Security teams have spent the last year bolting guardrails onto their AI agents. A recent attack shows why that is not enough on its own, and it points at a cleaner way to think about the problem.
AI has moved from something employees experiment with to something that runs inside core business systems. Models draft and review work, and agents, meaning software that can take actions on a person’s behalf such as querying a database or updating a record, now sit inside everyday workflows. For a CIO or CISO, that shift raises a familiar question in a new setting: how do you give the business the speed it wants from AI while keeping the control the enterprise requires? As we set out in our view of the AI control plane for the agentic era, the answer starts with routing AI through a place where policy can be applied consistently.
Scope. Enforce. The Two Primitives of Runtime Governance In June, we named the mandate: Governance by Design. We said the fix has two moving parts — embedding controls into the agent’s action surface, and enforcing them at runtime. That was correct. It was also missing something a CIO or AI leader could say out loud in a meeting.
Autonomous agents are becoming the fastest-growing identity class in the enterprise. Yet most organizations cannot inventory them, govern them, explain their decisions, or even prove who performed an action. The next decade of enterprise security will not be built around users or applications it will be built around trust, runtime identity, and continuous authorization for autonomous systems.
More and more engineering teams have made Claude Code, Anthropic’s command-line coding assistant, a daily part of how they ship software. Anthropic just shipped the Claude Apps Gateway, a central control point for teams running Claude Code. Here is what it does, and how LangGuard already supports it out of the box.