Runtime Policy Firewall: A Zero-Trust Governance Layer for Enterprise Agentic AI
DOI:
https://doi.org/10.63412/16ctyp82Keywords:
agentic AI, zero trust, Azure OpenAI, audit logging, runtime governance, LLM security, policy enforcement, prompt injectionAbstract
Enterprise adoption of generative AI is shifting from passive question answering to autonomous agentic execution. Modern agents can decompose goals, retrieve business context, call tools, update records, send messages, initiate transactions, and coordinate workflows across multiple systems. This creates productivity opportunities, but also introduces a critical control problem: organizations must govern not only what an agent says, but what it does at runtime.Existing work on LLM applications has investigated retrieval-augmented generation, reasoning-action loops, tool use, software agents, and foundation-model governance. Security research has also documented prompt injection, indirect instruction attacks, data leakage, and tool-abuse risks in LLM-integrated systems. However, enterprise deployment requires a stronger runtime control plane. Traditional application security assumes stable code paths, deterministic authorization checks, and explicit user interfaces. Agentic AI weakens these assumptions because one natural-language request may produce many tool calls, each with different risk, data exposure, and business impact.
This paper proposes the Runtime Policy Firewall (RPF), a mandatory control point between agent orchestration and enterprise tools. The novelty of RPF is not a new access-control mechanism or policy engine, but the elevation of model-generated semantic actions to first-class governable objects with formal mediation semantics, evidence-aware execution constraints, and lifecycle invariants. RPF makes these actions auditable execution tuples evaluated before any enterprise side effect occurs.
The paper asks: RQ1, can semantic action mediation reduce unauthorized execution? RQ2, can evidence-aware governance reduce hallucination-induced side effects? RQ3, can zero-trust runtime mediation preserve compliance with acceptable latency? The proposed guarantees hold under an explicit trusted computing base and mandatory mediation assumption. The contributions are formal RPF semantics, a runtime evaluation algorithm, and a comparison plus validation methodology.
Downloads
Download data is not yet available.
Downloads
Published
2026-09-30
Issue
Section
Articles
License
Copyright (c) 2026 Swapneswar Ray (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.
Creative Commons Attribution 4.0 International License (CC BY 4.0). Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share and adapt the work with an acknowledgment of the work's authorship and initial publication in this journal.
How to Cite
[1]
S. Ray, “Runtime Policy Firewall: A Zero-Trust Governance Layer for Enterprise Agentic AI”, IJGIS, vol. 3, no. 9, Sep. 2026, doi: 10.63412/16ctyp82.