Arcjet Enhances AI Agent Security with Advanced Controls and Audit Trails

www.news4hackers.com-arcjet-enhances-ai-agent-security-with-advanced-controls-and-audit-trails-arcjet-enhances-ai-agent-security-with-advanced-controls-and-audit-trails

Arcjet has introduced a new product called agent runtime security, designed to assist engineering teams in securing AI agents during development and provide security teams with necessary governance and compliance evidence.

Introduction

Arcjet has introduced a new product called agent runtime security, designed to assist engineering teams in securing AI agents during development and provide security teams with necessary governance and compliance evidence. The solution offers observability, enforcement, and audit capabilities across agent workflows, enabling teams to identify active agents, regulate their actions, and analyze outcomes and reasons behind them. AI agents are transitioning from chat interfaces to production workflows, where they interact with databases, respond to support tickets, process refunds, invoke tools and APIs, and perform other user-directed tasks. These workflows can originate from chat interfaces, text messages, code commits, or other sources. As agents handle extended workflows, security teams must address three critical questions: which agents are active, whether specific actions should be permitted, and what occurred and why.

Observe

Arcjet’s agent runtime security addresses these concerns through observe, enforce, and audit functionalities. Teams can track agent activity and link actions across sessions, implement deterministic security policies before and after interactions with large language models, tools, databases, and APIs, and retain execution context for security reviews and compliance. Security teams now require visibility into agents operating within production systems, including their activities and controls applied at machine speed, according to David Mytton, CEO of Arcjet. Risky outcomes may emerge from sequences of steps that individually appear acceptable. Arcjet connects these steps and provides policy controls to detect such scenarios.

Security teams now require visibility into agents operating within production systems, including their activities and controls applied at machine speed, according to David Mytton, CEO of Arcjet.

Enforce

The product focuses on three core components for securing agents in production: observe, enforce, and audit. Observe: Discover all agents Arcjet supports ingestion of agent activity without requiring application code changes or additional agent deployments. Platform and security teams can leverage existing OpenTelemetry observability tools to send activity directly to Arcjet for real-time visualization and analysis. For teams using Claude, Arcjet can also access activity data via the Claude Compliance API. Arcjet correlates activity across sessions, allowing teams to view an agent’s sequence of actions as a unified workflow rather than isolated events. Agent identity and inventory are part of this visibility, providing teams with an inventory of agents and applications operating within their environment. Activity and individual runs are linked to each agent, enabling step-by-step inspection of actions and security decisions.

Audit

Enforce: Apply controls before and after every action Once teams can monitor agents and their activity across sessions, Arcjet allows security teams to define controls for prompt injection detection, protection against PII and sensitive information leaks, and other policy-based restrictions. Policies can limit agent actions, such as restricting email recipients or attachments in tools, setting refund value boundaries, or limiting web fetch tools to trusted API URLs. Arcjet provides decisions to applications before actions execute, enabling them to halt operations, request human approval, or return explanations to agents. These controls apply before and after interactions with LLMs, tools, databases, and APIs, mitigating risks before consequential actions and verifying results before workflows proceed. Arcjet integrates natively with major agent frameworks, including Claude Agents SDK, Claude Managed Agents, OpenAI Agents SDK, LangChain, LangFuse, Strands, Mastra, and Microsoft’s Agent Framework. This in-code context allows Arcjet to track recorded actions, their inputs, and policy decisions across workflows.

Audit: Evidence and proof of compliance Arcjet collects execution context to enable teams to reconstruct events, understand policy decisions, and provide compliance evidence. Correlated traces preserve actions, inputs, security decisions, and policy evaluations throughout workflows.


Blog Image

About Author

en_USEnglish