AI agents are entering production faster than security teams can track them. They hold credentials, carry entitlements, and act on systems of record. Most enterprises cannot identify which agents are running or who owns them.
Gartner predicts that by 2028, a typical Fortune 500 company will run around 150,000 AI agents. Yet only a small percentage of organizations believe they have proper governance in place.
RSA announced RSA Agent ID, a platform to discover, secure, and govern AI agents. It works in regulated industries like finance, government, and healthcare. The platform has three modules: Discover, Secure, and Govern.
Discover scans endpoints, devices, networks, and applications in real time. It finds agents and registers each as an identity linked to an owner, risk tier, and lifecycle. Every agent should have a human owner.
Secure checks every tool call against policies at multiple levels. Calls that violate policy are denied or escalated. Actions are logged and streamed to regulatory systems.
The platform scores each action based on expected behavior, risk, and data sensitivity. Only high-risk actions require human approval. Organizations can set their own high-risk criteria with AI suggestions.
RSA emphasizes layered security. Agents cannot bypass controls like API gateways or traffic inspection. The system also enforces permission inheritance to prevent privilege escalation.
Why it matters
This platform helps organizations manage the growing number of AI agents, reducing security risks and regulatory compliance issues.
What to do
Organizations should start discovering their AI agents and link them to owners. They should also implement layered security controls for agent actions.