KDCube

Agent Controls Move Before the Tool Call as Runtimes and Capital Arrive

JetStream's Clearance authorizes agent actions before they run and can veto exfiltration-style sequences, while Microsoft's Agent Harness and Foundry Hosted Agents reach general availability as a governed production runtime. On the same day, HiddenLayer raised a $100M Series B for agentic runt...

Lead signal

Agent controls move before the tool call.

Pre-execution authorization, a production-grade runtime going GA, and two nine-figure raises in a single day all point the same way: for teams running agent fleets, control, security, and operations — not the model — are where the platform fight is landing.

  • governance
  • agent-runtime
  • runtime-security
  • agent-ops

Highlights

  • JetStream unveiled Clearance, an "AI zero-trust reasoning engine" that authorizes every agent action before it executes and blocks dangerous multi-step sequences — pushing governance ahead of the tool call instead of into post-hoc logs (Yahoo Finance).
  • Microsoft Agent Framework's Agent Harness and Foundry Hosted Agents are now generally available, giving platform teams a managed runtime with identity, sessions, versioning, tool-approval, and built-in OpenTelemetry — not just a build-time library (InfoQ).
  • HiddenLayer raised a $100M Series B (led by Delta-v, with Microsoft's M12 and Booz Allen Ventures) for agentic runtime security, and shipped Agent Harness Security to protect AI coding agents at runtime (SecurityWeek).
  • Wonderful closed a $550M Series C at a $5B valuation — doubling its price in under six months — to scale an enterprise "AI operating system," with Salesforce joining the round (TechCrunch).

Key Signals

  1. Authorization moves to pre-executionSept 2, 2026

    JetStream Clearance evaluates each request at its AI gateway against an approved design — mapping agent/user, tools, and parameters — and can veto a sequence (e.g., a legitimate query and attachment followed by a BCC to an external address) that signals exfiltration. It targets enterprises running hundreds of thousands of agents and enters GA in fall 2026 (Yahoo Finance). This is a category shift from the post-hoc audit traces that defined recent runtime-governance launches.

  2. A production agent runtime, in the boxpost-Build 2026, per InfoQ

    Microsoft's Harness runs as one binary across local, container, and hosted deployment, with plan-and-execute modes, context compaction, tool approval, and OTel on by default; Foundry Hosted Agents add managed identity, scaling, and versioning on consumption billing across 31 Azure regions, in .NET and Python (InfoQ). Platform teams now weigh build-your-own orchestration against a governed hosted surface.

  3. Capital confirms the agent-ops thesisSept 2, 2026

    HiddenLayer's $100M (total funding now >$155M) explicitly funds Agentic Runtime Security and coding-agent protection, while Wonderful's $550M scales managed workflows and conversational agents (SecurityWeek, TechCrunch). Investors are pricing the layer around the model — control, security, and operations — not the model itself.

Why It Matters / What To Watch

  1. Pre-action control vs. post-hoc audit are now distinct product categories.
    • Evaluate whether an authorization-before-tool-call layer (Clearance) belongs in front of your MCP/A2A traffic, versus relying on audit traces to catch abuse after the fact (Yahoo Finance).
    • Watch how these gateways compose with per-action identity and budget controls already landing in managed runtimes (InfoQ).
  2. "Runtime, not library" is becoming the default posture.
    • If you're standardizing agent hosting, compare Microsoft's hosted-agent identity/observability defaults against self-hosted orchestration cost and lock-in (InfoQ).
    • Note the naming collision: Microsoft ships an Agent Harness while HiddenLayer sells Agent Harness Security — track whether security vendors wrap these runtimes or the platforms absorb the controls (InfoQ, SecurityWeek).
  3. Follow the money into agent ops and security.
    • Two nine-figure raises in one day — one security, one enterprise AI OS — suggest budget is shifting toward governed deployment; watch for consolidation and Salesforce's expanding platform bets (SecurityWeek, TechCrunch).

Quick Links