October 6, 2026

What an AI Governance Platform Should Control at Runtime

Enterprise security
Artificial Intelligence/ AI

Identity, prompts, data, extensions, agent actions, and MCP, enforced while AI is in use.

Island blog hero image for What an AI Governance Platform Should Control at Runtime

Key takeaways

  • Runtime governance means controlling identity, prompts and data, destinations, extensions, agent actions, tool calls, and MCP while an agent is actively working, extending beyond the approval that happens before a use case starts.
  • Our scan of nearly 34,000 public MCP servers found that one in three carries a high or critical severity finding, and 92% of owners have no verifiable organizational affiliation.
  • Gartner expects AI agents to outnumber human users 10 to 1 in large enterprises within a few years, which means identity controls built for people alone will miss most of the workforce.
  • AI Runtime Protection applies one of three responses, allow with logging, prompt for confirmation, or block with a reason returned to the agent, to every prompt, tool call, and MCP response.
  • A single policy engine spanning the browser, endpoint, network, and integrations lets one set of rules follow an agent through its full sequence of actions.

AI governance programs commonly stop at policy documents and approval workflows. But once an agent is running, calling tools, and pulling data through MCP connections, a written policy can't do much on its own. We put 53% of AI interactions at autonomous actions rather than a person typing a question, and 93% of prompts sent to a human reviewer get approved anyway, turning the reviewer into a formality. Governance has to inspect each prompt, tool call, and MCP response at the moment it happens, across identity, prompts and data, destinations, extensions, agent actions, tool calls, and MCP.

The distance between policy and enforcement

Compliance Week's 2026 AI Compliance Survey found that 83% of organizations already use AI tools, but only 25% have implemented strong governance frameworks. Gartner predicts more than 40% of agentic AI projects will be canceled by the end of 2027, with governance issues discovered after production incidents named as a leading cause. That space between written policy and what happens once AI is running is where enforcement stops: policies get written, but no system checks whether a prompt or tool call followed them.

98% of organizations have employees using unsanctioned AI tools, and 47% of employees access AI through personal or unmanaged accounts. NIST's Generative AI Profile recommends organizations put a transparent acceptable use policy in place, but a policy sitting in a document doesn't stop a prompt from going out or a tool call from executing. It has to be enforced at the point where the action happens.

Identity across people, scripts, and agents

Every governance conversation starts with who's acting, but the answer is changing fast. Gartner expects AI agents to outnumber human users 10 to 1 in large enterprises within a few years, which means most organizations need to govern agents as a distinct population, not an extension of human identity management.

AI and agents also enter organizations through nine entry points, spanning channels that include web, desktop, and extensions, so identity checks built only for logins on managed devices miss most of the traffic. A governance platform has to know, at the moment a prompt or tool call happens, whether it's a person, a script, or an agent acting on someone's behalf, and apply policy accordingly. Without that, identity becomes a record of who approved the project, not who's operating inside it.

Prompts and data: what goes in and what comes back

A KPMG survey found that 48% of employees admit to uploading sensitive data into AI tools. AI Protect watches that traffic as it happens, rather than depending on employees to report what they typed into a chat window after the fact.

None of this argues against using generative AI at work. An NBER paper found a 14% increase in productivity for call center workers assisted by generative AI. But a productivity gain doesn't offset the cost of an unreviewed prompt carrying a customer record or a proprietary design file, so a governance platform has to inspect what a prompt contains before it leaves and what a response contains before it lands, the same way a data loss prevention tool inspects a file transfer.

Destinations: where the traffic lands

Our network treats the browser and endpoint as the control point rather than the network itself, combining Private Access, Secure Web Gateway, remote browser isolation, and SaaS API security. That matters because 47% of employees reach AI tools through personal or unmanaged accounts, so a control that only watches corporate SaaS tenants misses close to half the activity.

We apply granular privacy and data loss prevention controls across finance, healthcare, retail, and technology use cases. The same policy that governs a file download can govern a prompt sent from inside the browser to an AI tool, which closes the distance between where data lives and where AI reaches it.

Extensions: the plug-ins nobody reviewed twice

We monitor more than 18,200 AI extensions with real-time risk scoring. Most browser extensions get installed once and never reviewed again, and an AI extension can read page content, capture form data, or call an external API without security ever seeing it happen.

Runtime governance has to score and monitor that population continuously, not only at the point of install. A one-time review at deployment tells a team nothing about what an extension does six months later, after an update changes its permissions or its behavior.

Agent actions and tool calls: where execution happens

This is the stage where governance meets real execution. AI Runtime Protection governs the prompt an agent receives, the response it generates, every tool call it makes, the files it touches, and any skill or sub-agent it invokes along the way.

Instead of a single allow or deny decision made once at approval, we apply one of three responses to each of those actions in real time: allow with logging, prompt the user for confirmation, or block and return a reason to the agent. Approving an agent's use case in advance doesn't tell anyone what that agent did with a customer database three tool calls later. Only a system watching execution as it happens can catch that, and that continuous watch is what governance means once an agent is running.

MCP: the newest and least governed layer

MCP is the standard agents use to connect to tools and data sources. Without governance, developers install MCP servers with no inventory, no risk scoring, and no kill switch, which leaves an organization exposed to whatever that server can reach.

We scanned nearly 34,000 public MCP servers and found that one in three carries a high or critical severity finding, while 92% of owners have no verifiable organizational affiliation. Supply-chain review governs what gets installed. Runtime governance governs what happens during execution, including every live tool call, MCP response, and prompt. Our central MCP gateway applies per-source policy, identity, audit, and threat intelligence, along with a one-click block for a compromised MCP.

Point security tools each see one link in that chain, network, endpoint, or identity, but none see the full sequence from prompt to tool call to data movement. A single policy engine and audit trail can apply the same rules to every agent because we already sit in the browser, endpoint, network, and integrations at once. Runtime control across identity, prompts and data, destinations, extensions, agent actions, and MCP isn't a checklist to finish once. Teams building this kind of program can start from those same entry points.

FAQs

What does "runtime" governance mean, and how is it different from approval-based governance?

Approval-based governance reviews a use case once, before an agent starts working. Runtime governance watches every prompt, tool call, and MCP response while the agent is actively acting, applying a decision, allow, prompt, or block, to each one. The distance between the two matters because a use case approved in advance says nothing about what an agent does with data three tool calls later.

Who should own runtime AI governance inside the organization, security or IT?

Ownership spans identity, data, network, and endpoint controls at once. Because we apply one policy engine across the browser, endpoint, network, and integrations, the practical answer is a shared program rather than a single owner, built on one set of rules that follows an agent through its full sequence of actions.

What's the tradeoff between blocking agent actions and letting them run?

Our three-response model, allow with logging, prompt for confirmation, or block with a reason returned to the agent, assigns a response to each action based on its specific risk rather than applying one setting to everything. That is more scrutiny than the 93% of prompts a human reviewer approves.

How does runtime governance apply specifically to MCP servers?

MCP is the standard agents use to connect to tools and data. We scanned nearly 34,000 public MCP servers and found one in three carries a high or critical severity finding, with 92% of owners lacking verifiable organizational affiliation. Supply-chain review checks what gets installed, while runtime governance covers live tool calls and MCP responses through a central gateway with per-source policy and a one-click block.

Does identity governance need to change once agents outnumber human users?

Yes. Gartner expects AI agents to outnumber human users 10 to 1 in large enterprises within a few years, and agents enter organizations through nine separate entry points, spanning channels that include web, desktop, and extensions. Identity checks built only for human logins on managed devices will miss most of that activity, so agents need to be governed as a distinct population.

Does adding runtime controls create extra operational overhead for employees or agents?

We don't have a latency number here. Enforcement is a response applied in real time to each action, extending the same policy engine that already governs file downloads and network traffic, rather than adding a new parallel process.

How does this connect to data loss prevention and network security tools organizations already run?

Prompt inspection works the same way a data loss prevention tool inspects a file transfer. Our network combines Private Access, Secure Web Gateway, remote browser isolation, and SaaS API security in the browser and on the endpoint. Point tools each see one link in the chain, network, endpoint, or identity, while a single policy engine is built to see the full sequence from prompt to tool call to data movement.

Island Team

Island is defining the future of work for people and AI agents. Its enterprise agentic control plane helps organizations enable, govern, and audit agentic workforces alongside people. Island boosts productivity across devices, browsers, applications, networks, and data while protecting sensitive information, simplifying access, and helping enterprises scale AI safely.