![]()
At The AI Conference in San Francisco, RSA, the identity standard for government agencies, finance, and high-assurance organizations, today announced RSA Agent ID, the agentic security identity platform for highly-regulated industries. RSA Agent ID discovers, secures, and governs AI agents across their lifecycle, letting regulated organizations find and register agents, prove the authority behind every consequential action, and run it where they choose.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260929156008/en/
Three forces are reshaping how organizations operate, and they are arriving at once. AI is transforming work and pushing agents into production faster than security teams can track them, while making attacks cheaper, faster, and harder to detect. Companies and countries are reclaiming control over their data and the decisions made on their behalf. And security has moved from an IT responsibility to a board-level obligation. Each of these forces ultimately comes down to identity: identity determines what an agent can do, where control begins and ends, and where attackers strike.
Agents are identities. They hold credentials, carry entitlements, and act on systems of record, yet most organizations cannot say what agents are operating, who owns them, or whether anyone can stop them. By 2028, Gartner expects a typical Global Fortune 500 enterprise to run roughly 150,000 AI agents, up from fewer than 15 in 2025, while only 13% of organizations believe they have the right agent governance in place. This rapidly growing risk is driving up costs: IBM found that incidents involving “shadow AI” cost $670,000 more on average than standard incidents. Gartner named agentic AI oversight its top cybersecurity trend for 2026.
The market's answer has largely been to ship first and patch later: park the data nearby, then hand the decision back to the vendor's own cloud. That trade may suit convenience-first buyers. It does not suit the institutions that hold up the financial system, governments, and critical infrastructure the world relies on. A bank's agents reach core systems and customer data. Government agents may call restricted or classified information. For these organizations, examiners and regulators are already asking who owns each agent and how its access is reviewed: U.S. federal agencies introduced 59 AI-related regulations in 2024, more than double the prior year. Most agentic security was not built for these conditions. RSA Agent ID is.
RSA Agent ID brings agentic identity security to the RSA Unified Identity Platform, the same platform that already secures workforce identities. Available as standalone modules or one interconnected system, it secures AI agents across their lifecycle:
- RSA Agent ID Discover finds agents and MCP servers, known and unknown, sanctioned and shadow, across your identity, cloud, endpoint, and gateway sources, and registers each as a first-class identity with a named owner, risk tier, and lifecycle state, linked to the identity provider you already use.
- RSA Agent ID Secure enforces your policy on each call at an AI/MCP Gateway that runs either RSA-hosted or in your own environment, chosen per gateway. The solution provides approval with real assurance, demanding a named, authenticated operator approve high-risk actions out of band with a phishing-resistant credential. Access is revoked when an agent is decommissioned.
- RSA Agent ID Govern certifies and reviews agents the same way organizations govern people, with continuous certification, risk-based access reviews, and lifecycle automation for agents.
Sovereign control
RSA Agent ID delivers sovereign control to high-assurance organizations. The AI/MCP Gateway runs in the cloud, hybrid, or on-premises, chosen per gateway, and when you host the Gateway, the policy decision on each call is made in your environment. Tenant data stays in the region you select, US or EU, and enforcement evidence is generated where the Gateway runs and streams to your SIEM. Organizations govern agents independently of any single identity ecosystem, keeping the identity provider they already run. A full air-gapped, self-managed version is planned for 2027.
This sovereign control now extends across human and agentic identities. In March, RSA announced RSA ID Plus Sovereign Deployment, the next evolution in RSA ID Plus, the market's most secure identity and access management (IAM) platform. RSA ID Plus Sovereign Deployment introduced a "deploy anywhere" capability that lets organizations modernize their identity infrastructure while maintaining the highest standards in security, availability, and regulatory compliance across private cloud, multi-cloud, on-premises, and air-gapped configurations.
RSA Principal Product Manager Nandini V will discuss the sovereign controls that regulated industries need to secure agents at The AI Conference on September 30 at 1:45 PM in Theater 1. In a new whitepaper, Architecting agentic identity for high-assurance organizations, RSA details how high-assurance organizations must architect agentic identity to preserve sensitive information, maintain operations, and satisfy regulatory requirements.
Securing the agentic era
“Three forces are converging on our customers at once: AI that moves faster than the teams meant to watch it, a hard requirement to keep control of data and decisions at home, and boards that now own security outcomes directly," said Greg Nelson, CEO of RSA. “For government, financial services, and critical infrastructure, getting agentic security wrong is not inconvenient, it is catastrophic. Hope won’t control agents, but RSA Agent ID will. RSA Agent ID brings agents under the same identity discipline RSA has applied to human access for decades, and it maintains control where it belongs: with the customer, in the customer's own environment.”
“Agents skipped every process built for people: no registration, no owner, no accountability," said Jim Taylor, President and Chief Product and Strategy Officer at RSA. “To secure agents, organizations must secure their identities. RSA Agent ID finds agents across your environment, known and unknown, gives each a first-class identity with a named owner, proves the authority behind every consequential action, and hands examiners evidence they already know how to read. It is the same exacting identity standard that secures the most demanding organizations in the world, applied to a new kind of actor.”
“AI holds enormous potential to improve productivity and create value in regulated institutions, but it has to be deployed responsibly,” said Roy Singh, RSA AI Advisor and CEO of Korza, an AI engineering firm that partnered with RSA on the development of Agent ID. “Organizations cannot simply outsource agent governance and authorization to a cloud provider; they need to retain control over what their agents are allowed to do. Those decisions should be made within the organization's own environment, with a named person accountable for actions that carry real consequences. As governments and regulators assert greater control over data, infrastructure and decision-making, financial institutions, public agencies and other regulated organizations should demand the same level of control over their AI.”
BENEFITS
RSA Agent ID enables regulated organizations to find, control, and govern the AI agents operating in their environment:
- Choose where Agent ID runs: the AI/MCP Gateway runs cloud, hybrid, or on-premises, chosen per gateway, and the decision runs where the Gateway runs.
- Provable human authority: no high-risk action is taken without a named, authenticated human, and every governed action traces back to the person who authorized it.
- Regulatory evidence: every governed action is recorded and mapped to ten industry frameworks, generated where the Gateway runs and streamed to your SIEM.
- Identity provider independence: govern agents independently of any single identity ecosystem, on the identity provider you already run.
USE CASES
- Discover which agents are running across your identity, cloud, endpoint, and gateway sources, known and unknown, before it becomes a governance problem.
- Replace shadow AI with one registry of agents, each with a named owner.
- Bound what agents can do so permissions never expand beyond what was explicitly granted.
- Establish policy on each call at tool and argument depth, with a per-call, attributable record for every governed action.
AVAILABILITY
RSA Agent ID Discover and Secure will be generally available November 16, 2026. RSA Agent ID Govern will be generally available in the first half of 2027.
RESOURCES
- RSA Agent ID product page
- Download the white paper, Architecting identity for high-assurance organizations
- RSA Agent ID solution brief
- Launch blog post
ABOUT RSA
RSA is the identity standard for government agencies, finance, and high-assurance organizations. RSA provides the identity intelligence, authentication, access, governance, and lifecycle capabilities needed to prevent threats, secure access, maintain operations, and surpass compliance. More than 9,000 security-first organizations trust RSA to manage more than 60 million identities across on-premises, hybrid, and multi-cloud environments. For additional information, visit our website to contact sales, find a partner, or learn more about RSA.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260929156008/en/
Media gallery

