Arcjet Unveils Groundbreaking Agent Runtime Security for AI Production Environments
Arcjet Launches Agent Runtime Security for Production AI Agents
Arcjet, the innovative platform focused on security within AI code, has unveiled its latest offering: Agent Runtime Security. This new product aims to assist engineering teams in securing the AI agents they develop by providing comprehensive oversight, governance capabilities, and compliance evidence critical for their operations. Given the complexity of modern AI agents, which are now infiltrating production workflows far beyond simple chat interfaces, the need for robust security measures has never been more urgent.
AI agents have evolved significantly; they now handle essential tasks such as reading and writing to databases, managing support tickets, processing refunds, and executing other user-specific actions. These operations can commence through various channels, including emails, chat messages, or code commits, enabling agents to function autonomously across a multitude of systems. As the tasks of these agents grow in complexity, security teams are faced with three pivotal questions that span the entire sequence of actions: Which agents are operational? Should specific actions be permitted? And what occurrences are unfolding, and why?
Arcjet's Agent Runtime Security addresses these inquiries through a trifecta of functionalities: observability, enforcement, and audit capabilities. This allows teams to not only discover agent activities but also maintain control over actions before and after execution while ensuring relevant evidence is preserved for future security assessments and compliance checks.
Observability: Discover All Your Agents
The heart of the platform's functionality revolves around the observe feature. Arcjet simplifies the process of tracking agent activity by allowing security personnel to ingest real-time data without making any changes to existing application code. By utilizing established OpenTelemetry tools, teams can efficiently channel agent activity data straight to Arcjet for immediate visualization and analysis. For platforms utilizing Claude, Arcjet can seamlessly pull activity through the Claude Compliance API.
Arcjet highlights agent identity and inventory, creating a comprehensive view of all active agents and their respective activities. This functionality enables teams to track sequences of actions that agents undertake, turning what could be disparate events into cohesive workflows.
Enforcement: Apply Controls to Safeguard Actions
Following the discovery of agent activities, the next crucial step is enforcement. Arcjet empowers security teams to establish controls that help prevent unauthorized prompt injections, protect sensitive data from leaks, and enforce rate limits. By applying deterministic security policies to inputs and outputs, Arcjet asserts its integral role in safeguarding the actions undertaken by AI agents.
Whether through direct application or via APIs, teams can enforce policies that detail what agents are allowed to do. For instance, scenarios could involve restricting recipients in an email tool, capping refund values, or limiting API calls to verified URLs. The system effectively checks compliance with these policies before proceeding with actions, thereby allowing applications to halt operations, seek human intervention, or provide detailed feedback to agents.
Audit: Providing Evidence and Compliance
Lastly, the audit capabilities implemented by Arcjet ensure that every executed action builds a defensible narrative. This process grants teams the ability to reconstruct incidents, clarify policy decision motives, and compile evidence crucial for compliance audits. The structured collection of execution data helps monitor actions and guidance decisions, providing a transparent trail for security reviews.
As stated by David Mytton, CEO of Arcjet, “With agents now taking substantial actions within production systems, it is paramount that security teams are informed about which agents are functioning and the actions they have undertaken.” He emphasizes that being able to connect disparate events helps identify risks spanning multiple stages of workflows and apply necessary controls at machine speed.
With the introduction of Agent Runtime Security, Arcjet not only provides a fortified approach to AI agent security but also enhances the ability of teams to govern AI operations effectively, allowing businesses to leverage technology while ensuring stringent security standards.