Home / Companies / Datadog / Blog / Post Details
Content Deep Dive

What we learned about AI agent security by monitoring our agents

Blog post from Datadog

Post Details
Company
Date Published
Author
Alexa Levine, Emmanuelle Lejeail, Mallory Mooney
Word Count
2,491
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

Datadog describes an approach to securing AI agents by collecting telemetry across their full execution paths rather than relying only on application logs or model inputs and outputs. It recommends maintaining an AI bill of materials that records exact model versions, prompts, frameworks, tools, connected services, gateways, component provenance, and ownership, including applications operating outside approved infrastructure. The approach emphasizes tracing prompts, retrieved content, model responses, tool calls, policy decisions, sensitive-data flows, and downstream actions to identify prompt injection, attempted data exfiltration, and other risks before they reach protected resources. Datadog also advises prioritizing controls according to an agent’s exposure and the consequences of its tools, enforcing authorization and sandboxing, separating human, agent, and authenticated-service identities, and using human approval for consequential actions. Rather than treating isolated alerts or operational changes as conclusive evidence, teams should correlate related events within a session and compare behavior with established baselines, while using inline guardrails and detailed traces to block unsafe actions and support investigations.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.