Agent Identities Become a New Mandatory Task for Regulated Companies
RSA introduces Agent ID, a tool that lets regulated firms locate, secure and manage AI agents – a step likely to fundamentally reshape governance, liability and operational organization.

On September 29, 2026 RSA announced the launch of Agent ID in a press release – a platform specifically designed for heavily regulated industries to identify, classify, and control the use of AI agents. The announcement is aimed at financial institutions, insurers, health services and other sectors that, due to legal requirements, must trace and document every automated decision. RSA stresses that the solution is not merely a technical add‑on but an integral part of the compliance strategy, because an increasing number of companies depend on autonomous AI agents in critical processes.
What is Agent ID?
Agent ID consists of three modules – Discover, Secure and Govern – which together enable complete lifecycle management of AI agents. The Discover module scans network and application environments, detects both approved and unapproved agents and assigns them to their respective owners. In addition, it identifies MCP servers (Model‑Control‑Plane) and links them to the associated agents, providing a full picture of the deployed AI infrastructure. The results are presented in a central overview, allowing responsible parties to instantly see which agents are active, where they run, and who is accountable for them.
The Secure module checks in real time every tool‑call and argument combination against predefined policies. If a call does not meet the established criteria, Secure can request a separate, authenticated approval before the action is executed. This prevents unauthorized or potentially risky agent operations from going unnoticed. RSA emphasizes that the inline check does not add network latency because the policy engine is embedded directly in the data flow. Companies also receive detailed logs of rejected calls, strengthening traceability and audit reporting.
How does the governance work?
Govern, the third module of Agent ID, takes care of exhaustive logging of all actions performed by AI agents. Each interaction is mapped to one of ten predefined rule sets that reflect common regulatory requirements – ranging from data‑privacy to financial and health regulations. The collected evidence can be automatically forwarded to supervisory authorities or internal audit teams. RSA plans to make Govern generally available in the first half of 2027, while Discover and Secure are already scheduled for customer rollout on 16 November 2026. The modular architecture allows companies to start with the first two components and add governance later.
RSA provides the only quantitative hint, stating that a large bank already has more than 4,000 agents in operation that are subject to an internal prohibition policy. This figure comes from RSA itself and has not been verified by independent market studies. Nevertheless, it illustrates the scale that AI agents have already reached in regulated environments and underscores the need for a structured identity and control layer.
Implications for Liability and Operational Organization
By introducing Agent ID, companies receive a tool that makes the assignment of responsibility clearer. If an unauthorized agent makes a faulty decision, the Discover and Govern logs allow precise determination of which developer, team, or service provider had control. This strengthens the legal enforceability of liability claims and reduces the risk of fines, because regulatory requirements can be demonstrably met. Operationally, this means that IT and compliance departments must work closely together to implement policies in Secure, conduct regular scans with Discover, and review governance reports from Govern.
- Establish a central agent inventory via Discover.
- Define and implement policies in Secure for all critical tool calls.
- Integrate Govern into existing audit and reporting processes.
- Train business units on responsibilities related to AI agents.
- Regularly review and update the ten rule sets in line with regulatory changes.
From now on, regulated companies must incorporate Agent ID into their compliance strategy to meet the growing demands for transparency and control of AI agents. The availability of Discover and Secure from 16 November 2026 enables a rapid start, while Govern in the coming year ensures full evidentiary reporting. Companies that do not proactively address this mandatory task risk not only regulatory sanctions but also operational uncertainty, as unidentified agents can make unpredictable decisions. Agent ID therefore represents a clear turning point: agent identities move from an optional best practice to an indispensable requirement for every regulated organization.
Sources
- Hope Isn’t an AI Strategy: RSA Agent ID Closes the Agentic Identity Gap for Highly Regulated IndustriesRSA · September 29, 2026
- RSA Launches Agent ID Platform to Secure AI Agents and MCP ServersCyber Security News · September 30, 2026



