Agents Don't Read Your Policy Docs: Gravitee demos gateway-level AI governance
AI Engineer · youtube · 2026-10-11
At AI Engineer World's Fair 2026, Gravitee CTO Sam runs five live scenarios showing why agent governance belongs in the API gateway, not prompt instructions:
- Blocking destructive tool calls: the gateway stops a 'delete all bookings' request
- Stopping data exfiltration: an attempt to pull every guest's personal data is blocked
- Rate-limiting runaway agents: a buggy agent firing the same request 8 times gets throttled
- Semantic caching: repeated questions served from cache to cut token costs
- Oversized prompt rejection: blocked before reaching the LLM
Also covers agent observability, avoiding hyperscaler lock-in, trimming bloated MCP tool lists, and shadow AI on employee laptops. Core argument: agents can still call APIs no matter what rules you write in markdown — enforcement must happen at the gateway.
More from coding & agent
- Developer builds a Tesla Roadster entirely in code with Opus 5.5, rendered in Three.js — majidmanzarpour · 2026-10-11
- Matthew Berman shares a Codex prompt that pings him every 3 hours about forgotten projects — MatthewBerman · 2026-10-11
- GitSwarm paper: multi-agent swarm compounds inference in a shared Git repo, solves all 30 IMOProofBench problems — NandoDF · 2026-10-11
- Agents don't know if you've got permission — the two-sided safety problem — aparnadhinak · 2026-10-11
- Sharp observation: every agent assumes its human has infinite attention — msg · 2026-10-11
- Lead bots can spawn new sub-bots, no manual creation needed — nateliason · 2026-10-11