RSA has introduced a platform named Agent ID aimed at helping regulated enterprises—such as financial services, government bodies, and critical infrastructure operators—bring oversight to AI agents and Model Context Protocol (MCP) servers. The tool is designed to discover, secure, and govern non-human identities that currently slip past traditional controls used for human users. The concern is mounting as AI agent deployments scale rapidly. Experts estimate that a typical Fortune 500 company could be managing roughly 150,000 of these agents by 2028, up from barely a handful today. Despite this, only a small fraction of organizations believe they have proper governance in place.
What Agent ID Does
The platform addresses a key issue: many AI agents are granted credentials and access to internal systems without going through the same registration, ownership assignments, or access-review processes applied to humans. To counter this, Agent ID treats these AI agents as identities, enabling enterprises to properly assign ownership, manage entitlements, and revoke access when needed. The platform breaks down into three modular components—Discover, Secure, and Govern—each tackling different parts of the lifecycle.
The Discover module helps locate both known and rogue AI agents and MCP servers across identity systems, endpoints, cloud environments, and gateway logs. It builds a registry that assigns a human owner, evaluates risk tier, and tracks the lifecycle stage of each agent. Meanwhile, Secure applies policy enforcement to agent actions via an AI/MCP gateway. This allows organizations to mandate human approvals for high-risk tasks—like large financial transactions or access to sensitive data—regardless of whether the gateway is hosted by RSA or within a customer’s own cloud or on-premises infrastructure.
The Govern module handles the continuous oversight side: conducting risk-based access reviews, automating entitlement controls, enforcing lifecycle transitions (such as decommissioning when tasks end), and supporting audits. For compliance-conscious organizations, Agent ID streams tamper-evident logs of agent action and access decisions, aligns with several frameworks including NIST AI RMF 1.0, ISO/IEC 42001, DORA, and NYDFS Part 500, and lets customers choose where the gateway and policy enforcement happen.
Availability and Impacts
The Discover and Secure modules will become generally available on November 16, 2026. The Govern module is set for release in the first half of 2027. For sectors that handle sensitive data and require strong controls—like banks or government agencies—the absence of such oversight can lead to data breaches, regulatory penalties, or operational disruptions. RSA estimates that security incidents tied to unmanaged AI agents now cost organizations on average about $5.39 million—significantly more than a typical data breach.
This launch comes amid growing concern over “shadow AI”—where agents and tools operate outside of approved security or compliance channels. Such scenarios heighten risk because they reduce visibility and increase potential for misuse. By introducing Agent ID, enterprises gain the tools to assign ownership, control access, review actions, and maintain evidence needed for audits.
Why this matters: As companies increasingly rely on autonomous agents to handle tasks and make decisions, treating these agents as identities rather than tools is essential for governance, security, and accountability. Agent ID could mark a turning point in how organizations manage non-human actors within their systems. What to watch: how well RSA integrates Agent ID’s modules into existing identity and access management systems, how performance and cost scale when tens or hundreds of thousands of agents are in the registry, and whether regulatory bodies begin specifying agent identity requirements in compliance rules.