Agentic AI stood out at RSA Conference 2025 because the discussion was shifting from AI that generates or summarizes content to systems designed to take actions across workflows. RSAC named it among several pressing topics—not the conference’s sole or definitively top subject—and the practical questions included agent identity, governance, and traceability.
Why agentic AI came up at RSAC 2025
RSAC’s May 2, 2025 wrap-up listed agentic AI alongside identity shifts, vulnerability management, and regulation and policy as pressing conference topics. The 34th annual flagship conference took place at Moscone Center in San Francisco. RSAC reported nearly 44,000 attendees, 730 speakers, 650 exhibitors, and 400 members of the media. These are organizer-reported figures, not an independent attendance count. RSAC 2025 conference wrap-up
Contemporaneous coverage also described AI broadly as a headliner, while placing agentic AI within a wider agenda that included generative AI, AI in security operations, application security, LLM protection, and governance. ITPro reported that RSAC executive chairman Hugh Thompson identified agentic AI as a leading term in the conference’s topic data, with sessions addressing agent identity, governance, and traceability. That supports calling agents a prominent theme, but it does not establish a quantitative, event-wide ranking. ITPro’s retrospective on AI at RSAC 2025
How agentic AI differs from generative AI
The useful distinction is the role a system plays. Generative AI produces or summarizes content in response to a prompt. Agentic AI, as discussed in the RSAC session description, involves workflows in which systems can work through more complex problems, collaborate with other agents, and learn iteratively. That description is a forecast of what such workflows may enable, not proof that every product marketed as an agent has the same capabilities or autonomy. RSAC session listing: “Security in the Age of Agentic AI”
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
The distinction matters in security because a system that can take steps through a workflow raises questions beyond the quality of its generated text. What identity does it act under? Which systems and actions can it access? How can an organization review what it did and trace its decisions? These are governance questions raised in reporting about the conference, not evidence that any particular vendor has solved them.
What the program and submission data show
A dedicated security session
RSAC’s April 28, 2025 listing for “Security in the Age of Agentic AI” named Vasu Jakkal, Microsoft Security Corporate Vice President, as the speaker. Its description focused on agentic workflows, collaboration, complex problem-solving, and iterative learning. It establishes that agentic AI had a place in the conference program; it is not an independent evaluation of deployed systems or their security.
Rank #2
An earlier signal from proposed talks
RSAC’s conference submission-trends report says about 5% of proposed talks were AI-related as recently as 2023. It also says submitters considered how humans and agents will coexist. The 5% figure concerns proposals in 2023; it is not the percentage of sessions delivered at RSAC 2025, the share of conference discussion, or a measure of attendee interest. RSAC 2025 conference submission-trends report
What security teams should take from the discussion
The conference conversation points to a practical trade-off: agentic workflows may aim to improve efficiency and productivity, but the ability to act makes permissions and oversight central design questions. For any proposed deployment, security teams need to understand:
Recommended Free Tools
- Identity: Which account, role, or credential does the agent use, and can its actions be distinguished from a human’s?
- Authority: What actions can it take, and are those permissions limited to what its task requires?
- Traceability: Can an organization reconstruct what the agent did and follow its actions through connected systems?
- Governance: Who sets the rules for the workflow and is accountable for its results?
These are questions raised by the conference coverage and later RSAC programming, not a checklist that proves a product is safe. An RSAC Innovation Showcase published September 30, 2025, discussed the move from traditional automation toward agentic AI, potential productivity and efficiency gains, risks in agentic decision-making, and security frameworks. It was a later online program, not an in-person session at the 2025 flagship conference. RSAC Innovation Showcase: Agentic Security for the Enterprise
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Was agentic AI the main topic at RSA 2025?
The evidence supports a narrower conclusion: agentic AI was a conspicuous part of RSAC 2025’s AI conversation, within a broader security agenda. RSAC’s wrap-up named it among several pressing issues, and a dedicated program session addressed it. Neither the official recap nor the available coverage establishes it as the conference’s single leading topic. “The real conversation” is best understood as a description of the shift from AI that generates content toward systems that can act through workflows—not as a verified event ranking.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

