Drooid Logo
Back to story perspectives

Full Breakdown

Enterprise AI Agent Security Platforms Take Shape

By Drooid · · How we work

Background & Context

The rapid deployment of autonomous AI agents in regulated environments has outpaced traditional identity and access-management controls. Organizations report that agents can act without registration or accountability, creating “catastrophic” risk for finance, government, and critical infrastructure. RSA cited Gartner’s projection that a typical Global Fortune 500 firm may run ? 150,000 AI agents by 2028, up from fewer than 15 in 2025. This pressure has prompted vendors to embed security, governance, and detection capabilities directly into the agents.

New Security Solutions Unveiled

RSA Agent ID

Unveiled at World Summit AI in Amsterdam, RSA Agent ID treats each AI agent as a first-class identity that can hold credentials, receive permissions, and act on behalf of an enterprise. The platform offers three pillars:

  • Discover – identifies agents and Model Context Protocol (MCP) servers across identity, cloud, endpoint, and gateway layers, registering each with an owner, risk classification, and lifecycle status.
  • Secure – enforces policy at every access attempt; high-risk actions trigger phishing-resistant human approval.
  • Govern – applies continuous certification, risk-based access reviews, and lifecycle automation.

RSA announced that Agent ID Discover and Secure are scheduled to become generally available on November 16 2026, with Govern expected in early 2027. The solution runs in cloud, hybrid, or on-premises environments, with U.S. or Europe data residency and a fully air-gapped version planned for 2027.

AIBound AgentHarness

AIBound introduced AgentHarness, a control plane that embeds hundreds of predefined security rules inside AI agents. Rules cover secret-theft prevention, destructive-command blocking, and data-exfiltration safeguards. Organizations can enable, disable, or tailor each rule per team, with default actions of allow, ask the user, or deny. The product integrates with AIBound’s See-Stop-Govern platform, mapping enforcement to the EU AI Act, NIST AI RMF, and ISO/IEC 42001 standards.

Sierra fleming-1

On October 7 2026, Sierra launched fleming-1, a model that scores incoming call audio in real time to determine whether the caller is an AI agent. The system evaluates synthetic-voice signatures beyond human perception, flagging likely AI callers while defaulting to a conservative stance to avoid false positives. Sierra positioned fleming-1 as a “Caller ID for AI agents,” enabling businesses—e.g., banks—to add verification steps when an agent initiates a call.

Data & Statistics

Data & Statistics
MetricSource
Projected AI agents per Fortune 500 firm by 2028: ~150,000 (vs <15 in 2025)RSA (citing Gartner)
Number of built-in security rules in AgentHarnessAIBound
Global AI token usage attributed to Hermes Agent (? 2.5 %)Nous Research
Launch date of fleming-1Sierra (Oct 7 2026)

Official Statements & Responses

  • The platform extends RSA’s identity discipline to AI actors.
  • The tool is presented as a conservative safeguard that lets businesses decide subsequent actions.

Verbatim Quotes

  • “AI agents have become the most privileged users in the enterprise. They hold their users’ keys, repos and production access, and they act in seconds,” — Niall Browne, CEO, AIBound

What’s Next

  • RSA Agent ID Discover and Secure become generally available on Nov 16 2026; Govern follows in early 2027.
  • Sierra plans to publish the v0.1 specification of its Personal Agent Protocol later in Oct 2026 and to host design workshops with industry partners.
  • AIBound will continue expanding its rule catalog and aligning enforcement reports with emerging AI governance frameworks.

These coordinated launches signal a growing market focus on embedding identity, policy, and detection mechanisms directly into AI agents, aiming to bring enterprise-grade security to a rapidly expanding class of autonomous software actors.