ID Discover and Secure are slated for general availability on November 16, 2026, with RSA Agent ID Govern expected in the first half of 2027. This launch signifies a proactive step by RSA to address the burgeoning security challenges posed by the widespread adoption of AI agents in enterprise environments.