TL;DR — Key Takeaways

– Apollo GraphQL is extending GraphOS governance capabilities to AI agents through GraphOS Agent Services.

– The platform is designed to control what data AI agents can access, down to the individual field level.

– GraphOS Agent Services can translate agent requests into API calls, broker credentials and enforce governance policies.

Apollo GraphQL today extended its platform for managing application programming interfaces (APIs) to also make it possible to govern what data an artificial intelligence (AI) agent is allowed to access.

Launched at an Apollo Summit event, GraphOS Agent Services expands the scope of governance capabilities that can be applied via a Model Context Protocol (MCP) server through which AI agents access a knowledge graph that Apollo GraphQL previously embedded in GraphOS, a platform orchestrating access to APIs.

At the same time, Apollo GraphQL is previewing an update to GraphOS Router that improves performance and lowers costs by reducing the time and amount of memory that needs to be allocated to query planning.

Apollo GraphQL also revealed it is now making it possible for an AI agent to query the knowledge graph itself to track launch history, composition errors, lint, router status, and other metrics. 

Finally, the company is making available a set of AI skills that make it simpler to deploy and manage its platform alongside an Operator for deploying its MCP server on Kubernetes clusters.

At its core, GraphOS Agent Services is designed to convert each agent request into the right API calls, broker the access credentials required to invoke a tool or service using a built-in search capability and enforce the appropriate controls down to the individual field level. 

That approach makes it possible for organizations to extend the same framework used to govern APIs to AI agents that are generally invoking APIs to access backend systems, says Apollo GraphQL CEO Matt DeBergalis. Rather than adding a separate platform to manage AI agents, it will prove to be much more cost effective to apply a common set of governance policies to those APIs to ensure compliance mandates are met in a way that is easily auditable, he adds. “We’re making it possible for AI agents to make a better decision,” says DeBergalis.

Additionally, IT teams will be able to better control costs by, for example, limiting the total amount of data that an AI agent might otherwise try to access, he notes.

In effect, Apollo GraphQL, in addition to providing access to the context AI agents require to more reliably automate a task, is now also making it possible to ensure they don’t access sensitive data without express permission, says DeBergalis. That capability will be crucial to foster the ultimate development of an emerging AI economy, he adds.

It’s not clear at what rate organizations are deploying AI agents but there are probably more of them than most business and IT leaders realize. The challenge is finding a way to secure and govern them to prevent any unexpected rogue behavior. AI agents, after all, are programmed to accomplish any task assigned to them by any means necessary unless specifically instructed otherwise.

Of course, there are likely to be multiple incidents involving AI agents before governance policies are consistently applied. The issue then will become finding the fastest way possible to implement those governance policies in a way that causes the least amount of disruption possible.

Frequently Asked Questions

What is GraphOS Agent Services?
GraphOS Agent Services is an Apollo GraphQL offering designed to govern how AI agents access APIs, tools and enterprise data.
How does it control AI agent access?
It converts agent requests into API calls, brokers required credentials and applies controls that can extend down to individual data fields.