News / AI & Data
RSA Agent ID: A Platform to Master the Risks of AI Agents in Regulated Sectors Published on 30 September 2026 by Christ-loisele (3 min read)
RSA unveiled at The AI Conference a solution dedicated to governing autonomous agents, designed for companies subject to strict frameworks. According to Jim Taylor, these dynamic tools often evade existing security policies, with costly and critical consequences.
Video (Vimeo)
An Explosive and Poorly Controlled Market
AI agents are multiplying in companies at a pace that security teams struggle to keep up with. According to Gartner , a company from the Global Fortune 500 could have up to 150,000 autonomous agents by 2028 , compared to fewer than 15 in 2025 (source: MarkTechPost ). Yet, only 13% of organizations believe they have governance under control, the same source reveals.
These tools, often created without oversight, accumulate permissions and access without monitoring. A striking example: a mid-sized global bank hosted over 4,000 of them despite an internal policy banning them . Worse, an incident reported by Jim Taylor , RSA’s strategy president, shows that a poorly phrased request to an AI agent caused a Salesforce instance to crash while attempting to download an entire database (source: MarkTechPost ).
AI agents are neither static service accounts nor entities that inherently respect policies: they evolve on their own, and it is this dynamic that makes them dangerous.
Image: RSA (official image)
RSA Agent ID: A Response to Regulatory and Operational Risks
RSA Agent ID, presented at The AI Conference in San Francisco on September 29, 2026, positions itself as a platform dedicated to securing AI agents in financial, government, healthcare, and critical infrastructure sectors (source: RSA.com ). It is built on three modules: Discover (identifying agents, including 'shadow' ones), Secure (access control via an AI/MCP gateway), and Govern (centralized governance), available separately or integrated into the RSA Unified Identity Platform .
Each agent is linked to a responsible human identity, with a defined lifecycle. The platform applies control policies to every call and requires human approval for high-risk actions. It generates audit trails compliant with ten major regulatory frameworks , as highlighted by RSA (source: RSA.com ). Approvals are processed through a phishing-resistant channel, inaccessible to the agents themselves.
What This Changes Here
For Beninese and African companies operating in regulated sectors, such as banks, insurance, or public administrations, this solution could address a twofold urgency: the uncontrolled proliferation of internal AI tools and the intensification of regulatory requirements . According to IBM , incidents involving 'shadow' AI agents cost on average $670,000 more than conventional incidents (source: MarkTechPost ).
In West Africa, where digital infrastructures are expanding and frameworks such as the African General Data Protection Regulation (GDPR) (currently in development in several countries) could apply, a solution like RSA Agent ID would enable:
Tracking undeclared autonomous agents, often used without explicit IT service consent. Securing interactions with critical systems (such as banking platforms or medical records) by limiting risks of leaks or tampering. Demonstrating proactive compliance during audits, a key challenge for institutions subject to international oversight (e.g., banks partnered with the BCEAO). The compatibility of RSA Agent ID with cloud, hybrid, or on-premises environments, as well as with tools like Microsoft Entra ID or AWS IAM , would facilitate its adoption by organizations already equipped with Microsoft or AWS solutions, common in major regional enterprises.
Deployment timeline: a phased approach
The Discover and Secure modules of RSA Agent ID will be available in general release on November 16, 2026 , while Govern will follow in the first half of 2027 (source: BriefGlance ). An air-gapped (disconnected) version is planned for 2027, addressing the needs of the most sensitive sectors, such as strategic infrastructure or defense.
The platform integrates with existing ecosystems (RSA ID Plus, Microsoft Defender) and aims to preserve data sovereignty within local environments. For African administrations and businesses, this modularity could allow for a gradual adoption, starting with the detection of unauthorized agents before expanding controls.
Sources