Fastly AI Runtime Control is a new request-path layer that routes model calls, tracks usage and applies limits before traffic reaches an AI provider. Fastly launched it on September 21 alongside AI Firewall and expanded API Security, turning its edge network into a policy point for model applications and autonomous agents.
Everyone else is reporting three product names; we are explaining the control boundary. The important change is not another dashboard. It is that governance decisions can sit in the live request path, where a system can route, limit, inspect or reject traffic before the model or enterprise API acts.
How Fastly AI Runtime Control works
Fastly’s documentation says an application sends requests to Runtime Control instead of calling a model provider directly. The service identifies a virtual key, applies limits, substitutes the underlying provider credential and forwards the call to a configured model. The response returns through the same path and the request is recorded.
That layout can separate application developers from raw provider keys and give platform teams one place to attribute consumption. It can also support failover and model choice without requiring every application to implement the same routing rules. Those are product capabilities disclosed by Fastly, not independently measured performance claims.
| Layer | Declared job |
|---|---|
| AI Runtime Control | Route model calls, issue virtual keys, enforce limits and track usage |
| AI Firewall | Inspect prompts and responses for injection attempts |
| API Security | Observe or block agent requests that violate API contracts |
The firewall is optional, not automatic
Fastly’s product documentation makes a useful distinction: security inspection is provided by AI Firewall as a separate add-on and is enabled on selected virtual keys. Administrators can configure detections to log and forward a request or to block it. That means buyers should not assume Runtime Control alone provides prompt-injection filtering.
The announcement says the platform can govern applications calling models, people and systems using AI applications, and agents calling enterprise APIs. API contract enforcement is particularly relevant because an agent can produce syntactically valid requests that still exceed an intended operation or send malformed fields.
What enterprises should test
A request-path control plane becomes operational infrastructure, so latency, availability and failure behaviour matter as much as policy features. Buyers should test what happens when the control layer or a provider is unavailable, how keys are rotated, how logs handle sensitive prompts, and whether detections work on their own traffic.
Fastly said machine-generated traffic exceeded half of its network traffic in July and August, while AI traffic grew 6.5 times faster than human traffic from January through May. Those are Fastly’s own network observations. They help explain the launch, but they do not prove how broadly the new products are deployed.
Lapaas Voice has covered F5’s workforce AI security controls and Zayo’s controlled network actions for agents. Fastly’s approach sits between those layers by governing the request while it is travelling between an application, model and API.
The practical consequence
Fastly AI Runtime Control gives infrastructure teams a common enforcement point without forcing them to standardise on one model vendor. The trade-off is dependency on another live system in the request path. Procurement should therefore demand service-level details, audit controls, regional data handling and measured injection-detection results before treating the platform as a complete security boundary.
The announcement is a real product launch with current documentation. The next evidence should come from customer deployments: latency under load, policy accuracy, failover behaviour and whether agent API controls prevent actions outside approved contracts.
FAQs
What is Fastly AI Runtime Control?
It is a control plane that receives an application’s model requests, applies identity, routing and usage policies, then forwards them to configured AI providers.
Is AI Firewall included automatically?
No. Fastly’s documentation describes AI Firewall as a separately purchased add-on enabled per virtual key.
What does API Security do for agents?
Fastly says it can observe or block agent requests that do not conform to an enterprise API’s declared contract.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



