What it means that RSA found 4,000 hidden AI agents and a prompt took down a company's Salesforce — September 30, 2026
noticias ia para empresas ai first agentes de ia inteligencia artificial empresas rsa salesforce shadow ai

What it means that RSA found 4,000 hidden AI agents and a prompt took down a company's Salesforce — September 30, 2026

· CompaniesAutomation

Flash edition of the Radar: RSA found 4,000 hidden AI agents in a bank that banned them, and a single prompt took down a company's Salesforce. The three questions you must be able to answer.

Flash edition. A bank that prohibited AI agents had more than 4,000 running, and an employee knocked out Salesforce for their entire company with a single request. RSA shared these stories while launching a product to control agents. In today's Radar, we looked at how OpenAI sets rules for its agents; here, what to do with the ones you already have without knowing it.

What happened

RSA presented RSA Agent ID on Tuesday at The AI Conference in San Francisco. It has three modules: Discover locates agents, whether authorized or "shadow," and assigns a human owner to each; Secure reviews every tool call before execution, requests human approval for risky actions, and features a kill switch; Govern, planned for 2027, generates evidence for audits (Source). Discover and Secure arrive on November 16.

The anecdotes were shared by its president, Jim Taylor, in an interview (Source). A medium-sized global bank claimed to have no agents because its policy prohibited them: "We did an audit and found more than 4,000." In another company, which he did not identify, a customer service employee asked an agent to "go to Salesforce and get all the data" for some charts. The agent began downloading the entire database, Salesforce's defenses mistook it for a denial-of-service attack and shut down the instance. "He didn't do anything wrong," says Taylor.

Why it matters

In neither case is there an attacker: the agent did what it was asked with the permissions it had. Gartner, cited by RSA, estimates that a typical large enterprise will go from fewer than 15 agents in 2025 to 150,000 in 2028. Taylor summarizes it in the press release: agents "skipped every process built for people: no registration, no owner, no accountability" (Source). Prohibiting is not controlling: people set up an agent to meet a deadline and nobody turns it off afterward.

For your company

You don't need to buy anything to answer the three questions Taylor opens every pilot with:

  • Which agents are running today? Check the Google Workspace or Microsoft 365 console for connected applications with data access, and ask about automations in Zapier, Make, n8n, or connectors for ChatGPT and Claude.
  • Who is responsible for each one? One name per agent. Anything without an owner gets disconnected.
  • Can you stop it? Each agent should have its own credential, the minimum possible permission and, if possible, read-only. And you must know how to revoke it in a minute.

And give tasks with limits: "active customers from this quarter," not "all the data." Downloading the entire CRM also clashes with the GDPR principle of data minimization. On the AI First ladder, no agent should work unattended (step 3) without an inventory, an owner, and a kill switch.

FAQ

What is a "shadow" AI agent?

One that a staff member puts to work using their own credentials without IT approval or registration.

Is RSA Agent ID suitable for an SME?

It is designed for banking, government, healthcare, and critical infrastructure, and RSA does not publish pricing. For an SME, the immediate step is a manual inventory; a tool like this makes sense when that list can no longer be managed in a spreadsheet.