RSA Launches Agent ID as Shadow AI Agents and Salesforce Shutdown Expose Identity Gaps
RSA announced Agent ID, an agentic identity security platform, at The AI Conference in San Francisco. It combines discovery, an inline AI/MCP gateway and governance logging as enterprises face thousands of unmanaged agents and costly shadow AI incidents.
Gartner expects a typical Global Fortune 500 enterprise to run roughly 150,000 AI agents by 2028, up from fewer than 15 in 2025, while only 13% of organizations believe they have the right agent governance in place, the article said. According to IBM, incidents involving shadow AI cost $670,000 more on average than standard incidents.
Jim Taylor, president and chief product and strategy officer at RSA, said agents break the identity model because they are not service accounts and are not static. “You give an agent a task, and if you badly word that task, it will do whatever it deems necessary to perform it. Agents don’t get tired at two o’clock in the morning. They just go.” He added that agents accumulate permissions, data and access over time, and nobody follows up. “Employees create an agent to hit a deadline, but once it’s off in the wild, that’s it. We don’t check when its permissions change. We don’t delete or disable agents.”
The scale can surprise even regulated firms. A medium-sized global bank told RSA it had no agents because policy prohibited them. “Agents don’t tend to respect policy,” Taylor said. An audit found more than 4,000 agents running around in the bank’s enterprise, according to the article.
Taylor’s failure scenario involved no attacker. A customer success employee at an unnamed company asked an agent to “go to Salesforce and get all the data” to build customer health charts. The agent began downloading the entire Salesforce database. Salesforce’s defenses read the traffic as an attack, shut down the instance, and warned the company that it appeared to be under a denial-of-service attack. “One operator on the customer service desk took the whole company’s Salesforce instance down by essentially having an agent perform a denial-of-service attack. He didn’t do anything wrong.”
RSA Agent ID ships as three modules, available standalone or as one system on the RSA Unified Identity Platform. Discover scans endpoints through connectors into tools such as CrowdStrike and Zscaler, plus devices, network and applications in real time. It finds agents and MCP servers, sanctioned and shadow, and registers each as a first-class identity with a named owner, risk tier and lifecycle state, linked to existing identity providers such as Microsoft Entra ID, Okta and AWS IAM. “Every agent should have an owner,” Taylor said. “It should be attached to a human identity.”
Secure is an inline AI/MCP Gateway that checks every tool call against policy at tool and argument depth. Calls within policy are allowed, calls against policy are denied, and high-risk calls are escalated to the registered owner. Approvals go through an out-of-band, authenticated channel with phishing-resistant credentials that agents cannot access. Govern logs every governed action and maps the evidence to ten regulatory and industry frameworks out of the box, streaming it to the customer’s SIEM. “Regulators want to know if you had a policy in place at the time of an incident, who approved it, what actions took place, and they want to see that in indelible logs,” Taylor said.
Taylor rejects the approve-or-deny fatigue of many AI tools. “A hundred prompts a day is just an invitation to say yes. It’s another form of denial-of-service attack.” Instead, a risk engine scores each action on the user, whether the behavior is expected; the action, such as read, write or something riskier; and the data and endpoint, including how sensitive the target is. Only actions that cross a threshold go to a human. A refund agent might process refunds under $500 automatically, while larger ones need the owner’s approval, or a second approver through a built-in workflow. The customer defines what counts as high-risk, with AI-assisted suggestions. “I don’t know what’s important to everyone else on the planet,” Taylor said. “Organizations know their business risk.”
Asked about a prompt-injected support ticket requesting a fraudulent refund, Taylor said hidden malicious instructions are evaluated against policy and would be caught. A legitimate-looking refund from a fraudster on a stolen device is a different problem. “Models have good guardrails, but they’re not enough. You need a fraud detection system too.” He was just as candid about gateway bypass, such as coding agents lifting another team’s API keys from a repository.