Arcjet has released a new agent runtime security product designed to provide enterprise engineering and compliance teams with governance controls and comprehensive audit trails for production AI agents.
As autonomous AI agents transition from chat interfaces into live enterprise environments to interact with databases, handle customer support tickets, process refunds, and execute API calls, organizations face expanded security risks. Because these multi-step workflows often run across multiple external and internal systems, security teams require continuous visibility to monitor agent identities, validate specific actions before execution, and reconstruct sequences during post-incident investigations.
The newly launched platform centers on three core functional pillars: observation, enforcement, and auditing. For observability, Arcjet integrates natively with OpenTelemetry tooling and the Claude Compliance API to ingest real-time agent execution data without requiring application code changes or separate deployed agents. This capability correlates actions across disparate sessions into unified workflows, mapping out complete inventories of active agents and their granular operational steps.
To mitigate runtime risks, Arcjet applies deterministic security policies governed by Rego and Open Policy Agent. Organizations can deploy immutable, versioned policies via an application programming interface, command-line interface, model context protocol, or web user interface to block prompt injections, prevent sensitive information leaks, enforce rate limits, and redact personally identifiable information. These policies are evaluated before and after execution calls to language models, APIs, and databases, allowing applications to block malicious operations or require manual intervention dynamically.
The platform also features native integrations with widely adopted agent frameworks, including LangChain, LangFuse, Strands, Mastra, Microsoft Agent Framework, Claude Agents SDK, Claude Managed Agents, and OpenAI Agents SDK. These integrations enable deep contextual tracking of tool parameters, session metadata, prompts, and deterministic security decisions throughout the operational lifecycle.
“Agents are now taking real actions inside production systems, which means security teams need to know which agents are operating and what they have done, and apply controls at machine speed,” said David Mytton, CEO at Arcjet. “A risky outcome can develop across a series of steps that look perfectly reasonable on their own. Arcjet connects those steps and gives teams policy controls to detect them.”
Finally, the audit module collects detailed execution contexts to generate compliance evidence and support forensic security reviews. By preserving correlated traces of inputs, system outputs, and policy evaluations, Arcjet gives enterprises the deterministic proof required to satisfy strict regulatory standards and internal audits.