Skip to main content
The Quantum Dispatch
Back to Home
Cover illustration for Fastly AI Firewall and Runtime Control Target Agent Traffic

Fastly AI Firewall and Runtime Control Target Agent Traffic

Fastly's new AI Firewall, AI Runtime Control and API Security tools ship today, as machine-generated traffic passes 50% of the requests on its network.

Kai Aegis
Kai Aegis★Sep 21, 2026★4 min read

Guardrails at the Edge for AI Traffic

Fastly launched three security products on September 21 aimed at a problem most organizations running AI in production now share: model calls and agent traffic are flowing through their systems faster than their controls were designed to handle. The new tools, AI Firewall, AI Runtime Control and API Security, are available now and run on Fastly's edge network.

  • AI Runtime Control: routes model calls from public and self-hosted providers through a single endpoint, with virtual keys, token-spend visibility, rate limits, budgets and failover
  • AI Firewall: evaluates prompts in real time at the edge to block LLM attacks, including prompt injection
  • API Security: enforces API contracts so agents cannot call operations they are not supposed to
  • The traffic shift: Fastly says machine-generated traffic passed 50% of its network in July and August 2026, and AI traffic grew 6.5 times faster than human traffic from January to May

Why Put AI Controls at the Edge?

The simplest way to understand the launch is to follow a single request. An agent inside your company decides to call a model. Without a central gateway, that call goes straight to a provider using an API key stored somewhere in the agent's environment. Nobody sees the token spend until the invoice arrives, and nothing checks whether the prompt carries injected instructions from a malicious web page the agent just read.

AI Runtime Control puts one endpoint in the middle. Agents authenticate with virtual keys, so the real provider credentials never sit in agent code, which is exactly the class of leak we examined in our look at keeping MCP server credentials out of Git. The gateway can enforce rate limits and budgets and fail over to another provider if one goes down. Fastly cites McKinsey data showing that 93% of organizations exceed their AI budgets, so spend control is not a side feature.

How Does the AI Firewall Handle Prompt Injection?

Prompt injection works by hiding instructions in content the model will read, such as a web page, a document or a tool result. AI Firewall inspects prompts before they reach the model and blocks those that match attack patterns. No filter catches everything, and defenders should treat this as one layer among several: least-privilege tool access, output validation and human review for high-impact actions still matter. But stopping the obvious attacks cheaply at the edge takes a lot of noise off everything behind it.

What Does API Security Add for Agents?

Agents do not read documentation the way developers do. They infer which endpoints exist and sometimes guess. API Security enforces the published contract, so an agent that tries an unsupported operation or steps outside its allowed parameters is stopped at the boundary. That is a sensible complement to agent identity work like Postman Passport's keyless API access, which controls who the agent is; contract enforcement controls what it can do.

Where Does This Fit in the Stack?

Fastly positions the three tools alongside its existing Bot Management, DDoS protection, API Discovery and Next-Gen WAF. Chief Product Officer Kelly Shortridge framed the goal as giving enterprises "control in production, at runtime," which captures the broader industry direction well. Like last week's Arcjet agent runtime security launch, the focus has moved from making models behave to instrumenting where they touch real systems.

For teams starting out, the practical first step is visibility: route model calls through one gateway and see what your agents are actually doing. More defensive tooling is covered in our AI security coverage.

Sources: Help Net Security — September 21, 2026; Fastly via Business Wire — September 21, 2026; RuntimeWire — September 21, 2026.

More Ai Security Stories