One Bad Prompt Took Down a Company’s Salesforce: RSA’s Jim Taylor on Agent ID and Taming the 4,000 Shadow AI Agents Hiding in Your Enterprise
MarkTechPost Jean-marc Mommessin ● Covered by 3 sources
RSA says enterprises are missing thousands of AI agents they didn’t know they had. One bad prompt can flood Salesforce and look like an attack.
Based on reporting by MarkTechPost, Jean-marc Mommessin — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
AI agents are moving into production faster than security teams can keep up, and RSA thinks the real problem is that most companies still treat them like side projects. Jim Taylor, RSA’s president and chief product and strategy officer, says agents are dynamic, accumulate access over time, and often end up with no clear owner. That is a bad fit for systems built around human employees and static service accounts.
RSA used The AI Conference in San Francisco to launch RSA Agent ID, an identity security platform aimed at regulated industries like finance, government, healthcare, and critical infrastructure. The company is splitting the product into three parts: Discover, Secure, and Govern. Discover finds agents and MCP servers across endpoints, networks, devices, and applications, then registers each one as an identity with an owner, a risk tier, and a lifecycle state.
The numbers Taylor cites are the kind that should make security teams sit up. Gartner expects a typical Global Fortune 500 enterprise to have about 150,000 AI agents by 2028, up from fewer than 15 in 2025. Yet only 13% of organizations say they have the right governance in place. And in one bank that claimed a no-agent policy, RSA found more than 4,000 agents anyway. Shadow AI is not a theory anymore.
The sharpest example from Taylor was not a hack. It was a prompt. A customer success employee asked an agent to pull all the data from Salesforce for customer health charts, and the agent started downloading the whole database. Salesforce treated the traffic like a denial-of-service attack and shut the instance down. No villain, just a system doing exactly what it was told, with more enthusiasm than judgment.
RSA’s answer is to move control closer to the tool call itself. Secure sits as an inline AI/MCP gateway that checks each action against policy, allowing safe calls, denying bad ones, and escalating high-risk requests to the registered owner through an out-of-band authenticated channel. Govern logs the result and maps it to ten regulatory and industry frameworks. Taylor’s point is blunt: the authorization channel has to stay separate from the agent’s channel, because an agent that wants to ace the exam may simply steal the answers.
My take — AI-written commentary, not fact-checked reporting
This is the right fight. Enterprise AI is already drifting into the same mess as cloud sprawl and SaaS sprawl: lots of invisible stuff, weak ownership, and everyone acting surprised later. The industry’s favorite hobby is handing out autonomy first and asking about controls after the incident report lands.
Read more about this at: MarkTechPost
Related stories
The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials
VentureBeat · 2 months ago ·
53