Skip to main content

Arcjet Launches Runtime Security Product for Production AI Agents

San Francisco – – September 19, 2026 -- Arcjet has launched agent runtime security, a new product designed to give engineering and security teams visibility and control over AI agents operating inside production systems. The platform targets agents that read and write to databases, process refunds, call APIs, and take autonomous actions across multiple systems on behalf of users.

Arcjet builds its product around three functions: observe, enforce, and audit

The observe layer lets teams ingest agent activity without changing application code, using existing OpenTelemetry tooling or, for Claude users, the Claude Compliance API. Arcjet connects actions across sessions into a single workflow view, capturing prompts, tool call parameters, session metadata, identity, and security decisions, and maintains an inventory of agents and applications running in a given environment.

Enforcement applies deterministic policies before and after agent actions

Security teams can define controls for prompt injection detection, PII leak prevention and redaction, bot detection, rate limits, and quota enforcement. Powered by Rego and Open Policy Agent, policies are versioned and immutable and can be created through Arcjet's web UI, API, CLI, or MCP without redeploying application code. Example controls include restricting email recipients or attachments, capping refund values, or limiting web-fetch tools to trusted API URLs. Arcjet returns a decision to the application before an action executes, allowing it to block the operation, request human approval, or return an explanation to the agent.

Arcjet has built native integrations with major agent frameworks, including Claude Agents SDK, Claude Managed Agents, OpenAI Agents SDK, LangChain, LangFuse, Strands, Mastra, and Microsoft's Agent Framework, allowing it to track recorded actions, inputs, and policy decisions across a workflow.

The audit layer preserves execution context for compliance reviews

Arcjet collects context from each execution so teams can reconstruct what happened, understand why a policy decision was made, and produce evidence for security reviews and compliance audits. Correlated traces preserve actions, inputs, security decisions, and policy evaluations across a workflow.

"Agents are now taking real actions inside production systems, which means security teams need to know which agents are operating and what they have done, and apply controls at machine speed," said David Mytton, CEO at Arcjet. He noted that a risky outcome can develop across a series of individually reasonable steps, and that connecting those steps is central to detecting risk.

Published by
fairsonline_team
Industries
Company
News Type