Will it run?
Agents

AI agents are taking over critical systems, and security can't keep up

By Marco Vane Clawpit staff
AI agents are taking over critical systems, and security can't keep up

AI agents are moving into production faster than security teams can absorb them. They hold privileges, reach into core systems, and act autonomously, yet most organizations don't know which agents are running, who owns them, or how to stop them when something breaks. Gartner projects that a typical Fortune 500 organization will run roughly 150 thousand agents by 2028, up from fewer than 15 in 2025, while only 13% of organizations believe they have proper agent governance in place.

The bank that thought it had no agents

The gap between policy and reality surfaced at a mid-sized global bank that declared it had zero agents because policy forbade them. "Agents don't tend to respect policy," Taylor said. An RSA audit uncovered more than 4,000 active agents in the environment. According to IBM, incidents involving "shadow AI" — unmanaged agents — cost an average of 670 thousand dollars more than ordinary incidents. Agents also accumulate permissions and access over time with no oversight: employees spin up an agent to meet a deadline, and once it is "released into the wild" there is no control over permission changes, no decommissioning, no kill switch.

When one prompt takes down Salesforce

The scenario Taylor describes involves no external attacker. A customer-service employee at an unnamed company asked an agent to "access Salesforce and pull all the data" to build customer-health dashboards. The agent began downloading the entire database. Salesforce's own defenses flagged the traffic as an attack, shut down the instance, and alerted the company that it was under a denial-of-service assault. "One operator at a service desk brought down the company's entire Salesforce instance by causing the agent to launch a DoS attack," Taylor explained. "He didn't do anything wrong."

Discovery, security, governance

RSA Agent ID launches as three modules, available separately or as a unified system on RSA's unified identity platform. Discover scans endpoints — via connectors to CrowdStrike and Zscaler — devices, network, and applications in real time. It locates agents and MCP servers, both authorized and shadow, and registers each as a first-class identity with a defined owner, risk tier, and lifecycle state, linked to existing identity providers such as Microsoft Entra ID, Okta, and AWS IAM. "Every agent needs an owner," Taylor emphasized. "It needs to be tied to a human identity."

A policy gate at tool-call time

Secure operates as an inline AI/MCP gateway that inspects every tool call against policy at the tool and argument level. Calls that comply are approved; calls that violate policy are blocked; high-risk calls are routed to the registered owner for approval. Those approvals travel through an out-of-band channel with phishing-resistant authentication — a channel the agents themselves cannot reach.

Immutable logs for regulators

Govern records every governed action and maps the evidence to ten regulatory and industry frameworks out of the box, streaming to the customer's SIEM. "Regulators want to know whether policy existed at the time of the incident, who approved it, what actions were taken, and they want to see that in logs that cannot be altered," Taylor said.

Human security, not a prompt-by-prompt sign-off

Taylor rejects the human-in-the-loop model that creates approval fatigue. "A hundred prompts a day is just an invitation to say yes. It's another form of alert fatigue." RSA's approach aims to replace the exhausting approval loop with clear ownership, automated policy enforcement, and a complete audit trail that satisfies regulators — without asking people to sign off on every step the agent takes.