Skip to main content
The Quantum Dispatch
Back to Home
Cover illustration for Arcjet Agent Runtime Security Adds Audit Trails

Arcjet Agent Runtime Security Adds Audit Trails

Arcjet's agent runtime security uses Open Policy Agent to enforce controls on AI agents and keep replayable audit evidence for compliance reviews.

Kai Aegis
Kai Aegis★Sep 20, 2026★6 min read

The Gap Between Building Agents and Running Them

There is a moment in every AI agent project where the thing stops being a demo. It starts writing to a database, answering a customer ticket, or moving money. At that point the interesting question changes from what can it do to what did it do, and most teams discover they cannot answer. Arcjet launched agent runtime security on September 17 aimed squarely at that gap — controls that sit in the code path of a running agent, and an audit record you can replay afterwards.

  • Three functions: observe what agents are doing, enforce policy on what they may do, and retain audit evidence of why each decision went the way it did
  • Policy engine: deterministic rules written in Rego and evaluated by Open Policy Agent, applied to tool calls, API requests and database operations
  • Controls shipped: prompt injection detection, PII and sensitive data leak prevention with redaction, bot and automation detection, and rate and quota limits
  • Availability: generally available now with a 15-day free trial, and native SDKs for JavaScript, Python and Go

Why Deterministic Policy Instead of a Model Guardrail?

This is the design decision worth examining. A large share of agent-safety tooling works by asking another model whether an action looks acceptable. That is flexible and it is also probabilistic — the same request can be allowed on Tuesday and blocked on Thursday, and neither outcome comes with an explanation an auditor will accept.

Arcjet's choice of Rego and Open Policy Agent points the other way. OPA is well-established infrastructure in Kubernetes and API authorisation, the policies are code, and the same input produces the same decision every time. For a compliance conversation that distinction is the whole conversation: a deterministic policy can be reviewed, version-controlled, diffed and tested before it ever runs. It does not replace model-based detection — prompt injection detection is inherently fuzzy — but it means the consequential allow-or-deny step has a stable answer.

The placement matters too. These controls live inside the application, in the agent's execution path, rather than at a network boundary. An agent calling an internal function never crosses a network perimeter, so a gateway cannot see it. In-code enforcement can.

What Does the Audit Trail Actually Capture?

Discovery works through OpenTelemetry ingestion or an integration with the Claude Compliance API, which means teams get an inventory of which agents are running before they try to govern them — a step that sounds trivial and is usually the hard part in an organisation where three teams have each shipped something.

From there, Arcjet builds correlated traces that group individual actions into sequences and preserve the inputs, the security decisions and the policy evaluations alongside them. The point of correlation is reconstruction: an audit question is rarely about one call, it is about what chain of steps led to an outcome. Storage is flexible — Arcjet's cloud, a single-tenant or private VPC deployment, or streaming out to whatever detection stack a team already runs — which is the right answer for anyone whose agents touch regulated data.

Framework coverage is broad enough to be practical: native integrations listed for the Claude Agents SDK and Claude Managed Agents, the OpenAI Agents SDK, LangChain, LangFuse, Strands, Mastra and Microsoft's Agent Framework.

Where Does This Fit in the Agent Security Stack?

It joins a category that has been filling in quickly and sensibly. We covered Codenotary's AgentMon 3 taking on agent runtime security and the Trace proposal for runtime attestation of agent behaviour earlier this year, and the through-line is consistent: the industry has largely stopped trying to make agents safe by prompting them better and started instrumenting the boundary where they touch real systems.

That is the right instinct. Identity, authorisation and audit are solved problems for human users and for services; agents have been running without the equivalent mostly because the tooling did not exist yet. Products like this are that tooling arriving. It is also a useful complement to hygiene work further upstream, like the hardcoded MCP credentials turning up in public repositories we looked at this week. More defensive tooling and responsible disclosure in our AI security coverage.

For teams with agents already in production, the practical first move is the cheap one: run discovery and find out how many agents you actually have. The enforcement conversation is much easier once that list exists.

Sources: Arcjet — September 17, 2026; Help Net Security — September 18, 2026; SiliconANGLE — September 17, 2026.

More Ai Security Stories