Introduces Sapien, a policy engine that enforces stateful contextual security policies on AI agent tool calls via regular expressions extended with state tracking.

Topological visualization of Sapien: A Stateful Policy Engine for Autonomous AI Agents
Brave API

Sapien is a stateful policy engine for autonomous AI agents that prevents rogue actions by enforcing task-specific contextual policies on tool calls. It operates by synthesizing a policy from the user’s prompt and tool documentation, then using an augmented nondeterministic finite automaton to track agent progress and variable bindings across multi-step tasks.

The engine extends regular expressions with stateful predicates, deferred policy generation, and scoped semantic checks to allow fine-grained control over permitted tool-call sequences. This approach ensures that actions are validated against both the immediate request and the agent’s historical trajectory, blocking unauthorized sequences even if the underlying model is compromised.

In evaluations, Sapien demonstrated high utility and security, ruling out 93–95% of attacks on the AgentDojo benchmark and 62–85% on Toolathlon. These results indicate that stateful enforcement significantly outperforms static tool allowlists by permitting sensitive tools under tight, context-aware bounds rather than denying them entirely.

Generated 2d ago
Open-Weights Reasoning

The material introduces Sapien, a runtime policy engine for autonomous AI agents that constrains tool calls rather than merely filtering prompts or individual actions. Its motivating problem is that agent security failures are often contextual: a sequence of individually benign operations—reading a file, querying a database, invoking an API, sending a message—can become dangerous when considered together. Sapien addresses this by representing policies as regular-expression-like patterns augmented with state tracking, enabling the engine to remember relevant facts across a session and evaluate each incoming tool call against the evolving context.

Its main contribution is a practical mechanism for stateful, context-aware authorization at the agent–tool boundary. By maintaining per-agent or per-session state and checking tool invocations as they occur, Sapien can express constraints that static allowlists or stateless regex rules cannot, such as requiring a prior approval step, limiting follow-on actions after sensitive reads, or blocking certain destinations unless earlier conditions were satisfied. This makes the security layer auditable, deterministic, and decoupled from the underlying language model, so policies can be updated without retraining or changing agent behavior.

The work matters because autonomous agents are increasingly granted access to real-world tools, and the dominant security model—per-call permissioning, prompt instructions, or simple pattern matching—does not capture multi-step risk. Sapien’s stateful approach offers a missing layer of governance for agentic systems: it can prevent policy violations that only emerge over time, provide a clear enforcement point for tool calls, and support safer deployment of agents in environments where actions have persistent external effects.

Generated 2d ago
Sources