Zero Day Room
Live
Threats

Akeyless launches real-time control layer for AI agents

Akeyless has released Agentic Runtime Authority, a real-time enforcement layer that blocks unauthorized AI agent actions in production environments before

Akeyless has released Agentic Runtime Authority, a real-time enforcement layer that blocks unauthorized AI agent actions...

Akeyless has announced the general availability of its Agentic Runtime Authority, a real-time identity control layer designed to govern the actions of AI agents in live production systems. The new product works on top of the company's existing SecretlessAI credential protection layer to enforce intent-based access control, restricting what agents can do once they have access to enterprise resources.

Modern AI agents are moving beyond simple question-answering to autonomously access databases, execute workflows, and make decisions within operational environments. According to the company, traditional access controls can authorize an agent's entry into a system but cannot verify the legitimacy of every subsequent action it takes. For autonomous agents that may act unpredictably or be manipulated through prompt injection, the potential impact can escalate at machine speed, as highlighted by the July 2026 Hugging Face incident. Runtime Authority aims to close this gap by evaluating agent actions in real time and blocking policy violations before execution.

Runtime Authority enforces dynamic policy

Runtime Authority layers intent enforcement on top of traditional role- and attribute-based controls. It evaluates an agent's objectives and actions in real time, blocking activity that violates policy or exceeds its assigned task before it runs. Akeyless describes this as a powerful "kill switch" that can revoke an agent's authority to act in real-time when issues arise. For instance, an agent instructed to summarize sales data would be prevented from deleting a database or exfiltrating large volumes of data, even if its underlying permissions would technically allow such actions.

Securing the path from credential to action

The control layer builds upon Akeyless's SecretlessAI, which addresses the credential problem by keeping passwords, tokens, and keys out of AI agents entirely. Instead of providing an agent with credentials it could store or leak, Akeyless brokers access through its Gateway, provisioning a short-lived identity directly on the target system. This approach is designed to work even with legacy and on-premises systems that use traditional identity methods. A compromised agent would theoretically have no credentials to steal. Runtime Authority uses this same brokered access path to add control over the agent's actions once connected, aiming to prevent risky operations before they cause damage.

Governance and visibility for security teams

Across both the credential and action layers, Akeyless provides security teams with visibility and control to monitor, investigate, and respond to agent activity. Every action is logged and traced back to the human, application, or agent that triggered it. The general availability release introduces new operational controls for production deployments. An Agentic Access Dashboard offers a live view of active agent sessions, including the ability to terminate a session immediately. New investigation capabilities show why a session was blocked, and enriched security events can be forwarded to tools like Splunk, Datadog, and Microsoft Sentinel for centralized monitoring.

Expanded integrations with AI platforms

With the launch, Akeyless is expanding its AI agent ecosystem with new integrations. The company has added support for Claude Enterprise, OpenAI Codex, and Amazon Bedrock AgentCore. These join existing support for a broad range of other AI models, frameworks, and developer environments.

This expansion is intended to give organizations a consistent method to apply SecretlessAI credential protection and Runtime Authority controls across the diverse mix of AI platforms and tools used enterprise-wide. Agentic Runtime Authority operates within the broader Akeyless Identity Security Platform, which the company says already secures over 220 billion machine identity interactions for Fortune 500 organizations. Akeyless CEO Oded Hareven stated that the company builds alongside its customers as trusted partners. "Humans and machines will continue interacting with critical systems," Hareven said, "so having a central point of access control and attribution only matters more over time."

Topics

#Threats

Related coverage

More from Threats