Fastly Introduces AI Runtime Control to Govern Model Access and Agent Activity in Real Time
What Happened – Fastly announced a suite of AI‑focused capabilities—AI Runtime Control, AI Firewall, and enhanced API Security—that let enterprises enforce routing, rate‑limiting, credential protection, and spend visibility for AI model calls and AI‑driven agents at the edge. The features are delivered on Fastly’s existing programmable edge platform and are positioned as a way to maintain resilience while scaling AI workloads.
Why It Matters for Trust & Control Assurance
- Real‑time enforcement of model‑access policies provides the continuous evidence needed for an AI‑governance control objective, turning “trust‑but‑verify” into “verify‑and‑trust.”
- Virtual keys and token‑spend dashboards create auditable artifacts that map to AI‑risk controls across multiple frameworks (e.g., NIST AI RMF, ISO 42001).
- Centralised edge enforcement reduces the attack surface of undocumented AI endpoints, supporting a defensible audit trail for model usage and agent authorization.
Who Is Affected – Organizations that embed AI models or coding agents into production services, especially in technology, financial services, and health‑care sectors.
Recommended Actions
- Inventory all AI model integrations and agent‑driven API calls.
- Map your AI‑governance policies to the Verisq Common Framework (VCF) control area “AI model access and usage.”
- Deploy runtime monitoring (e.g., token‑spend logs) and collect evidence for audit readiness.
Technical Notes – Fastly reports that AI‑generated traffic grew 6.5 × faster than human traffic in H1 2026, and that 93 % of organizations are exceeding AI budgets. AI Runtime Control routes all model calls through a single programmable endpoint, applies virtual keys to protect provider credentials, and offers real‑time rate‑limiting and spend visibility. Source: Help Net Security