Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI gateway governance for agents: are tool calls and runtimes covered?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18936
Topic starter  

TL;DR: Roughly 30% of organisations have integrated AI agents into workflows, about 61% expect agents to handle half their job within three years, and roughly half lack clear governance for teams that include people and AI, according to TruFoundry. The editorial point is that agent governance now has to cover tool access, runtime control, and observable execution, because agents act rather than recommend.

NHIMG editorial — based on content published by TruFoundry: BCG Says Strategy Matters More Than Tools - Part 2, from agent adoption to governed tools and runtimes

By the numbers:

Questions worth separating out

Q: How should security teams govern AI agents that can access enterprise systems?

A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.

Q: Why do AI agents create governance problems that normal access reviews miss?

A: AI agents can read, copy, transform, and re-share data after the original access decision, so a static review of entitlements does not capture downstream impact.

Q: What breaks when credentials are embedded in agent configurations?

A: Embedded credentials break point-of-use governance.

Practitioner guidance

  • Define agent identities explicitly Create a separate identity class for agents, then map each one to an owner, purpose, tool scope, and expiry condition before production use.
  • Centralise tool authentication at the gateway Keep credentials out of prompts and agent definitions, and force all external tool calls through a gateway that handles delegation, policy, and logging.
  • Bind every agent to a trusted tool registry Allow agents to call only registered tools and approved servers, then review registry changes as access-control changes rather than as feature updates.

What's in the full article

TruFoundry's full article covers the operational detail this post intentionally leaves for the source:

  • Documented control mappings for the AI Gateway and Agent Harness, including how each surface governs a different part of the agent workflow
  • The full section-by-section comparison between BCG's survey findings and the runtime controls TruFoundry uses to interpret them
  • Implementation detail on sandboxing, approval gates, and per-step tracing for managed agent execution
  • The article's cited documentation references for MCP Gateway policy, delegation, and Skills Registry controls

👉 Read TruFoundry's analysis of BCG's agent governance gap and AI gateway controls →

AI gateway governance for agents: are tool calls and runtimes covered?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18527
 

Agent governance is now an identity problem, not just an AI ops problem. Once an agent can act across tools, the relevant control surface becomes delegation, not output quality. That shifts responsibility toward IAM, PAM, and NHI governance because the agent must be constrained as an executable identity. The practical conclusion is that teams need one governance model for humans, service accounts, and agents when those identities can all initiate work.

A few things that frame the scale:

  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation, according to the 2026 Infrastructure Identity Survey.
  • Only 44% of organisations have implemented any policies to govern AI agents, even though 92% say governing them is critical to enterprise security.

A question worth separating out:

Q: How should organisations decide when to widen an agent's access?

A: They should widen access only after the team has reviewed traces, approvals, and actual outcomes for the current scope. Expansion should be based on evidence that the agent stayed within bounds and produced reliable work, not on enthusiasm for the use case. That keeps authority growth tied to observed behaviour.

👉 Read our full editorial: AI gateway governance is widening to cover agent tools and runtimes



   
ReplyQuote
Share: