STOCK TITAN

Workday Launches Agent Passport to Test, Verify, and Continuously Monitor Every AI Agent in the Enterprise

Rhea-AI Impact
(Moderate)
Rhea-AI Sentiment
(Neutral)
Tags
AI

Workday (NASDAQ: WDAY) introduced Agent Passport, a framework to test, verify, and continuously monitor every AI agent used in HR, finance, and IT. Attestations are tied to public standards such as OWASP LLM Top 10, NIST AI RMF, and MITRE ATLAS.

Cisco joins as launch partner, using Cisco AI Defense to independently validate agents against threats like prompt injection, jailbreaks, goal hijacking, data leakage, and unsafe outputs. Agent Passport can allow, block, or route agent actions in real time and revoke compromised agents centrally. Early access starts in the second half of 2026, with general availability projected before year-end 2026.

Loading...
Loading translation...

AI-generated analysis. Not financial advice.

Positive

  • Launch of Agent Passport to test and monitor all enterprise AI agents
  • Attestations aligned with OWASP LLM Top 10, NIST AI RMF, MITRE ATLAS
  • Independent agent security validation via partnership with Cisco AI Defense
  • Real-time policy engine to allow, block, or route AI agent actions
  • Centralized revocation capability to restrict affected agents across the enterprise
  • Early access and general availability timelines communicated for 2026

Negative

  • Agent Passport not available until second half of 2026 for early access
  • General availability only projected by end of 2026, delaying broad adoption

News Market Reaction – WDAY

-5.31%
54 alerts
-5.31% News Effect
-4.4% Trough in 4 hr 21 min
-$2.18B Valuation Impact
$38.84B Market Cap
0.3x Rel. Volume

On the day this news was published, WDAY declined 5.31%, reflecting a notable negative market reaction. Argus tracked a trough of -4.4% from its starting point during tracking. Our momentum scanner triggered 54 alerts that day, indicating high trading interest and price volatility. This price movement removed approximately $2.18B from the company's valuation, bringing the market cap to $38.84B at that time.

Data tracked by StockTitan Argus on the day of publication.

Key Figures

Early access timing: Second half of 2026 General availability: Before end of 2026
2 metrics
Early access timing Second half of 2026 Agent Passport early access availability
General availability Before end of 2026 Projected Agent Passport GA timing

Market Reality Check

Price: $126.77 Vol: Volume 9,283,319 is 65% a...
high vol
$126.77 Last Close
Volume Volume 9,283,319 is 65% above 20-day average of 5,613,886, signaling elevated interest ahead of this AI launch. high
Technical Price at 157.23 is trading below the 200-day MA of 185.56, despite today’s strong gain.

Peers on Argus

Momentum scanner shows 3 peers (e.g., TEAM, DDOG, MSTR) moving down with changes...
3 Down

Momentum scanner shows 3 peers (e.g., TEAM, DDOG, MSTR) moving down with changes from -3.83% to -9.36%, indicating broader sector pressure even as several software peers in the watchlist show notable positive moves.

Common Catalyst Multiple peers, such as SNOW, also issued AI-centric announcements today, pointing to a broader enterprise AI and agentic security narrative across application software.

Previous AI Reports

5 past events · Latest: May 27 (Positive)
Same Type Pattern 5 events
Date Event Sentiment Move Catalyst
May 27 AI planning launch Positive +0.4% Introduced Adaptive Decision Intelligence in Workday Adaptive Planning with early adopter access.
May 27 AI workplace study Positive +0.4% Released Human Connection Workplace Index on AI, burnout, and launched $500,000 microgrant initiative.
May 12 AI accelerator launch Positive -1.8% Announced AI-focused solopreneurship accelerator with seed funding and AI training support.
Apr 21 AI-first deployment Positive -2.2% EZE Cloud Consulting completed AI-first deployment of Workday HCM and Financial Management.
Apr 16 AI rewards launch Positive +0.6% Launched AI-powered recognition and rewards solution with Achievers integrated into Workday HCM.
Pattern Detected

Recent AI-related headlines have produced mostly modest price reactions, with a mix of aligned and divergent moves versus generally positive AI narratives.

Recent Company History

Over the past few months, Workday has maintained a steady cadence of AI-focused announcements. Recent AI items include Adaptive Decision Intelligence, research on AI and workplace connection, community-focused AI accelerator programs, and AI-driven recognition and rewards offerings. Price reactions to these AI updates have generally been modest, with a mix of small gains and declines. Today’s Agent Passport announcement extends this pattern of expanding the AI and agentic security stack on top of Workday’s core HR and finance platforms.

Historical Comparison

-0.5% avg move · In the past few months, Workday has released multiple AI-tagged updates averaging a -0.52% move. Tod...
AI
-0.5%
Average Historical Move AI

In the past few months, Workday has released multiple AI-tagged updates averaging a -0.52% move. Today’s Agent Passport AI security announcement fits this ongoing AI platform expansion theme.

AI news has progressed from engagement and recognition tools to planning intelligence, research on AI’s workplace impact, and ecosystem/accelerator programs, now extending into agent security and governance.

Regulatory & Risk Context

Active S-3 Shelf
Shelf Active
Active S-3 Shelf Registration 2026-05-29

Workday has an effective Form S-3ASR shelf dated May 29, 2026, registering an unspecified amount of various securities with no stated aggregate limit. Specific terms and sizes would be defined in future prospectus supplements as offerings are launched.

Market Pulse Summary

The stock moved -5.3% in the session following this news. A negative reaction despite a high-profile...
Analysis

The stock moved -5.3% in the session following this news. A negative reaction despite a high-profile AI security launch would fit Workday’s mixed history around AI news, where some positive announcements saw declines. With an effective S-3ASR shelf and moderate short interest at 13.34%, concerns could center on potential future issuance or profit-taking after prior AI-driven gains. Historical AI headlines often produced modest moves, so a sharp selloff would stand out against that backdrop.

Key Terms

owasp llm top 10, nist ai rmf, mitre atlas, prompt injection, +4 more
8 terms
owasp llm top 10 technical
"Agent Passport Measures Every Agent Against Industry Standards Including OWASP LLM Top 10, NIST AI RMF..."
A concise, expert-backed list of the most important security, safety and privacy risks associated with large language models (LLMs), produced to help builders and reviewers spot and fix problems. Think of it as a building inspection checklist for AI: it highlights common failure modes—like data leaks, poisoned training, or manipulative outputs—that can lead to legal trouble, customer harm, or product recalls, so investors can gauge operational, regulatory and reputational risk.
nist ai rmf regulatory
"Agent Passport Measures Every Agent Against Industry Standards Including OWASP LLM Top 10, NIST AI RMF, and MITRE ATLAS..."
NIST AI RMF is a guideline from the U.S. standards agency that helps organizations identify, assess and manage risks from artificial intelligence systems, like a safety checklist for new machines. Investors care because it influences how companies design, test and disclose AI products and controls—affecting legal exposure, reputation and the reliability of AI-driven revenue or cost savings, much like a quality inspection impacts a factory’s output and trust.
mitre atlas technical
"Agent Passport Measures Every Agent Against Industry Standards Including OWASP LLM Top 10, NIST AI RMF, and MITRE ATLAS..."
Mitre ATLAS is a publicly developed catalog that maps the ways artificial intelligence systems can be attacked or manipulated, similar to a cookbook that lists recipes for hacking AI. It matters to investors because it helps quantify cybersecurity and operational risk tied to AI products and services, informing evaluations of a company’s defenses, potential liability, regulatory exposure, and the likely costs of strengthening or insuring AI systems.
prompt injection technical
"tested against the most serious risks before it goes into production, including prompt injection, jailbreak and goal hijacking..."
A prompt injection is a deliberate attempt to trick an AI system by inserting misleading or malicious instructions into the text it reads, causing the system to behave in unintended ways or reveal sensitive information. Like slipping a fake note into a stack of instructions, it matters to investors because it can lead to data breaches, regulatory breaches, faulty decisions, reputational damage, and unexpected costs for companies that rely on AI-driven tools.
jailbreak technical
"tested against the most serious risks before it goes into production, including prompt injection, jailbreak and goal hijacking..."
A jailbreak is the act of removing or bypassing built‑in software restrictions on a device or platform so users can run unofficial apps, change settings, or access hidden features. For investors it matters because jailbreaks can alter product security, change how a company earns money from its app ecosystem or service contracts, and invite regulatory or legal responses—similar to removing a manufacturer’s seal on a tool and changing who controls how it’s used.
goal hijacking technical
"tested against the most serious risks before it goes into production, including prompt injection, jailbreak and goal hijacking..."
Goal hijacking is when a person, team, or automated system shifts focus from an intended long-term objective to a competing short-term reward or distraction, often because that reward is easier, more visible, or immediately reinforced. For investors this matters because it can lead managers or algorithms to pursue quick gains, boost short-term metrics, or cut corners in ways that undermine sustainable profits, increase risk, or trigger regulatory problems — like a driver swerving toward a bright billboard and missing the intended exit.
system prompt extraction technical
"including prompt injection, jailbreak and goal hijacking, system prompt extraction, leaks of employee data..."
System prompt extraction is the act of uncovering or retrieving the hidden instructions that guide an AI assistant’s behavior—those internal directions are normally not visible to users. For investors this matters because exposed prompts can reveal sensitive business rules, proprietary strategies or security weaknesses, similar to finding a company’s locked playbook, and that leakage can lead to reputational damage, regulatory scrutiny, or financial loss.
data leakage technical
"protect them at runtime against prompt injection, data leakage, jailbreaks and unsafe actions."
Data leakage is the accidental or unauthorized release of confidential, non-public information—such as financial results, trade secrets, or patient records—outside the organization that owns it. For investors it matters because leaked information can move a stock price before official disclosure, create legal and regulatory risk, and damage trust in management, much like an exam answer sheet shared early changes how others act on the information.

AI-generated analysis. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google

Agent Passport Measures Every Agent Against Industry Standards Including OWASP LLM Top 10, NIST AI RMF, and MITRE ATLAS

Cisco Joins as Launch Partner to Independently Test AI Agents in Workday Using Cisco AI Defense

LAS VEGAS, June 2, 2026 /PRNewswire/ -- Workday DevCon — Workday, Inc. (NASDAQ: WDAY), the enterprise AI platform for HR, finance, and IT, today announced Agent Passport, which tests and verifies every AI agent, Workday-built or third-party, before it goes into production, and continuously monitors it after. Every attestation is tied to a public industry standard, such as OWASP LLM Top 10, NIST AI RMF, and MITRE ATLAS, so security teams have a signed, auditable record of what each agent has been tested for and who did the testing.

Agent Passport gives companies a verified record that every agent has been tested against the most serious risks before it goes into production, including prompt injection, jailbreak and goal hijacking, system prompt extraction, leaks of employee data, and unsafe outputs. Each test result is tied to a public standard and signed by the partner that performed it, so the record is independent, auditable, and comparable across agents from any vendor.

When an agent attempts to execute a task, Agent Passport will monitor in real time and either allow, block, or route the action accordingly. If a problem is discovered, a single revocation can automatically stop, limit, or otherwise restrict affected agents based on company policy.

"AI agents are now doing the most sensitive work in the enterprise, from onboarding employees to processing payments, and one insecure agent can leak employee data, break compliance, and put the company on the front page for the wrong reasons," said Dean Arnold, vice president, AI Platform, Workday. "Agent Passport gives companies confidence that every agent has been independently tested and verified, and the power to shut any of them down across the business the moment something changes."

A Shared Standard, Built with Industry Leaders

Most platforms that offer agent security testing do it themselves, which means customers receive a "safe" label from the same vendor that built the agent. Workday has built extensive trust with customers with its broad portfolio of AI solutions for HR and finance. The company is building on that trust through open standards and partnership with leading vendors in agentic security and regulatory compliance, so the testing is independent and open, and the results are comparable across agents from any vendor.

Each agent's record has three layers. The first covers the broad areas of trust that Workday defines and keeps current, such as protection against attacks, safe behavior at runtime, and human oversight. The second is a set of specific, testable claims tied to public standards, like resistance to known attack techniques. The third is the signed results from the partner that performed the testing, issued by verified, trusted attestors starting with Cisco.

Because every check is tied to a public standard, security teams can compare agents from different vendors on the same terms for the first time. If two agents carry the same check from two different partners, companies know they were held to the same bar.

Independent Attestations from Industry Leaders in Agentic Security

Cisco is the launch partner for Agent Passport, bringing Cisco AI Defense to independently test AI agents running in Workday against leading security standards before deployment and continuously protect them at runtime against prompt injection, data leakage, jailbreaks and unsafe actions.

Cisco AI Defense confirms the agent resists attempts to override its instructions, keeps its own instructions from being exposed, protects sensitive employee information from leaking, and blocks harmful or policy-violating responses before they reach a user. These validations are important for any agent, but are non-negotiable for agents operating on payroll, benefits, and financial data.

"Agents are going to be everywhere in the enterprise, and that only works if security teams have a clear, signed record of what each one has been tested for," said DJ Sampath, senior vice president and general manager, AI Software and Platform, Cisco. "Cisco AI Defense was built for exactly this kind of validation, and we're excited to partner with Workday to secure the agentic workforce."

Availability

Agent Passport will be available to early access customers in the second half of 2026, and general availability is projected before the end of 2026. The Workday and Cisco partnership is active today, with joint capabilities rolling out over coming quarters.

For More Information

  • Discover how Workday and Cisco are partnering to define enterprise agentic security.
  • Read how Workday Build is now agent-ready, empowering developers to build, connect, and verify AI agents for HR, finance, and IT.
  • Learn how the latest expansions to Workday Data Cloud allow developers to securely bring live HR and finance data into their existing AI, analytics, and applications without rebuilding data pipelines.
  • Explore the three paths to build AI apps and agents with Workday, without giving up control or safety.

About Workday

Workday operates at the heart of the enterprise – HR, finance, and IT – where the margin for error is effectively zero. By tightly coupling AI with the context, guardrails, and trusted processes that run the business, Workday goes beyond AI that assists work to agents that do the work and drive measurable outcomes. More than 11,500 organizations worldwide, including more than 65% of the Fortune 500, trust Workday to deliver. For more information about Workday, visit workday.com.

© 2026 Workday, Inc. All rights reserved. Workday and the Workday logo are trademarks of Workday, Inc. All other brand and product names are trademarks or registered trademarks of their respective holders.

Forward-Looking Statements
This press release contains forward-looking statements including, among other things, statements regarding Workday's plans, beliefs, and expectations. These forward-looking statements are based only on currently available information and our current beliefs, expectations, and assumptions. Because forward-looking statements relate to the future, they are subject to inherent risks, uncertainties, assumptions, and changes in circumstances that are difficult to predict and many of which are outside of our control. If the risks materialize, assumptions prove incorrect, or we experience unexpected changes in circumstances, actual results could differ materially from the results implied by these forward-looking statements, and therefore you should not rely on any forward-looking statements. Risks include, but are not limited to, risks described in our filings with the Securities and Exchange Commission ("SEC"), including our most recent report on Form 10-Q or Form 10-K and other reports that we have filed and will file with the SEC from time to time, which could cause actual results to vary from expectations. Workday assumes no obligation to, and does not currently intend to, update any such forward-looking statements after the date of this release, except as required by law.

Any unreleased services, features, or functions referenced in this document, our website, or other press releases or public statements that are not currently available are subject to change at Workday's discretion and may not be delivered as planned or at all. Customers who purchase Workday services should make their purchase decisions based upon services, features, and functions that are currently available.

 

Workday

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/workday-launches-agent-passport-to-test-verify-and-continuously-monitor-every-ai-agent-in-the-enterprise-302787979.html

SOURCE Workday Inc.

FAQ

What is Workday Agent Passport and how does it improve AI agent security for WDAY customers?

Workday Agent Passport is a system to test, verify, and continuously monitor AI agents before and after deployment. It ties each test to public standards, helping security teams document defenses against prompt injection, jailbreaks, data leakage, and unsafe outputs across Workday and third-party agents.

How does Agent Passport for WDAY use OWASP LLM Top 10, NIST AI RMF, and MITRE ATLAS?

Agent Passport maps each attestation to public standards such as OWASP LLM Top 10, NIST AI RMF, and MITRE ATLAS. According to Workday, this lets security teams compare agents from any vendor on the same criteria and maintain auditable, signed security records.

What role does Cisco AI Defense play in Workday (WDAY) Agent Passport?

Cisco is the launch partner, using Cisco AI Defense to independently test AI agents running in Workday. According to Workday, Cisco AI Defense validates resistance to prompt injection, instruction override, system prompt exposure, data leakage, and harmful or policy-violating responses at runtime.

When will Workday (WDAY) Agent Passport be available to enterprise customers?

Agent Passport is planned for early access in the second half of 2026, with general availability projected before the end of 2026. According to Workday, the partnership with Cisco is active now, with joint capabilities rolling out over coming quarters.

How does Workday Agent Passport monitor and control AI agent actions in real time?

When an AI agent attempts to execute a task, Agent Passport evaluates the action and can allow, block, or route it. According to Workday, a single revocation can automatically stop or limit affected agents based on company policy across the enterprise.

What are the three layers of attestation in Workday (WDAY) Agent Passport?

Agent Passport records three layers: high-level trust areas defined by Workday, specific testable claims tied to public standards, and signed results from independent partners. According to Workday, verified attestors like Cisco issue these results, creating comparable, auditable records across vendors.

How does Agent Passport help Workday (WDAY) customers secure HR, payroll, and finance AI agents?

Agent Passport focuses on agents handling sensitive HR, payroll, benefits, and financial data, testing them against key security risks. According to Workday, Cisco AI Defense helps ensure such agents resist instruction overrides, protect sensitive information, and block harmful or policy-violating outputs before users see them.