QUESTIONS PEOPLE ASK
Frequently asked questions.
How do you stop an AI agent from taking a harmful action?
You check each action before it runs, from a control the agent cannot influence. That control sits beside the agent in the execution path, sees every kind of action, weighs it against context such as the user, the goal and recent history, and then allows, constrains, pauses or blocks it. Ackuity is the Agent Execution Control Switch AI builders add to their agents, verifying every action before it runs.
What is the difference between an AI guardrail and an execution control?
An AI guardrail checks what goes into and comes out of a model, while execution control checks what the agent is about to do before it runs. Guardrails live inside the model or the agent harness, so the agent they restrain can sometimes reason around them. Execution control sits outside the agent and decides on the action itself, such as a shell command, a SQL query or a refund. The two work well together.
Can an MCP gateway stop agent attacks?
An MCP gateway can stop some attacks that travel through MCP tool calls, but most agent actions never pass through a gateway. Of 11 kinds of agent action, 3 pass a gateway: LLM calls, MCP tool calls and API calls. The other 8, including CLI commands, SQL queries, IMDS metadata calls and A2A hand-offs, never meet one. A gateway also sees each call alone, without the user, goal or history behind it. Ackuity works alongside gateways and feeds them that context.
Where should agent security sit?
Agent security should sit beside the agent, in the execution path: not inside the agent, not at the gateway. We call that the Goldilocks zone. Inside the agent is too close, because the agent can reason around its own rules. A gateway is too far, because most actions never pass through it and the context is missing. Beside the agent, the control sees intent, plan and history and stays outside the agent's control.
What happens if the sidecar fails?
The sidecar fails open or fails closed, whichever your policy sets, and a failure affects one pod, not your whole estate. Fail open lets the agent keep working unchecked until the sidecar recovers. Fail closed stops that pod's actions until it does. You can choose differently for different agents.
Does Ackuity require code changes?
No, Ackuity does not require changes to your agent's code. The sidecar runs in the agent's pod, and an init container reroutes traffic through it, so the agent never knows. For platforms such as Copilot Studio, Ackuity uses API injection. For the fastest start, it pulls events from OpenTelemetry, Langfuse or LangSmith in observe-only mode.
Where does my data go?
Your data stays in your own cloud account, because Ackuity runs there. For stricter requirements, Ackuity can also hold the agent's credentials and run the action on its behalf, handling mTLS, so the agent never touches the tokens.
What is a security context graph for AI agents?
The Agent Security Context Graph is a security context graph for AI agents: everything relevant to a single agent action, across six dimensions and 29 signals, assembled outside the agent before the action runs, so the agent cannot edit it. The six dimensions are User; Agent; Intent and goal; Target system and data; Tools and supply chain; and History. Most security context graphs help analysts investigate after an incident. The Agent Security Context Graph is built around each agent action, in real time, before it executes.
What is an AI agent kill switch?
An AI agent kill switch is an independent control that stops a harmful agent action before it executes, and the agent has no influence over the decision. A traditional kill switch stops the whole agent. Ackuity works as a control switch: it acts on each action and keeps Terminate, which shuts the container down, for catastrophic cases.
Does Ackuity work with NVIDIA OpenShell?
Ackuity is building an integration with NVIDIA OpenShell's supervisor middleware, and it is in development. In OpenShell, a supervisor beside each sandbox is the agent's only way out, inspecting outbound HTTP, GraphQL and MCP traffic against policy before it leaves. The middleware lets an external service such as Ackuity allow, deny or modify that traffic, which maps to Allow, Block and Constrain. Ackuity is an NVIDIA Inception member. Outside OpenShell, the same decision layer runs as the Ackuity sidecar on any Kubernetes cluster.
How is Ackuity different from an agent sandbox?
A sandbox limits what an agent can reach, and Ackuity decides whether each action inside those limits should run right now. A sandbox policy might allow an agent to query the customer database. Ackuity looks at who asked, what the agent is trying to do and what it did before, then allows, constrains or blocks that specific query. The two work best together.
How fast is a decision?
Ackuity makes a decision in 40 to 100 ms per action. That is decision time, measured separately from end-to-end latency, and the sidecar runs in the agent's own pod, close to the action.
What are the 14 threat categories?
Ackuity's 60+ threat models fall into 14 categories, mapped to NIST, OWASP and MITRE ATLAS. They are A2A threats; memory poisoning; misaligned and deceptive behaviour; privilege compromise; remote code execution; identity spoofing and impersonation; agent social engineering; resource overload; sensitive and regulated data exposure; tool misuse; intent breaking and goal manipulation; overwhelming human in the loop; MCP threats; and policy violations. Framework mappings are not certifications.