RSA Launches Agent ID to Control What AI Agents Can Do in Regulated Enterprises

Identity security concept representing RSA Agent ID controls for AI agents

RSA has introduced Agent ID, an identity security platform designed to discover, control and monitor artificial intelligence agents at banks, public agencies and other organizations with strict security and regulatory compliance requirements. The solution aims to ensure each agent has an identified owner, scoped permissions and a verifiable record of actions that require human authorization. General availability is planned for November 2026 for two of its modules, while the governance module will arrive in the first half of 2027.

RSA Agent ID in 30 seconds

  • The platform can locate AI agents and Model Context Protocol (MCP) servers, including those operating without formal authorization.
  • Each agent can be registered with an owner, a risk level and a status within its lifecycle.
  • High-risk actions require approval from an identified person authenticated through a phishing-resistant mechanism.
  • The control gateway can run in the cloud, in hybrid environments or on-premises.
  • Discover and Secure will launch on November 16, 2026; Govern is planned for the first half of 2027.

The announcement responds to a problem that is becoming more pressing as companies adopt agents capable of querying data, using tools and executing operations on corporate systems. Unlike an assistant that is limited to answering questions, an agent can hold credentials and permissions to act on applications, databases or internal services — a concern also central to Gartner’s recent ranking of agentic AI and cybersecurity among top public-sector priorities.

That requires extending identity management beyond employees and traditional service accounts. Organizations need to know which agents are active, who is responsible for them, what resources they can access and how to shut them down when they are no longer needed.

RSA, a provider of identity and access control solutions, presents Agent ID as an extension of its Unified Identity Platform. The company argues that agent identities should be managed with controls similar to those applied to people, though with specific mechanisms to automate their registration, review their permissions and link relevant operations to verifiable authorization.

Three modules to discover, secure and govern agents

RSA Agent ID is divided into three modules that cover different stages of an agent’s lifecycle. The company says they can be purchased separately or used as parts of a connected platform.

ModuleMain functionWhat it enables
Agent ID DiscoverDiscovery and registrationLocates agents and MCP servers across identity sources, cloud, devices and gateways. Registers them with an owner, risk level and status.
Agent ID SecureAccess control and authorizationApplies policies to every call that passes through the AI/MCP gateway and requires additional human authorization for high-risk actions.
Agent ID GovernGovernance and reviewEnables certifying agents, reviewing their access based on risk, and automating management tasks throughout their lifecycle.

Discover is designed to identify both known agents and those operating outside internal procedures, a situation often described as shadow AI. The platform also aims to register MCP servers, which let models and agents connect to external tools, data sources and services.

Secure sits at the point where agents invoke tools. The AI/MCP gateway applies policies to each call and can require an identified person to approve certain operations. According to RSA, that approval must take place outside the automated flow and use a phishing-resistant credential.

The third component, Govern, adds periodic access reviews and certification processes for agents. Its goal is to prevent automated identities from accumulating permissions without review or remaining active after they are no longer used.

The three modules address different needs: knowing which agents exist, limiting what they can execute, and periodically checking that their permissions remain appropriate — a similar philosophy to the physical and behavioral limits NVIDIA recently proposed for AI agents with OpenShell and Sentry.

Decision control and on-premises deployment

One of the features RSA highlights is the ability to run the gateway in the cloud, in a hybrid architecture or on local infrastructure. The location can be chosen for each gateway, and when an organization hosts it in its own environment, the decision to apply the policy to each call is made there.

The company also states that each customer’s data stays in the selected region, the United States or the European Union, and that control evidence is generated where the gateway runs before being sent to the security information and event management (SIEM) system.

This approach aims to meet the needs of banks, public agencies and critical infrastructure operators that cannot delegate all authorization decisions to an external provider. For these organizations, data location, traceability of operations and the ability to demonstrate who authorized an action can be part of audit requirements.

RSA also states that Agent ID doesn’t require adopting a single identity provider. The platform aims to work with the system the organization already uses, so that agent management doesn’t depend on a specific identity ecosystem.

There is, however, an important limitation in the initial offering: the fully self-managed version isolated from external networks, known as air-gapped, is planned for 2027. This mode should therefore not be confused with the deployment options announced for initial availability.

Human authorization as a limit on agents

Control over high-risk actions is one of the central points of Agent ID. RSA proposes that certain operations should not run simply because an agent has technical access to a tool. Authorization from an identified and authenticated person must exist first.

This mechanism aims to link each relevant action to a human owner. It also lets organizations log governed operations and have evidence available for internal reviews or external audits.

The platform also provides for revoking permissions when an agent is retired. That aspect is relevant in environments where agents are created for specific tasks, change roles or stop being used without necessarily having all their credentials removed immediately.

The effectiveness of these controls will depend on how policies are configured, which systems are connected to the gateway and which actions fall within its scope of oversight. The information published by RSA describes the planned capabilities, but doesn’t provide results from independent deployments that would quantify its effectiveness in production.

Availability dates and initial scope

RSA has set November 16, 2026 as the general availability date for Agent ID Discover and Agent ID Secure. Agent ID Govern is planned for the first half of 2027.

The company unveiled the platform at The AI Conference in San Francisco on September 29, 2026. It also published a technical paper on identity architecture for organizations with high security and compliance requirements.

The launch reflects an emerging need in corporate security: automated identities require controls that make it possible to know their origin, limit their permissions and attribute their operations. RSA’s proposal is to apply those controls at the point where agents access tools and systems, while keeping the option to run the policy in the environment the customer chooses.

For organizations incorporating agents into financial, administrative or infrastructure processes, the question is no longer just which AI model they use. They must also determine which identity is acting, with what authority and under what oversight mechanisms.

Frequently asked questions

What is RSA Agent ID?

It’s an identity security platform for discovering, protecting and governing artificial intelligence agents. It’s aimed especially at regulated organizations, such as banks and public agencies.

What’s the difference between Discover, Secure and Govern?

Discover locates and registers agents; Secure applies access policies and authorization controls; Govern enables reviewing permissions, certifying agents and automating their management throughout the lifecycle.

When will RSA Agent ID be available?

Discover and Secure are set for general availability on November 16, 2026. Govern is planned for the first half of 2027.

Can RSA Agent ID run on-premises?

The AI/MCP gateway can be deployed in the cloud, in hybrid environments or on local infrastructure. RSA has announced a fully self-managed version isolated from external networks for 2027.

Scroll to Top