• bitcoinBitcoin(BTC)$83,203.000.19%
  • ethereumEthereum(ETH)$2,668.200.22%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$758.520.07%
  • rippleXRP(XRP)$1.490.36%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$119.021.20%
  • tronTRON(TRX)$0.3351250.28%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.032.76%
  • zcashZcash(ZEC)$1,409.021.99%
  • HyperliquidHyperliquid(HYPE)$85.95-0.62%
  • dogecoinDogecoin(DOGE)$0.0932100.29%
  • chainlinkChainlink(LINK)$14.36-3.99%
  • moneroMonero(XMR)$541.170.05%
  • USDSUSDS(USDS)$1.000.00%
  • whitebitWhiteBIT Coin(WBT)$83.190.25%
  • cardanoCardano(ADA)$0.2435650.53%
  • RainRain(RAIN)$0.0125811.41%
  • leo-tokenLEO Token(LEO)$9.030.00%
  • stellarStellar(XLM)$0.219848-2.59%
  • nearNEAR Protocol(NEAR)$4.946.92%
  • bitcoin-cashBitcoin Cash(BCH)$305.39-0.02%
  • uniswapUniswap(UNI)$8.741.63%
  • litecoinLitecoin(LTC)$66.92-1.23%
  • CantonCanton(CC)$0.127481-4.28%
  • avalanche-2Avalanche(AVAX)$11.257.89%
  • Ethena USDeEthena USDe(USDE)$1.000.00%
  • suiSui(SUI)$1.153.11%
  • daiDai(DAI)$1.000.00%
  • hedera-hashgraphHedera(HBAR)$0.103305-13.20%
  • USD1USD1(USD1)$1.00-0.01%
  • quant-networkQuant(QNT)$294.1629.07%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.48-3.93%
  • BitwayBitway(BTW)$1.4023.52%
  • BittensorBittensor(TAO)$300.590.03%
  • shiba-inuShiba Inu(SHIB)$0.0000062.80%
  • tether-goldTether Gold(XAUT)$4,178.870.94%
  • crypto-com-chainCronos(CRO)$0.067062-1.19%
  • Global DollarGlobal Dollar(USDG)$1.00-0.01%
  • paypal-usdPayPal USD(PYUSD)$1.000.00%
  • Pump.funPump.fun(PUMP)$0.00579622.02%
  • okbOKB(OKB)$120.802.42%
  • Ripple USDRipple USD(RLUSD)$1.00-0.01%
  • EthenaEthena(ENA)$0.245352-1.59%
  • aaveAave(AAVE)$159.567.92%
  • OndoOndo(ONDO)$0.497938-1.14%
  • Circle USYCCircle USYC(USYC)$1.140.01%
  • MemeCoreMemeCore(M)$1.04-5.64%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.15-0.06%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

One Bad Prompt Took Down a Company’s Salesforce: RSA’s Jim Taylor on Agent ID and Taming the 4,000 Shadow AI Agents Hiding in Your Enterprise

September 30, 2026
in AI & Technology
Reading Time: 8 mins read
A A
One Bad Prompt Took Down a Company’s Salesforce: RSA’s Jim Taylor on Agent ID and Taming the 4,000 Shadow AI Agents Hiding in Your Enterprise
ShareShareShareShareShare

AI agents are moving into production faster than security teams can track them. They hold credentials, carry entitlements, and act on systems of record, yet most enterprises cannot say which agents are running, who owns them, or whether anyone can stop them. Gartner expects a typical Global Fortune 500 enterprise to run roughly 150,000 AI agents by 2028, up from fewer than 15 in 2025, while only 13% of organizations believe they have the right agent governance in place.

At The AI Conference in San Francisco, RSA announced RSA Agent ID, an agentic identity security platform for regulated industries such as finance, government, healthcare, and critical infrastructure. We sat down with Jim Taylor, President and Chief Product and Strategy Officer at RSA, to dig into how it works.

YOU MAY ALSO LIKE

Don’t Throw Away Your Old Router — Do This Instead

The AI Industry Wants Models To Assist In Legal Battles, But Will They Help?

Why Agents Break the Identity Model

“What changes with agents? Everything. They’re not a service account. They’re not static. They’re dynamic. You give an agent a task, and if you badly word that task, it will do whatever it deems necessary to perform it. Agents don’t get tired at two o’clock in the morning. They just go.”

Agents also accumulate permissions, data, and access over time, and nobody follows up. “Employees create an agent to hit a deadline, but once it’s off in the wild, that’s it. We don’t check when its permissions change. We don’t delete or disable agents.”

The scale surprises even regulated firms. A medium-sized global bank told RSA it had no agents, since policy prohibited them. “Agents don’t tend to respect policy,” Taylor said. “We did an audit and found more than 4,000 agents running around in their enterprise.” According to IBM, incidents involving shadow AI cost $670,000 more on average than standard incidents.

When a Prompt Becomes a Denial-of-Service Attack

Taylor’s failure scenario involved no attacker at all. A customer success employee at an unnamed company asked an agent to “go to Salesforce and get all the data” to build customer health charts. The agent began downloading the entire Salesforce database. Salesforce’s defenses read the traffic as an attack, shut down the instance, and warned the company that it appeared to be under a denial-of-service attack.

“One operator on the customer service desk took the whole company’s Salesforce instance down by essentially having an agent perform a denial-of-service attack. He didn’t do anything wrong.”

Discover, Secure, Govern

RSA Agent ID ships as three modules, available standalone or as one system on the RSA Unified Identity Platform.

Discover scans endpoints (via connectors into tools such as CrowdStrike and Zscaler), devices, network, and applications in real time. It finds agents and MCP servers, sanctioned and shadow, and registers each as a first-class identity with a named owner, risk tier, and lifecycle state, linked to existing identity providers such as Microsoft Entra ID, Okta, and AWS IAM. “Every agent should have an owner,” Taylor said. “It should be attached to a human identity.”

Secure is an inline AI/MCP Gateway that checks every tool call against policy at tool and argument depth. Calls within policy are allowed, calls against policy are denied, and high-risk calls are escalated to the registered owner. Approvals go through an out-of-band, authenticated channel with phishing-resistant credentials that agents cannot access.

Govern logs every governed action and maps the evidence to ten regulatory and industry frameworks out of the box, streaming it to the customer’s SIEM. “Regulators want to know if you had a policy in place at the time of an incident, who approved it, what actions took place, and they want to see that in indelible logs,” Taylor said.

Human Assurance, Not Human in the Loop

Taylor rejects the approve/deny fatigue of today’s AI tools. “A hundred prompts a day is just an invitation to say yes. It’s another form of denial-of-service attack.”

Instead, a risk engine scores each action on the user (is this expected behavior?), the action (read, write, or something riskier?), and the data and endpoint (how sensitive is the target?). Only actions that cross a threshold go to a human. A refund agent might process refunds under $500 automatically, while larger ones need the owner’s approval, or a second approver through a built-in workflow.

The customer defines what counts as high-risk, with AI-assisted suggestions. “I don’t know what’s important to everyone else on the planet,” Taylor said. “Organizations know their business risk.”

Layered Defense, Not a Silver Bullet

Asked about a prompt-injected support ticket requesting a fraudulent refund, Taylor said hidden malicious instructions are evaluated against policy and would be caught. A legitimate-looking refund from a fraudster on a stolen device is a different problem. “Models have good guardrails, but they’re not enough. You need a fraud detection system too.”

He was just as candid about gateway bypass, such as coding agents lifting another team’s API keys from a repository. “We don’t walk on water,” he said. API gateways, firewalls, and traffic inspection should also catch credential theft. “We don’t need to reinvent security. We need to layer agentic security on top of effective security that’s already in place.” The key design principle is to keep the authorization channel separate from the agent’s channel: “Tell an agent to do really well on an exam, and the easiest way is to steal the answers.”

Taylor also argued that CI/CD and DevSecOps pipelines are now an identity attack surface, and deserve the same controls as admin access to a production server.

Delegation: “Agents Cannot Give What They Don’t Get”

When agents spawn sub-agents or hand off tasks, Agent ID intercepts at tool-execution time and enforces an inherited permission model:

“An agent can only enable another agent with the entitlements it was granted. It cannot leverage another agent’s permissions. We would see that at runtime and say: who’s asking you to do that task? He doesn’t have those permissions. Denied.”

That closes a privilege-escalation path through delegation chains, a growing concern as multi-agent orchestration spreads.

The 30-Day Pilot: Three Questions

For a CISO evaluating Agent ID, Taylor starts with three questions:

  1. What agents are running in your environment? Not your AI initiatives, but the agents actually running.
  2. Who owns them? Not who created them, but which human is responsible.
  3. Can you kill them? If an agent misbehaves, would you even know?

“Most CIOs and CISOs can’t answer those,” he said. His recommended pilot is to connect a few key systems and run Discovery. “They’re usually surprised by what comes back. That gives them the internal ammunition to start assigning agents to people and building policy.”

Availability

RSA Agent ID Discover and Secure will be generally available November 16, 2026, with Govern following in the first half of 2027.

Key Takeaways

  • Agents are identities, not service accounts. They are dynamic, accumulate permissions, and usually lack an owner.
  • Shadow AI is already widespread. One bank with a “no agents” policy had more than 4,000.
  • Enforcement happens at the tool call. An inline AI/MCP Gateway allows, denies, or escalates every call.
  • Human assurance replaces approval spam. Only risk-scored, high-risk actions reach a human, out of band.
  • Delegated permissions are inherited, never expanded.
  • Before granting more autonomy, make sure you can discover, authorize, limit, and kill your agents.


Jean-marc is a successful AI business executive .He leads and accelerates growth for AI powered solutions and started a computer vision company in 2006. He is a recognized speaker at AI conferences and has an MBA from Stanford.

Credit: Source link

ShareTweetSendSharePin

Related Posts

Don’t Throw Away Your Old Router — Do This Instead
AI & Technology

Don’t Throw Away Your Old Router — Do This Instead

September 30, 2026
The AI Industry Wants Models To Assist In Legal Battles, But Will They Help?
AI & Technology

The AI Industry Wants Models To Assist In Legal Battles, But Will They Help?

September 29, 2026
Liquid AI Releases d1: A Decision Model That Returns Calibrated Probabilities With Zero Output Tokens
AI & Technology

Liquid AI Releases d1: A Decision Model That Returns Calibrated Probabilities With Zero Output Tokens

September 29, 2026
Codenames Party Is The Latest Addition To Netflix Games
AI & Technology

Codenames Party Is The Latest Addition To Netflix Games

September 29, 2026
Next Post
8% MORTGAGE RATES ARE COMING! (Get Ready)

8% MORTGAGE RATES ARE COMING! (Get Ready)

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Liquid AI Releases d1: A Decision Model That Returns Calibrated Probabilities With Zero Output Tokens

Liquid AI Releases d1: A Decision Model That Returns Calibrated Probabilities With Zero Output Tokens

September 29, 2026
NBC Nightly News Full Episode – Aug. 21

NBC Nightly News Full Episode – Aug. 21

September 25, 2026
Steve Kornacki analyzes results from South Carolina’s GOP Senate runoff | Kornacki Cam | NBC News

Steve Kornacki analyzes results from South Carolina’s GOP Senate runoff | Kornacki Cam | NBC News

September 23, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!