AGENT EXECUTION CONTROL SWITCH

AI agents at work. Nothing to lose sleep over.

Ackuity watches every action your agents take, in real time. Neurosymbolic AI weighs each one against a live security context graph of who, what and why. When an agent goes rogue, its next move never runs.

  • Decisions in 40 to 100 ms
  • 60+ threat models
  • No agent code changes
NVIDIA Inception memberOpen Secure AI Alliance member

Context inputs

Ackuity · Agent Execution Control Switch

Actions

EXISTING CONTROLS

Agent intends to act. Full context resolves. Ackuity verifies. Action proceeds. Companion controls coexist with Ackuity. Who initiated the action. What they are allowed to do. Why the agent is acting. What the agent intends to do next. What led to this action. Which agent delegated authority. The agent intends to act. Each action passes through Ackuity before execution. Full context resolves. Ackuity verifies. The action proceeds. Verify tool use before execution. Verify the request before it leaves the agent. Verify MCP access in full context. Verify data access before the query runs. Verify authority before delegation. Protect model input and output. Ackuity verifies actions. Coordinates agent behavior. Ackuity verifies execution. Secure connections. Ackuity verifies why the call should happen. Identity informs execution. Ackuity does not replace IAM. Protects sensitive data. Ackuity applies that context at execution. Receives security telemetry. Ackuity creates the execution record.

01 / THE GAP

Everyone checks what the model says. Nobody checks what the agent does.

Filters read the prompt. Gateways see the calls routed through them. An agent acts in at least 11 ways, and only 3 ever reach a gateway.

3

pass a gateway

  • LLM calls
  • MCP tool calls
  • API calls
8

never meet one

  • CLI commands
  • HTTP probes
  • SQL queries
  • IMDS metadata calls
  • Credential searches
  • Memory writes
  • RAG retrieval
  • A2A hand-offs

FOUR ILLUSTRATIVE CASES

Where agents drift from intent.

The guardrail passes the prompt.
Ackuity checks each action, with everything around it.

  • Same prompt, different outcome

    A safe prompt can still lead to risky actions.

  • See the full sequence

    Actions, context and history across the session.

  • Stop attacks at execution time

    Constrain or block a risky action before it completes.

CASE 01 · Action chain exploitation

Every call is legitimate. The sequence is the attack.

What the guardrail read

“Pull the Q3 vendor list, check which contracts renew this month, and prep the renewal summaries for finance.”
PASSED

The prompt has no injection and no sensitive data, so a filter has nothing to flag.

Where agent actions became threats

Action sequence · Ackuity security verdicts

  1. db.read vendors.q3ALLOWED
  2. db.read contracts.renewalsALLOWED
  3. iam.role.assume finance-adminCONSTRAINED
  4. api.post payments.batchBLOCKED
  5. email.send cfo@ "renewals done"BLOCKED

A gateway allows all five. Each call is in scope on its own.

Ackuity constrains the third. An agent prepping renewal summaries has no reason to become finance-admin, and it never has before.

01 / 04

02 / HOW IT DECIDES

How does Ackuity decide
whether an action runs?

Ackuity is the Agent Execution Control Switch AI builders add to their agents, verifying every action before it runs.

Six dimensions surround a single agent action: user, agent, intent and goal, target system and data, tools and supply chain, and history. Signals from each dimension travel to the Ackuity verifier before the action runs.UserIntent & goalAgentHistoryTools & supply chainTarget system & dataEvery action, in context
01 / BEGIN WITH CONTEXT

Agent Security Context Graph

Everything around one action, gathered before it runs.

Six dimensions and 29 signals for every action: user, agent, intent and goal, target system and data, tools and supply chain, and history. Built outside the agent, so the agent cannot edit it.

The agent stands at the center. Ackuity orbits close beside it, in the execution path but outside the agent itself. Tool, MCP and API gateways and LLM guardrails sit far out at the perimeter, where most agent actions never pass.Tool gatewayMCP gatewayLLM guardrailsAPI gatewayAgentNot inside the agent. Not at the gateway.
02 / WHERE IT SITS

The Goldilocks zone

Not inside the agent, not at the gateway.

Beside the agent, in the execution path: close enough to see intent, plan and history, and outside the agent’s control. Inside, an agent can reason around its rules. At a gateway, most actions never pass.

Rules, behavioral baselines and small language models feed the Ackuity verifier, which correlates findings across steps. Each action gets an allow, constrain or block verdict in 40 to 100 milliseconds.Small language modelsBehavioral baselinesCross-step correlationRules40 to 100 msAllowConstrainBlock
03 / VERIFY IN CONTEXT

Neurosymbolic verification

Rules, baselines and small models, checked together.

Each action is checked against 60+ threat models in 14 categories, with findings correlated across steps. The verdict lands in 40 to 100 milliseconds.

The Ackuity icon anchors one continuous verification plane across three agents. Each agent uses a different illustrative combination of model, framework and deployment environment.OpenAILangGraphAWSClaudeCustom agentsAzureLlamaLangChainOn-premisesOne control planeEvery agent stack
04 / MODEL & PLATFORM INDEPENDENT

One control plane, every runtime

Keep your choice of models, platforms and infrastructure.

One security policy across every model, framework and environment, running in your own cloud account.

Explore the platform

03 / RESPONSE LADDER

What happens when an agent tries something risky?

Allow: Signed, logged and run.

Constrain: Data masked or scope narrowed, then run.

Human in the loop: Paused until a person approves it.

Block: Dropped before it reaches the target.

Terminate: Container shut down. Kept for catastrophic cases.

04 / HOW IT SHIPS

How do you add Ackuity
to your agents?

Builders add an open source sidecar beside each agent, or start from telemetry they already collect. Security runs Ackuity Core in your cloud account.

OPEN SOURCE

The sidecar

Runs in the agent's pod. An init container reroutes its traffic, so you change no agent code. Set fail-open or fail-closed per policy; a failure touches one pod, not your estate.

COMMERCIAL

Ackuity Core

The Agent Security Context Graph, 60+ threat models, the response ladder, console, SSO, audit and policy packs. It runs in your cloud account, and your data stays there.

Three ways in

01

Event pull

Read agent events from OpenTelemetry, Langfuse or LangSmith.

OBSERVE-ONLY
02

API injection

Connect to Copilot Studio and similar platforms through their APIs.

PLATFORM AGENTS
03

Sidecar

In the execution path beside the agent, where Ackuity can stop any action before it runs.

DEEPEST COVERAGE

Stricter requirements? Ackuity can hold the agent’s tokens and run approved actions for it, including mTLS.

Request access Start observe-only. Move to control when you are ready.

CUSTOMERS & TRACTION

Enterprises already run
Ackuity in production.

Live

Paying customers in production

Including inside a global systems integrator’s agent platform.

3

Incumbents beaten

Chosen over established security vendors in head-to-head enterprise evaluations.

2

Banks in beta

Part of a wider enterprise beta.

7

Global SIs & consultancies

Taking Ackuity to their enterprise clients.

COMMON QUESTIONS

What people ask before they start.

Quick answers for builders and security teams. See all questions.

What is an AI agent kill switch?

An AI agent kill switch is an independent control that stops a harmful agent action before it executes, and the agent has no influence over the decision. A traditional kill switch stops the whole agent. Ackuity works as a control switch: it acts on each action and keeps Terminate, which shuts the container down, for catastrophic cases.

How do you stop an AI agent from taking a harmful action?

You check each action before it runs, from a control the agent cannot influence. That control sits beside the agent in the execution path, weighs every kind of action against context such as the user, the goal and recent history, and then allows, constrains, pauses or blocks it.

What is the difference between an AI guardrail and an execution control?

An AI guardrail checks what goes into and comes out of a model, while execution control checks what the agent is about to do before it runs. Guardrails live inside the model or the agent harness, so the agent they restrain can sometimes reason around them. Execution control sits outside the agent and decides on the action itself, such as a shell command, a SQL query or a refund. The two work well together.

Does Ackuity require code changes?

No. The sidecar runs in the agent's pod, and an init container reroutes traffic through it. Platforms such as Copilot Studio use API injection, and event pull from OpenTelemetry, Langfuse or LangSmith offers an observe-only start.

Where does my data go?

Your data stays in your own cloud account, because Ackuity runs there. For stricter requirements, Ackuity can also hold the agent's credentials and run the action on its behalf, handling mTLS, so the agent never touches the tokens.

Does Ackuity work with NVIDIA OpenShell?

An integration with NVIDIA OpenShell's supervisor middleware is in development. The supervisor inspects the agent's outbound HTTP, GraphQL and MCP traffic, and the middleware lets Ackuity allow, deny or modify it, which maps to Allow, Block and Constrain. Outside OpenShell, the same decision layer runs as the Ackuity sidecar on any Kubernetes cluster.

YOUR NEXT STEP

See what your agents are really doing,
read-only and at no cost.

We connect to the telemetry you already have and show you what your agents actually did.

See what discovery delivers

Design partner discovery: no fee, and you keep the findings.

Tell us about your agents.

Add a little context Optional

We’ll use your details to respond to your request.

05 / FIELD NOTES

What we are learning
about agent security.

All resources