No Agentic Sovereignty, No Agentic Security
RSA, Tuesday, September 22nd, 2026
RSA argues data residency doesn't equal agentic sovereignty, since AI agents move and act on data in ways residency rules don't cover.
RSA notes that roughly 70% of organizations in high-security sectors like banking, government and defense cite security and privacy as the top barriers to adopting AI agents, arguing this caution reflects sound judgment rather than resistance to change.
It challenges the assumption that data residency equals sovereignty, since agents don't work with data at rest: they pick data up, reason over it and act on it, so sensitive fields can land in prompts, memory, logs and embeddings outside an organization's system of record regardless of where data is stored.
RSA argues that because an agent's autonomy is inseparable from its authority to move money, grant access or change records, the capability organizations buy is also the exposure they now carry.