AI News Nuggets

Enterprise AI becomes more governable when model calls, prompt defenses, and agent API permissions are enforced in the live request path

Fastly has introduced AI Runtime Control, AI Firewall, and API Security capabilities intended to centralize model routing, budget and rate controls, prompt-attack inspection, and policy enforcement for agent calls to enterprise APIs.

Editorial read

This edition collects 1 notes across 1 topic areas and 1 source. Start with Runtime AI controls are most useful when the same request path can govern model choice, prompt risk, spend, and what agents may do through enterprise APIs to get the week's main practical signal before scanning the remaining links.

Edition signal

The September 23 signal is that AI governance is moving from product-specific settings toward runtime policy in the request path

Fastly's launch is one vendor implementation, not a universal architecture. Its operational pattern is useful, though: keep provider credentials behind an intermediary; make model routing, rate limits, spend controls, and failover observable; inspect hostile prompts before they reach a model; and enforce API contracts when an agent acts on enterprise systems. Teams should still validate coverage, false-positive handling, data residency, and the identity context carried into each decision rather than treating a gateway as a complete governance programme.

SecurityAgentsInfrastructure