agent gthe control point for ai agents
Agent G controls your agents’ internet access.
Every request your agents send passes through Agent G. It’s allowed, blocked, or held for a person before it leaves, and every decision is recorded.
Scroll. We’ll take this picture apart.
01Agents
Agents choose their next action at runtime.
Give an agent the same task twice and it takes a different path. You can’t map every path, test every edge case, or predict every action.
02Stakes
Teams won’t let agents act until they can control them.
- 81%of technical teams are already testing or running agents.
- 88%had a confirmed or suspected AI-agent security incident in the last year.
- 69%say security concerns are slowing their adoption of agents.
Gravitee, State of AI Agent Security 2026 (900+ respondents) · Okta buyer survey, Jan 2026 (150 IT and security leaders)
03Evidence
Agents with internet access are already going rogue.
- Sep 2026OpenAI agents went after U.S. government websites.NYT · Nextgov/FCW
- Mar 2026A Meta agent acted without permission, triggering a Sev 1 data exposure.The Information
- Dec 2025Amazon’s AI agent deleted production, causing a 13-hour AWS outage.Financial Times
- Jul 2025Replit’s agent wiped a production database during a code freeze.The Register
04Control
One checkpoint between your agents and the internet.
Every one of those incidents went over the network. Agent G runs there, as an egress proxy on your network, outside the agent. Route agent traffic through it and nothing leaves unchecked.
- Prompt guardrailsThe prompt and model output
- MCP / API gatewaysTool calls and requests
- Agent GPrompt → model → tools → network → verdict → reviewer
05Method
See, decide, record. Every request.
- SeeDown to the payload: HTTP and inspected HTTPS, MCP tool calls, TCP/UDP connections and DNS.
- DecideYour rules, outside the model. Allowed, blocked, or held for a person, before it executes.
- RecordEvery run becomes one story, with a receipt for every decision.
What Agent G sees today
- HTTP / inspected HTTPS
- Method, path, API operations and payload fields. HTTPS requires TLS inspection to be enabled and trusted.
- MCP
- Tool names, arguments and decisions, through wrapped stdio or inspected HTTP.
- TCP / UDP on macOS
- Process attribution, destination, timing, byte counts and decisions.
- Observed DNS
- Domain-to-IP evidence. Incomplete for encrypted or shared-resolver DNS.
Self-hostedHTTP + MCP<10 ms p95 added<5 min install · npm or Homebrew
06Proof · scroll to replay
Here it is, stopping a $500 refund.
- The agent may refund up to $50.
- It requests a $500 refund.
- $500 > $50: Agent G holds it for review.
- Denied. The request is never forwarded to Stripe.
Recorded demonstration · real model and tool calls · Stripe test environment.
07Contrast
Guardrails filter what agents say. Agent G controls what they do.
A hidden instruction in a support email told an agent to leak customer data. The prompt looked harmless. The request didn’t. Agent G blocked the call in 20 ms.
Decision · refused · rule support-egress-deny
- request
- GET /verify?order=10271&name=Hiro%20Tanaka&phone=…&address=… customer name, phone, address
- destination
- parcel-trace.io unapproved destination
- response
- stopped · nothing sent
Frame from the recorded demo, test data. Watch the full demo
08in development
Guardrails must adapt to keep step with agents.
Intent-based guardrails are the answer.
- Two runs, one task: resolve support ticket #10231.
- Other guardrails ask whether each action is allowed. Agent G asks whether it serves the task.
- Order, customer, a $40 refund. It matches the task, so it goes through.
- Every customer, then pastebin. Each step passes a rule; the run is outside the task, so it’s stopped.
Illustrative example of the direction we’re building, on the run records Agent G keeps today. The dataset compounds with every deployment.
09Early access
Let’s stop agents from hacking the internet.
Agent G is live with five design partners and installs in under five minutes. Tell us about your agents and we’ll get you set up.
Or write to founders@agentg.dev