Home/Resources/Agentic AI governance: the control has to reach the tool call
Resource

Agentic AI governance: the control has to reach the tool call

A document cannot refuse a live tool call. See where agentic AI runtime control sits, what it must do and how to tell enforcement from reporting.

What changes when an agent acts instead of answering

A chat assistant produces text and a person decides what to do with it. An agent decides and then does it, and the doing lands somewhere with consequences: a ticket updated, an email sent, a payment released. The output stopped being the unit of risk somewhere in that transition. The tool call took its place, and a tool call happens mid-run, on arguments the model assembled a second earlier, in a sequence nobody wrote down in advance.

A document cannot refuse a call

Policy written as a document governs the design of an agent. It has nothing to say to that agent at 2am, halfway through a run, about to call a tool with an argument nobody anticipated. The register, the risk assessment, the approved use case: all worth having, none of them in the execution path. Something has to be in the execution path, and it has to be able to say no to a specific call rather than to a category of behaviour.

Sitting at the tool call is necessary, and on its own it is not enough

If the agent also holds an API key, it has a second route, and your control becomes advice the first time the model works out that the direct path is quicker. The property that makes runtime control real is that the agent has nothing to act with. It proposes. Something else holds the credential, reads the resolved arguments, decides, then acts. That component ends up holding the only complete account of what was attempted, which is how evidence turns into a by-product of enforcement instead of a separate reporting project.

Prompt injection is why this is not optional

OWASP's Top 10 for Agentic Applications 2026, published on 9 December 2025, was assembled from documented 2025 incidents rather than from thought experiments. EchoLeak, CVE-2025-32711, sits in it as a zero-click data exfiltration route. The value of a real CVE in this argument is that it settles the mechanism: instruction and data arrive on the same channel, so an agent reading a document, a ticket or a web page is reading something an attacker may have authored. You cannot instruct your way out of that. The durable defence constrains what the agent may do whatever it was told, enforced outside the model. Excessive Agency, LLM06 in the 2025 LLM Top 10, is the same finding written up as a design fault.

The tool surface grew faster than the controls did

Wiz reported in 2026 that more than 80% of Fortune 500 companies have Model Context Protocol servers in active production workflows, and that more than 30 CVEs were filed against MCP servers, their clients and the surrounding infrastructure in January and February 2026 alone. One security vendor's count, so treat the figures as indicative. The direction is hard to argue with. The tool surface an agent can reach is now large, largely third-party, and changing weekly, which means the thing deciding has to be yours.

Proportional beats binary

Gartner issued a press release on 26 May 2026 under the heading that applying uniform governance across AI agents will lead to enterprise AI agent failure, arguing that organisations treat agent governance as binary, either locked down or fully trusted, and recommending proportional governance across distinct autonomy levels. Direct access to the release was blocked when this page was written, so the position is reported from its published title and public summaries rather than quoted. The practical version is unglamorous: a read-only lookup and a payment should not attract the same ceremony, and that difference belongs in configuration per tool, not in a judgement call by whoever happens to be on call.

How Difinity.ai enforces at the tool call

The tool call is where Difinity's enforcement sits. An agent cannot hold a credential or reach a system directly, so every action is proposed to the tool gateway, which holds the credential, applies the rules the organisation set, then decides and acts. The tool gateway is not reachable from the internet. Gmail and Slack are the connectors Difinity brokers; anything else is an MCP server the organisation registers, which Hub labels Tool servers. An administrator switches a connector on and chooses which of its tools agents may call at all, and that is the organisation's ceiling. A person then connects their own account, and an agent acting for that person uses that person's credential, never anything wider than the ceiling. The tool gateway refuses any tool it holds no schema for, because arguments it cannot check are arguments it cannot constrain. Where a tool server acts as itself rather than as the person using it, Hub marks it, because a server like that can hand a caller reach the person never had.

Six checks for runtime control

Run these against whatever you are building or buying. They are the questions that separate enforcement from a dashboard.

  • The agent holds no credential, and there is no second route into the system.
  • The decision reads the resolved arguments, and a tool with no schema is refused rather than allowed on trust.
  • Every tool is marked effectful or read-only, and effectful carries a floor that a written rule cannot lower.
  • The organisation's ceiling for a connector is set once by an administrator, and a person's own connected account can only narrow it.
  • When the deciding component cannot answer, effectful work goes to a person instead of going through.
  • The record is produced by the component that decided, rather than reconstructed afterwards from application logs.

Frequently asked questions

What is runtime control in agentic AI governance?

A decision taken about one proposed action, on its resolved arguments, while the run is in progress, by something outside the model that holds the credentials the action needs. It allows, refuses, or sends the action to a person, and it records what it did.

Is documentation-based AI governance useless then?

No. The register, the risk assessment and the approved use case do real work in deciding what an agent should exist to do. They just have no way to reach a call in flight, so pairing them with an enforcement point is the whole argument here.

Why can prompt engineering not solve this?

Because instruction and data reach the model through the same channel. An agent reading a ticket or a web page is reading text an attacker may have written, which is what EchoLeak (CVE-2025-32711) demonstrated. A constraint the agent cannot talk its way past has to live outside the model.

Does every action need a human approval?

No, and requiring one defeats the point of the agent. Gate the actions that are hard to reverse, and let the rest run within their configured authority. In Difinity only the person the agent is acting for can answer an approval, and a run nobody answers expires rather than proceeding.

Sources and further reading

Have an agent that needs production authority?

Read the MCP governance guide