What happened
On Sept 29-30, 2026 RSA announced RSA Agent ID, an agentic identity security platform with three modules: Discover (finds AI agents and MCP servers across identity/cloud/endpoint/gateway sources, assigns owners/risk tiers), Secure (policy checks + mandatory named-human approval for high-risk agent actions via an AI/MCP Gateway running RSA-hosted or in the customer's cloud/on-prem), and Govern (access review, lifecycle/automated decommissioning, tamper-evident audit records mapped to NIST AI RMF 1.0, ISO 42001, DORA, NYDFS). Discover and Secure GA Nov 16, 2026; Govern H1 2027.
Why it matters
RSA is targeting heavily regulated verticals (financial services, government, critical infrastructure) where shadow AI agents (~150k per Fortune 500 by 2028 per Gartner) with long-lived credentials pose compliance and operational risk; Agent ID treats agents as governed identities with human-approval gates on irreversible actions and sovereign deployment, a differentiated angle vs cloud-only agent-security tools.
Applicability
CISOs in regulated industries should evaluate Agent ID for agent inventory + human-approval on high-risk agent actions; pilot against discovery needs now given GA in November.