Agent Ops: runtimes, control planes, network defense, on-device agents

Everything we launched during Agents Week. Cloudflare rolls out an agent runtime, an Agent Development Lifecycle (ADLC), Zero Trust for agents, and an Agentic Internet vision to support AI-native autonomous apps. This supplies infrastructure primitives you’ll reuse for orchestration and secure deployment — Principle 09 in practice.

Brex assumes its AI agents could do anything — so it watches the network, not the code. Brex builds CrabTrap to assume agents can be compromised and police outbound network traffic using LLM judges plus static rules. Treating compromised agents as network threats reframes where you enforce policies and detect exfiltration — a practical Immune System approach to agent security (Principles 10 & 14).

How to ground Genie Agents in both structured data and documents without losing governance. Databricks makes Genie Agents run as the user and inherit Unity Catalog controls so answers respect row-, column- and object-level permissions across tables and files. This is a concrete pattern for data-aware agents that preserves access control and auditability in production (Principles 02 & 10).

AWS Continuum integrates with OpenAI Codex and Anthropic Claude Code in major AI security push. AWS embeds Continuum across rival model environments, positioning itself as the security control plane across developer workflows. If you build agents, expect the control point for policy, logging, and runtime enforcement to move toward cloud security platforms — plan integration and audit hooks accordingly (Principles 09 & 10).

Needle 2: 14MB agentic LLM for phones, wearables, smart home and robots. Needle 2 packs a 45M-parameter agentic model into a 14MB binary with tool-calling and device control for budget edge hardware. On-device agentic models change latency, availability, and threat models — incorporate offline validation, capability gating, and local provenance into your agent design (Principles 15 & 06).