Policy-Constrained Runtime Defense for Tool-Using AI Agents in Enterprise API Ecosystems
DOI:
https://doi.org/10.63412/ss28se48Keywords:
AI agents, API security, runtime policy enforcement, prompt injection, tool use, enterprise systems, cybersecurityAbstract
Tool-using AI agents can invoke internal APIs, retrieve documents, update records, and coordinate enterprise workflows. These capabilities create a runtime security problem: an agent may select an unauthorized tool, hallucinate an endpoint, follow malicious instructions embedded in retrieved context, rely on poisoned memory, retry unsafe operations, or submit a schema-valid but policy-violating payload. This paper presents a policy-constrained runtime enforcement framework that intercepts each proposed action before execution and classifies it as allow, deny, or escalate. We implement a deterministic trace-driven simulator with five service domains, six user roles, six threat classes, benign and adversarial tasks, and four defense configurations. The evaluation isolates enforcement effectiveness by replaying identical seeded action traces across all configurations. Across 8,000 controlled workflow executions, the framework reduces adversarial attack success from 100.0% for an unconstrained agent, 72.2% for prompt-only controls, and 18.5% for static gateway rules to 0.2%. It achieves a 99.9% overall safe-outcome rate, 100.0% benign safe completion under simulated reviewer approval, a 4.8% benign false-positive rate, and a 24.9 ms median enforcement latency. Ablation results show that registry validation, authorization, retry governance, and intent checking directly reduce attack success. Payload inspection addresses schema-valid semantic misuse, while context-integrity and escalation controls provide defense-in-depth and operational-governance benefits. The framework provides a structured basis for controlled evaluation of policy-constrained runtime enforcement across tool-using enterprise agents.Downloads
Download data is not yet available.
Downloads
Published
2026-09-01
Issue
Section
Articles
License
Copyright (c) 2026 Swapneswar Ray (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.
Creative Commons Attribution 4.0 International License (CC BY 4.0). Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share and adapt the work with an acknowledgment of the work's authorship and initial publication in this journal.
How to Cite
[1]
S. Ray, “Policy-Constrained Runtime Defense for Tool-Using AI Agents in Enterprise API Ecosystems”, IJGIS, vol. 3, no. 8, Sep. 2026, doi: 10.63412/ss28se48.