OZZZER · AI NEWS1 of 3 free stories opened
← Back to AI News

Automation & Agents · 30 Sep 2026 · 03:30 CEST

One Bad Prompt Took Down a Company’s Salesforce: RSA’s Jim Taylor on Agent ID and Taming the 4,000 Shadow AI Agents Hiding in Your Enterprise

MarkTechPost · 30 Sep 2026 · 03:30 CESTRead original at MarkTechPost ↗
Share
LinkedInXFacebookWhatsApp
One Bad Prompt Took Down a Company’s Salesforce: RSA’s Jim Taylor on Agent ID and Taming the 4,000 Shadow AI Agents Hiding in Your Enterprise

Publisher preview · OZZZER analysis pending editorial review.

PUBLISHER ARTICLE PREVIEW

From the original article

AI agents are moving into production faster than security teams can track them. They hold credentials, carry entitlements, and act on systems of record, yet most enterprises cannot say which agents are running, who owns them, or whether anyone can stop them. Gartner expects a typical Global Fortune 500 enterprise to run roughly 150,000 AI agents by 2028, up from fewer than 15 in 2025, while only 13% of organizations believe they have the right agent governance in place.

At The AI Conference in San Francisco, RSA announced RSA Agent ID, an agentic identity security platform for regulated industries such as finance, government, healthcare, and critical infrastructure. We sat down with Jim Taylor, President and Chief Product and Strategy Officer at RSA, to dig into how it works.

“What changes with agents? Everything. They’re not a service account. They’re not static. They’re dynamic. You give an agent a task, and if you badly word that task, it will do whatever it deems necessary to perform it. Agents don’t get tired at two o’clock in the morning. They just go.”

Agents also accumulate permissions, data, and access over time, and nobody follows up. “Employees create an agent to hit a deadline, but once it’s off in the wild, that’s it. We don’t check when its permissions change. We don’t delete or disable agents.”

The scale surprises even regulated firms. A medium-sized global bank told RSA it had no agents, since policy prohibited them. “Agents don’t tend to respect policy,” Taylor said. “We did an audit and found more than 4,000 agents running around in their enterprise.” According to IBM, incidents involving shadow AI cost $670,000 more on average than standard incidents.

Taylor’s failure scenario involved no attacker at all. A customer success employee at an unnamed company asked an agent to “go to Salesforce and get all the data” to build customer health charts. The agent began downloading the entire Salesforce database.

Source

MarkTechPost · 30 Sep 2026 · 03:30 CEST

Open the original at MarkTechPost ↗