Interestana
Home/News/RSA Agent ID Tackles Shadow AI Agents and Enterprise Risk
MarkTechPost••4 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

RSA Agent ID Tackles Shadow AI Agents and Enterprise Risk

RSA Agent ID Tackles Shadow AI Agents and Enterprise Risk

RSA announced RSA Agent ID, an agentic identity security platform designed to manage the risks associated with the rapid proliferation of AI agents within enterprise environments. The platform aims to provide security for regulated industries including finance, government, healthcare, and critical infrastructure. Jim Taylor, President and Chief Product and Strategy Officer at RSA, highlighted the challenges posed by AI agents, noting that they fundamentally alter traditional identity and access management models. Unlike static service accounts, AI agents are dynamic and can perform tasks with significant autonomy. A poorly worded prompt can lead an agent to take actions the user did not intend, and agents do not experience fatigue or the need for breaks, potentially operating continuously.

Taylor emphasized that AI agents accumulate permissions, data, and access over time without adequate oversight. Employees might create an agent to meet a specific deadline, but once deployed, the agent's evolving permissions are often not reviewed, and the agent itself may not be disabled or deleted when no longer needed. This dynamic can lead to significant security vulnerabilities. The scale of unmanaged agents can be surprising, even for organizations with strict policies. Taylor recounted an instance where a medium-sized global bank, which believed it had no AI agents due to policy prohibitions, discovered over 4,000 agents operating within its enterprise during an audit, indicating that agents often do not adhere to established policies.

The financial implications of unmanaged AI incidents are substantial. According to IBM, incidents involving shadow AI cost an average of $670,000 more than standard security incidents. A critical failure scenario described by Taylor involved a customer success employee at an unnamed company who instructed an AI agent to "go to Salesforce and get all the data" to create customer health charts. This prompt, while seemingly innocuous, caused the agent to initiate a process that effectively became a denial-of-service attack on the company's Salesforce instance, demonstrating how a single, poorly constructed prompt can lead to severe operational disruption without any external malicious actor.

Gartner projects a dramatic increase in the number of AI agents within large enterprises. They forecast that a typical Global Fortune 500 enterprise will operate approximately 150,000 AI agents by 2028, a significant leap from fewer than 15 agents in 2025. Despite this anticipated surge, only 13% of organizations currently believe they possess adequate governance structures for managing these agents. RSA Agent ID seeks to address this governance gap by providing a dedicated identity security solution for these increasingly prevalent and powerful AI entities, aiming to bring visibility and control to the growing landscape of autonomous agents operating within corporate systems.

Original source — read the full reporting at the publisher:

Read on MarkTechPost

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next