Application-Native vs Remote Security Policies: A Technical Guide
Compare application-native and code-native security rules with remote policies, including ownership, architecture, Arcjet, Datadog AI Guard, and Runlayer.
Read guideAI Security
Runtime controls, enforcement architectures, and operational guidance for production AI agents.
AI agent security governs what an agent may do while a production workflow is running. It extends beyond model output filtering because an unsafe outcome can emerge from a valid tool call, a compromised data source, a dangerous action sequence, or authority that is technically valid but inappropriate for the current task. Runtime protection evaluates identity, tool arguments, target resources, prior steps, sensitive data, and accumulated cost at boundaries where the application can still block or restrict an operation. Architecture matters because proxies, AI gateways, in-code checks, and supervisory agents observe different parts of the workflow and fail in different ways.
Read the runtime security guide first for the risks and control model. Follow with the architecture comparison to decide which checks belong in application code, a proxy, an AI gateway, or a supervisory security agent.
Compare application-native and code-native security rules with remote policies, including ownership, architecture, Arcjet, Datadog AI Guard, and Runlayer.
Read guideCompare in-code, proxy, AI gateway, and security-agent controls by visibility, enforcement, context, latency, failure modes, and threat coverage.
Read guideAI agent runtime security for unauthorized tool calls, prompt injection, sensitive data, automated abuse, action sequences, and production cost controls.
Read guide