TL;DR: As enterprises move AI agents from experimentation to production, runtime threats now include sensitive data leakage, secret exposure, jailbreak attempts, and tool misuse, according to Zenity. Prompt-level and post-execution controls miss the point because agent decisions and chained actions unfold inside the execution path, where prevention has to happen in real time.
Editorial analysis by NHI Mgmt Group, based on content published by Zenity: “Zenity Announces Availability of Inline Agent Runtime Security for Agents Built on Microsoft Foundry”.
Key questions
Q: What breaks when AI agents are not governed at runtime?
A: Without runtime governance, an agent can shift behaviour after provisioning and still execute actions that were never reviewed in context.
Q: Why do AI agents need runtime enforcement instead of relying only on upstream identity controls?
A: AI agents can decide and act dynamically inside the execution loop, so upstream authentication alone does not control every tool call or data request.
Q: What are the signs that agent authority is failing in production?
A: Look for long-lived tokens, shared credentials, missing approval logs, and audit trails that cannot attribute an action to the agent itself.
Practitioner guidance
- Define the execution path as the control boundary Map where agents actually run, where they call tools and where data can leave the session, then enforce policy at those points rather than only at the prompt or after execution.
- Classify every connected system the agent can reach Inventory enterprise resources such as databases, SaaS platforms, internal APIs and collaboration tools so each dependency is covered by a runtime access decision.
- Separate prompt safety from runtime authorisation Keep prompt screening and content policy checks, but do not treat them as substitutes for inline prevention when agents can chain actions or invoke tools.
Bottom line: AI agent security now depends on controls that operate during execution, because prompt-level and post-execution methods cannot reliably stop tool misuse or unsafe chaining in time.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Inline runtime enforcement is now the control plane that matters for AI agents. The article shows why prompt-time filtering and post-execution logging are both too early and too late for production agents. Once an agent can decide, chain and invoke tools inside a live session, the decisive governance question becomes whether unsafe action can be blocked before the next execution step. The practitioner implication is that runtime becomes the primary security boundary for agentic systems.
A few things that frame the scale:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How should organisations balance prompt filters and runtime controls for AI agents?
A: Use prompt filters to reduce obvious abuse, but treat runtime controls as the primary enforcement layer. Prompt screening cannot reliably manage tool misuse, chained actions or secret exposure once an agent is active. The right model is layered control, with inline prevention carrying the final decision authority.
👉 Read our full editorial: Runtime security for AI agents in Microsoft Foundry needs inline controls