cd /news/ai-agents/akamai-and-mulesoft-unify-runtime-en… · home topics ai-agents article
[ARTICLE · art-126215] src=forkast.news ↗ pub= topic=ai-agents verified=true sentiment=↑ positive

Akamai and MuleSoft Unify Runtime Enforcement Across Agent Fabric – Bridging the Gap Between Security Policy and AI Orchestration

Akamai and MuleSoft announced an expanded collaboration on September 10, 2026 that integrates Akamai API Security with MuleSoft's Agent Fabric, already in use by more than 20 joint customers, to enforce security policy across AI agent orchestration. The integration creates a bidirectional feedback loop in which MuleSoft Exchange syncs API specifications and environment data to Akamai while Akamai returns behavioral analytics and threat risk scores to the MuleSoft control plane. The move follows the 2026 Akamai API Security Impact Study finding that 87% of organizations reported an API-related security incident during 2025, and builds on MuleSoft Agent Fabric, launched in September 2025.

by read3 min views1 publishedSep 10, 2026
Akamai and MuleSoft Unify Runtime Enforcement Across Agent Fabric – Bridging the Gap Between Security Policy and AI Orchestration
Image: Forkast (auto-discovered)

The enterprise agent economy is shifting toward a more disciplined phase of runtime enforcement as infrastructure providers move to secure the connections powering autonomous systems. On September 10, 2026, Akamai and MuleSoft announced an expanded collaboration that integrates Akamai API Security with MuleSoft’s Agent Fabric. This move represents a critical bridge between edge security and agent orchestration, effectively turning the network perimeter into a policy enforcement layer for AI agents.

The timing is driven by necessity. According to the 2026 Akamai API Security Impact Study, 87% of organizations reported an API-related security incident during 2025. As agents proliferate, they rely heavily on APIs and Model Context Protocol (MCP) servers to interact with enterprise data. Without visibility, these connections become vectors for shadow AI and unmonitored data exfiltration. The integration, already in use by more than 20 joint customers, aims to solve this by creating a bidirectional feedback loop: MuleSoft Exchange syncs API specifications and environment data to Akamai, while Akamai feeds behavioral analytics and threat risk scores back into the MuleSoft control plane.

This architecture builds upon the foundation laid by MuleSoft Agent Fabric, which launched in September 2025 to provide a unified solution for discovering, orchestrating, and governing agents. As Andrew Comstock, SVP & GM at MuleSoft, noted, Agent Fabric serves as the foundation of their multi-agent evolution, bringing agents under one umbrella to discover each other at runtime and route tasks based on intent. By layering Akamai’s edge security on top, organizations can now apply granular policy controls to these interactions. As Oz Golan, VP API Security Product & Engineering at Akamai, explained, security teams cannot protect APIs they cannot see or understand in context; this collaboration connects management context with security insights to improve inventory accuracy and reduce risk across the APIs and MCP servers powering modern applications.

This development is a tangible step forward in the governance-to-enforcement pipeline, aligning with the broader convergence of standards bodies discussed in our previous coverage of the three standards bodies currently shaping the industry. The OWASP Agent Control Standard is focused on runtime enforcement, the NIST AI Agent Standards Initiative is tackling identity and authorization, and the Linux Foundation AAIF is driving interoperability. The Akamai-MuleSoft integration effectively operationalizes these theoretical frameworks, moving governance from documentation into the live traffic flow of the enterprise.

However, the deeper issue remains: while the plumbing of APIs and MCP servers is becoming more secure, the specification layer underneath remains dangerously underserved. Research published in the UC Berkeley MAST taxonomy at NeurIPS 2025 shows that 79% of multi-agent failures are traced to specification problems rather than model capability or infrastructure limitations. Even with robust runtime enforcement, if the underlying intent or task specification is flawed, the agent will simply execute a failure with high precision. The industry is currently solving for the how of enforcement, but the what of agent behavior – the precise, machine-readable specifications that define agent boundaries – remains a fragmented landscape of vendor-specific implementations.

For builders and infrastructure decision-makers, this shift necessitates a change in strategy. The focus must move beyond securing model endpoints toward implementing granular policy controls at the API and MCP level. This is a move toward governance-as-code, where security policies are baked into the orchestration layer rather than bolted on as an afterthought. By simplifying inventory management and automating threat detection, teams can reduce the surface area for shadow AI, but they must remain cognizant that this does not replace the need for rigorous, standardized agent specifications. The roadmap for the second half of 2026 suggests that this integration will only deepen. Planned updates include native MuleSoft onboarding features and expanded runtime security specifically for AI and MCP environments. These capabilities will be demonstrated at Salesforce Dreamforce from September 15-17, 2026, providing a clearer view of how these tools will function in production environments.

While the governance-to-enforcement pipeline is clearly working, the tension between vendor-specific implementations and the need for universal, open standards will continue to define the infrastructure beat. Securing the rails is a necessary prerequisite for the agent economy, but it is only the first step in ensuring that agents actually do what they are specified to do.

── more in #ai-agents 4 stories · sorted by recency
── more on @akamai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/akamai-and-mulesoft-…] indexed:0 read:3min 2026-09-10 ·