AI Agents Don't Read Your Policy Docs. They Hit Your APIs — Gravitee
You can write all the rules you want in a markdown file. Your agent can still call the API. Sam, CTO at Gravity, skips the slides and runs five live scenarios against a hotel-booking agent to show why governance belongs in the infrastructure, not in the agent's instructions. Running on the Gravity Gateway with a Databricks backend, Sonnet and Groq, he shows the gateway blocking a destructive "delete all bookings" tool call, stopping an attempt to pull every guest's personal data, rate-limiting a buggy agent that fires the same request eight times, serving repeated questions from a semantic cache, and rejecting an oversized prompt before it ever reaches the LLM. He also covers telemetry across your agents, decoupling from any one hyperscaler, trimming bloated MCP tool lists, and shadow AI on employee laptops. In this talk: • Why prompts and policy docs can't enforce what agents do • Blocking destructive tool calls and data exfiltration at the gateway • Rate limits, semantic caching and token limits that cut cost • Observability, decoupling from vendors, and trimming MCP tools SPEAKER Sam, CTO, Gravity CHAPTERS 0:00 Intro 0:52 Agents without governance 1:32 Move policy to the gateway 2:57 Demo 1: Blocking destructive tools 4:57 Demo 2: Stopping data exfiltration 6:56 Demo 3: Runaway repeat requests 8:21 Demo 4: Semantic caching 11:01 Demo 5: Blocking oversized prompts 12:21 Expensive agent habits 15:01 Avoiding vendor lock-in 15:41 Trimming MCP tools 16:16 Shadow AI 16:56 Wrap-up Recorded at the AI Engineer World's Fair 2026 in San Francisco. Subscribe for more talks from the engineers building with AI. AI Engineer: https://ai.engineer YouTube: https://www.youtube.com/@aiDotEngineer X: https://x.com/aiDotEngineer LinkedIn: https://www.linkedin.com/company/aidotengineer/ #AIAgents #AIGovernance #AIEngineer
More like this

AI Security Engineer Foundations + Certificate — Javier Garza, Snyk

Same Model, Different Speed: Why Your Inference Provider Matters — FriendliAI

SonarQube + OpenAI: Agentic Development — Killian Carlsen-Phelan, Sonar

Let Your Agent Cook: Using Skills to Evaluate and Improve Your App — Ankur Duggal, Arize AI
Join the discussion
Sign in to join the discussion
Sign in