AI Agent Policies Need Runtime Enforcement at the API Gateway
Sam, CTO at Gravitee, argues that prompts and policy files cannot govern what an AI agent does once it can reach an API: enforcement has to sit in the infrastructure between the agent and the services it can call. In a live hotel-booking demonstration, he showed a gateway denying destructive actions and bulk access to guest data, while also limiting repeated requests, caching similar questions and rejecting oversized prompts before they reached a model.
AI Engineer·Oct 10, 2026·7 min read