RSA Launches Agent ID Platform to Secure AI Agents and MCP Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


RSA has announced RSA Agent ID, a new identity security platform that helps regulated organizations discover, secure, and govern AI agents.

The launch targets financial services, government agencies, critical infrastructure operators, and other organizations that need to control what AI agents can access and prove who authorized sensitive actions.

The platform addresses a growing problem in enterprise AI adoption: agents often receive credentials, access internal systems, and perform automated tasks without the same registration, ownership, and access-review controls used for employees and other human users.

RSA said AI agents should be treated as identities because they hold credentials and entitlements, while organizations may struggle to identify, assign ownership, and revoke access for every agent.

The challenge is expected to grow rapidly as more companies deploy agentic AI. RSA cited Gartner projections that a typical Global Fortune 500 enterprise could operate around 150,000 AI agents by 2028, compared with fewer than 15 in 2025.

The company also cited research indicating that only 13% of organizations believe they have the right governance for AI agents. Shadow AI refers to AI tools and agents operating outside approved security, compliance, and IT processes, creating a key organizational concern.

RSA Launches Agent ID

RSA’s solution brief states that shadow AI incidents can lead to data loss, operational disruption, regulatory penalties, and higher breach costs.

It cites an average cost of $5.39 million for security incidents involving shadow AI, about $400,000 more than the average data breach.

For banks, public-sector organizations, and critical infrastructure operators, an uncontrolled AI agent could access customer data, initiate payments, use privileged cloud credentials, or interact with sensitive government systems.

RSA said these environments require stronger controls than a cloud-only model can provide. RSA Agent ID is available as three standalone modules or as a unified platform:

Module Function Key Benefits
Discover Finds AI agents and MCP servers; assigns owners, risk tiers, and lifecycle status. Visibility, risk identification, and asset tracking
Secure Enforces policies and human approval for high-risk agent actions. Prevents unauthorized actions and reduces security risks
Govern Reviews access, automates lifecycle controls, and supports compliance audits. Better access control, governance, and compliance

RSA Agent ID Discover is designed to find AI agents and Model Context Protocol servers across identity, cloud, endpoint, and gateway data sources. It creates a registry for known and unknown agents, assigns each a human owner, and records a risk tier and lifecycle state.

RSA Agent ID Secure applies policy checks to agent calls through an AI/MCP Gateway. The gateway can operate in an RSA-hosted environment or within the customer’s own cloud, hybrid, or on-premises infrastructure.

Organizations can require a named and authenticated human operator to approve high-risk actions, including wire transfers, account access, classified-data access, or actions involving personally identifiable information.

RSA Agent ID Govern focuses on lifecycle controls. It supports continuous certification, risk-based access reviews, entitlement controls, and automated decommissioning to prevent agents from retaining access after their tasks or business roles end.

RSA offers sovereign control, allowing customers to choose where the gateway runs and policy decisions are made, keeping enforcement and evidence generation within customer-controlled environments.

RSA released a platform that generates tamper-evident records of agent actions, access decisions, and gateway calls, with evidence streaming to SIEM platforms and mapping to 10 compliance frameworks, including NIST AI RMF 1.0, ISO/IEC 42001, DORA, and NYDFS Part 500.

RSA Agent ID Discover and Secure are scheduled for general availability on November 16, 2026. RSA Agent ID Govern is expected to become generally available during the first half of 2027.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post RSA Launches Agent ID Platform to Secure AI Agents and MCP Servers appeared first on Cyber Security News.