[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-researchers-build-a-runtime-bouncer-for-ai-agent-actions":10,"sections":34},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":29,"feedback":33,"feedback_at":22,"cost_usd":33,"total_tokens":33},7370,"researchers-build-a-runtime-bouncer-for-ai-agent-actions","Researchers Build a Runtime Bouncer for AI Agent Actions","ActGov checks every AI agent tool call against runtime policies before it executes, cutting prompt-injection success without trusting the model itself.","A new framework called ActGov puts a policy check between every AI agent action and the real world.\n\nResearchers built ActGov as a runtime enforcement layer that validates each tool call an LLM agent proposes before it can take effect, rather than trusting the model to spot malicious instructions on its own. It works from a unified model of authorization, actions, context, and security constraints. One component, ActGov-Policy, builds up a policy set from tool specifications, normal task behavior, and observed failures, with every update checked by an SMT solver for counterexamples. A second component, ActGov-Runtime, turns each tool call into a policy record and only lets it through if it stays inside the task's authorization boundary. The team tested it on the AgentDojo and AgentDyn benchmarks, across several models and attack setups, and found it cut the success rate of indirect prompt-injection attacks while keeping the agent useful for its actual task.\n\nThat framing matters because most current defenses either sandbox untrusted content or lock agents into a predefined plan, which breaks down the moment a workflow branches dynamically, and that is exactly how most real agent tools behave now. ActGov's bet is that authorization should be enforced at the action layer, independent of whether the LLM itself gets fooled by injected text.\n\nIt's a sensible instinct, closer to a firewall than a filter, but it's still a benchmark result on AgentDojo and AgentDyn, not a production deployment against the messy, ever-expanding tool ecosystems agents actually get plugged into.","[\"ai-agents\",\"security\",\"prompt-injection\",\"llm\"]","2026-09-23T04:00:00.000Z","2026-09-23T10:00:31.955Z","2026-09-23T10:00:37.728Z","published",null,[],"security",[26,24,27,28],"ai-agents","prompt-injection","llm",[30],{"name":31,"url":32},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2609.24446",0,{"sections":35},[36,40,43,47,52,56,61,66,71,76,81,86,91,96],{"name":37,"slug":38,"count":39,"latest_published_at":18},"AI","ai",4344,{"name":41,"slug":24,"count":42,"latest_published_at":18},"Security",713,{"name":44,"slug":45,"count":46,"latest_published_at":18},"Policy","policy",370,{"name":48,"slug":49,"count":50,"latest_published_at":51},"Deals","deals",206,"2026-09-23T09:43:46.000Z",{"name":53,"slug":54,"count":55,"latest_published_at":18},"Hardware","hardware",169,{"name":57,"slug":58,"count":59,"latest_published_at":60},"Science","science",134,"2026-09-23T09:00:00.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Consumer Tech","consumer-tech",110,"2026-09-22T20:00:00.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Software","software",81,"2026-09-23T09:56:13.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":75},"Dev Tools","dev-tools",79,"2026-09-22T22:21:13.000Z",{"name":77,"slug":78,"count":79,"latest_published_at":80},"Startups","startups",65,"2026-09-22T22:06:48.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Gaming","gaming",45,"2026-09-22T15:35:06.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"General","general",43,"2026-09-21T23:48:56.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"Reviews","reviews",27,"2026-09-22T13:00:00.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]