Banks and government agencies are deploying AI agents that touch core systems and customer data, and examiners are already asking who owns each one. RSA's answer is to treat agents as identities: registered, owned, revocable. The pitch lands on real pain. The calendar is the tell: the full product does not exist yet, and the sovereign air-gapped deployment the marketing leans on is a 2027 promise.
The question nobody in the building can answer
Ask a bank's CISO how many AI agents run inside the building and who owns each one. RSA's bet is that the honest answer is usually silence. Agents hold credentials, carry entitlements, and act on systems of record, but they skipped every process built for people: no registration, no named owner, no offboarding.
RSA brought numbers to make the gap feel expensive. IBM found that incidents involving "shadow AI" cost $670,000 more on average than standard ones. US federal agencies introduced 59 AI-related regulations in 2024, more than double the prior year. Gartner named agentic AI oversight its top cybersecurity trend for 2026 and expects the typical Global Fortune 500 to run about 150,000 agents by 2028, against fewer than 15 in 2025. When the agent fleet goes from a rounding error to a workforce, "we don't have a list" stops being an acceptable posture.
What Agent ID actually does
Three modules. Discover finds agents and MCP servers across identity, cloud, endpoint, and gateway sources — sanctioned and shadow alike — and registers each as a first-class identity with a named owner, a risk tier, and a lifecycle state. Secure enforces policy on every call at an AI/MCP gateway that runs either RSA-hosted or inside the customer's own environment; high-risk actions demand a named, authenticated human approving out of band with a phishing-resistant credential, and access is revoked when an agent is decommissioned. Govern treats agents the way identity teams treat people: continuous certification, risk-based access reviews, lifecycle automation. Every governed action is recorded and mapped to ten industry frameworks, and the enforcement evidence streams to the customer's SIEM.
The sovereign-control angle is the part RSA pushed hardest. Tenant data stays in the chosen region, the policy decision happens in the customer's environment when they host the gateway, and the whole thing is identity-provider independent. That is the right sales pitch for buyers who cannot hand decisions back to a vendor's cloud.
The calendar reads as a tell
Discover and Secure go generally available November 16. Govern lands in the first half of 2027. The air-gapped, self-managed version that the sovereignty pitch keeps returning to is planned for 2027, with no firmer date.
None of that invalidates the product; enterprise launches ship in stages. But it means the complete version of the story RSA told in Amsterdam — agents under the same identity discipline as humans, enforcement where the customer chooses — is a 2027 proposition, not something you can buy this month. The press release is ahead of the product, and buyers who sign now are buying the roadmap for the parts that matter most.
The practical angle
If you build or deploy agents in a regulated industry, two things follow. First, expect procurement and security questionnaires to start asking where each agent is registered and who approves its actions. RSA just handed examiners a vocabulary for that conversation. Second, the ID-badge model creates a real design constraint: agents that take high-risk actions without a named human approver will look increasingly ungovernable to the customers with the largest budgets.
This is the enterprise counterpart to this morning's story about Sierra and Meta's personal agent protocol. Consumer agents are getting a shared standard; enterprise agents are getting an identity department. The direction is the same: agents are becoming a class of workers with HR files. Someone was always going to issue the badges.
Sources
- [1] RSA press release — “Stop Hoping for Secure AI and Start Building It: RSA Agent ID Closes the Agentic Identity Gap for Highly Regulated Industries” (October 7, 2026)Read source