Article 78RYN AWS offers local, open source leash for agent harnesses

AWS offers local, open source leash for agent harnesses

by
from www.theregister.com - Articles on (#78RYN)
Story ImageIf you don't want your AI agents running out of control and changing files or transferring data outside your rules, AWS has published an open source software library that it claims can add a new layer of policy control. Just as a dog's harness is useless without a leash to keep it under control, the Dogwood Local Engine promises to put AI agent tool calls on a leash, blocking actions that don't meet user-defined temporal conditions. The DLE comes in the form of a Rust library that can be embedded into an agent's harness or gateway and, to boil a long explanation down to a single sentence, simply issues allow/deny verdicts each time an agent tries to make a tool call. DLE doesn't do the enforcement itself, AWS explained in its announcement writeup - that's up to the harness itself - but it does check each tool call against policies defined using Dogwood, the open source governance language that AWS published in August. When AWS introduced Dogwood, it open sourced the language and reference tooling and added support for it to Amazon Bedrock AgentCore; DLE's release makes the policy engine directly embeddable into agent harnesses. A key feature of both DLE and Dogwood is their awareness of temporal conditions. DLE tracks agent tool call events over time, stamping them into a log step by step. Those logs are persisted to a disk as each entry is made, allowing DLE to retain its state even if the entire system crashes or is restarted. The persistence step happens before DLE evaluates the applicable policy, and at the end of that process it returns a result: allow the action, or deny it, based on what the engine's policies state. AWS gives the example of controlling coding agent Git pushes using DLE, defining a policy that only allows a push when the most recent test run has passed, and requiring that pass to have occurred within the past 15 minutes. If that's not the case, the push is denied. To accurately handle verdict enforcement, the harness intercepts every tool call, submits a request event to the engine, and runs the tool only if the engine's verdict is allow," AWS explained. This naturally raises the question of how much of a delay DLE introduces into agentic workflows; AWS claims the added delay is minimal. In tests simulating sessions from five minutes to 12 hours, DLE evaluation time was around 20 microseconds with a 15-minute window at the 12-hour mark, rising to about six milliseconds with a 24-hour window. DLE is also designed to prevent concurrent submission collisions by relying on a lock that only allows one event submission at a time, and that lock persists until policy evaluation is complete. AWS didn't make clear from its writeup how that would handle a situation where, say, two concurrent submissions were made in which one fulfilled pass conditions and one caused a failure. We asked how incorrect enforcement could be prevented in those situations, but didn't hear back prior to publication. Given repeated revelations of late that AI agents appear to regularly go off the (safety) rails imposed on them by human operators, the question of how durable DLE is also merits discussion. AWS admits that such situations are part of its reason for publishing the new library. Left unchecked ... tool calls can have irreparable consequences," the DLE announcement concludes. As agents scale to settings where they work autonomously for longer intervals with more tools, we need safeguards that can regulate how those tools are used." AI agents finding holes in Dogwood and the DLE is likely a matter of time. Until then, feel free to give Dogwood and DLE a shot through its GitHub page. (R)
External Content
Source RSS or Atom Feed
Feed Location http://www.theregister.co.uk/headlines.atom
Feed Title www.theregister.com - Articles
Feed Link https://www.theregister.com/
Reply 0 comments