Environment Steering: Using Data Flow Control to Improve Agent Utility and Safety A new arXiv paper (2609.35807v1) proposes "Environment Steering," a runtime defense that models an LLM agent and its harness execution state as database tables, tracks record-level data flows, and checks those flows against declarative policies while the agent runs, feeding policy- and context-specific feedback to steer the agent toward safe trajectories when violations occur. On the AgentDyn benchmark, the approach improved task success rate over no-defense while achieving a 0% attack success rate, according to the authors. arXiv:2609.35807v1 Announce Type: new Abstract: LLM agents can make unsafe tool calls even when instructed to behave safely. Existing defenses constrain agents before execution, modify tool inputs/outputs, or rely on LLM judges; these approaches may depend on model behavior or block unsafe actions without helping the agent recover. We argue that the execution environment should instead enforce safety as the agent runs and steer it toward safe alternatives when violations occur---we call this Environment Steering. We implement this by modeling the agent and harness execution state as database tables, track the record-level data flows, and check these data flows against declarative policies during runtime. When violations are detected, policy- and context-specific feedback steers the agent toward safe trajectories. On AgentDyn, this enables the agent to improve task success rate over no-defense while achieving 0% attack success rate.