Home / Topics / Agent Security vs Governance
Where governance ends and runtime enforcement begins

AI governance tells you the rules. Runtime agent security helps enforce them when the agent acts.

If you're standing up AI, you'll hear two things called "AI security" that do different jobs. Governance platforms define, validate, document, and prove your AI controls. Runtime agent security inspects and constrains what an agent actually does at the moment it acts. You likely need both, and it helps to be clear about which does what before you buy either.

See Crawdad's architecture → Talk to us →

Crawdad is the runtime-enforcement layer. It complements your governance system of record.

One writes the policy. The other enforces a piece of it, live.

An AI governance system is a system of record for responsible AI: it inventories your models and agents, maps controls to frameworks, runs approvals and validations, monitors, and produces the documentation and evidence a risk or compliance function needs. Its question is what should be allowed, and can we prove we governed it.

Runtime agent security operates at a different moment: the live interaction, where an agent reads content, calls a tool, touches data, and makes a network request. Its question is is this specific action, right now, within what this agent is allowed to do — and it can block, hold, or record that action before it happens.

Governance defines the rule. Runtime security is one of the places the rule becomes operational and provable. They're not competitors; a governance policy that says "agents must not exfiltrate credentials" needs something at the wire that actually stops it.

Side by side

QuestionAI governance platformRuntime agent security (Crawdad)
Main objectiveDefine, validate, document, oversee, and prove responsible-AI controlsInspect and constrain risky agent behavior at the moment of action
Typical usersGovernance, risk, compliance, legal, model-risk leadersAI, security, and platform engineering; technical operators
Control timingDesign, approval, testing, monitoring, audit, lifecycleLive agent interaction: tool use, data access, network egress
Evidence producedPolicy mapping, inventories, reviews, validation recordsRuntime decisions, enforcement events, agent and tool context
Relationship to the ruleGoverns what should happenMakes a subset of those rules operational and provable at the wire

Governance sets the boundary. Crawdad enforces it where the agent acts.

A governance program might require that a customer-facing agent never touches production credentials, only reads from approved sources, and produces an auditable record of its actions. Those are rules. Crawdad is one way they get enforced in reality:

Crawdad doesn't replace your governance system of record. It gives that system a runtime enforcement signal and a verifiable evidence trail for the agent-action layer — the part governance can define but can't itself execute.

When you need which

See the architecture → Read the benchmark →

Crawdad runs on the device, judges the action, and writes a record you can verify yourself.