Amazon Web Services (AWS) has released an instance of the open source Dogwood framework for using code to embed governance policies in agentic artificial intelligence (AI) workflows.
The Dogwood Local Engine makes it possible to embed the engine as a library in a harness running on a local machine to create an enforcement layer in an agentic AI workflow to apply policies based on temporal conditions involving, for example, a record of past actions or the order in which the actions occurred. For example, a policy that permits a coding agent to perform a git push only if a repository’s tests were successfully run within the last few minutes could be embedded into a workflow.
Dogwood Local Engine is an extension of an existing Dogwood policy-as-code framework that AWS released earlier this year. An event is a timestamped record of one step of a tool call, with each one typically recording two events: a request event when the agent calls the tool and a response event when the tool returns its result. The events form the history against which the engine evaluates temporal conditions. The engine only issues allow/deny verdicts for request events. Response events then record the outcome. The harness submits a request event to the engine and runs the tool only if the engine allows it. After the tool returns, the harness submits the response event.
The overall goal is to make it easier for organizations to incorporate a policy engine into the harnesses that builders rely on to create an agentic AI application on their local machine, says Marc Brooker, a vice president and distinguished engineer at AWS.
That approach provides the dual benefit of reducing latency while also making it simpler to extend policies to any dependencies that might exist in a workflow, he adds.
While at this point there is no doubt that AI agents are powerful, it’s also become apparent they require a significant amount of supervision. AI agents have shown a propensity to ignore guardrails as they seek to complete a task. The only way to ensure that AI agents are not attempting to execute a task that goes beyond the scope of the mission is to apply policies into the code that was used to build them in the first place.
It’s not clear how many AI agents the average organization is going to build and deploy, but they are rapidly becoming pervasive. “They are going to be one of the most important workloads of the future,” says Brooker.
The challenge right now is that most organizations don’t have the level of control over AI agents that they should, starting with isolating them in a runtime and then being able to intercept as needed and, finally, applying policies that prevent them from going rogue.
Hopefully, there will come a day when governance policies are routinely embedded in every AI agent. In the absence of that code, however, organizations should assume that an AI agent is not to be trusted unless proven otherwise.


