> Markdown version of [/videos/100552-i-don-t-trust-ai-agents-and-neither-should-you-building-production-ready-architectures](https://www.wearedevelopers.com/videos/100552-i-don-t-trust-ai-agents-and-neither-should-you-building-production-ready-architectures). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # I Don't Trust AI Agents (And Neither Should You): Building Production-Ready Architectures Are your AI agents exposing sensitive customer data? Stop trusting unpredictable models blindly. Build resilient, production-ready architectures with strict guardrails to contain the blast radius. - **Speakers:** [Darko Mesaros](https://www.wearedevelopers.com/@darko-mesaros) - **Event:** World Congress 2026 North America - **Published:** September 24, 2026 - **Duration:** 31:41 - **URL:** https://www.wearedevelopers.com/videos/100552-i-don-t-trust-ai-agents-and-neither-should-you-building-production-ready-architectures ## Summary AI agents are prone to spectacular, high-stakes failures in production—from hallucinating non-existent refund policies to exposing sensitive customer data. Instead of placing blind trust in an unpredictable large language model, engineering teams must design robust, layered architectures around their agents. Building resilient AI applications requires treating them with the same rigorous system design and security principles applied to traditional software, ensuring that even if the agent fails, the blast radius is tightly contained. To mitigate agentic risks, developers can adopt a multi-layered defense strategy using tools like the Strands Agent SDK and Amazon Bedrock AgentCore. The first layer involves implementing strict guardrails to automatically redact PII and deflect prompt injection attacks before they ever reach the model. Next, steering agents—acting as secondary LLM evaluators—sit between the primary agent and the user to validate responses and catch unfulfilled tool calls. For data access, injecting deterministic parameters via Model Context Protocol (MCP) interceptors prevents agents from hallucinating user IDs, ensuring they only fetch records authorized for the current session. Protecting high-stakes transactions demands deterministic tool authorization. By leveraging Dogwood, an open-source policy language from AWS, teams can enforce temporal rules and value thresholds—such as requiring human approval for large refunds or mandating eligibility checks before generating return labels. Finally, continuous observability and batch evaluation are critical for auditing agent behavior and enforcing accountability. Rather than deploying a single monolithic agent with excessive permissions, engineers should route tasks to scoped sub-agents, creating a trustworthy operational pipeline where safety is baked into the infrastructure rather than expected of the AI. **Keywords:** ai agent safety, production-ready ai architectures, large language model hallucinations, prompt injection prevention, amazon bedrock agentcore, strands agent sdk, model context protocol interceptors, steering agent evaluators, automated pii redaction, deterministic tool authorization, dogwood policy language, cedar policy language, ai application observability, agentic batch evaluation, scoped sub-agent routing ## Chapters 1. **Recognizing creative failures and risks in AI agents** (00:12) — Real-world agent failures highlight the need to build robust safety systems around large language models. 1. **Categorizing common failure modes in AI agents** (03:31) — Agents typically fail by providing incorrect information, executing harmful actions, or succumbing to prompt injection attacks. 1. **Defining the fundamental AI agent loop architecture** (04:32) — A standard agent architecture combines a large language model, an MCP server for tools, and specific routing SDKs. 1. **Adopting a layered approach to agent safety systems** (06:00) — Designing secure AI applications requires multiple defense dimensions rather than relying solely on the language model. 1. **Implementing guardrails to prevent user abuse and injection** (06:50) — Applying specific guardrails automatically redacts sensitive data and restricts unsafe topics from reaching the underlying model. 1. **Enforcing reliable responses using a steering agent** (08:48) — An intermediate steering language model intercepts and reviews agent responses to catch hallucinations or forgotten tool calls. 1. **Securing data access through deterministic MCP interceptors** (11:12) — Intercepting tool calls to deterministically inject customer authentication prevents agents from hallucinating parameters and leaking cross-account data. 1. **Controlling high-stakes transactions with deterministic policy languages** (14:39) — Evaluating every tool call against defined rules using policy languages prevents agents from executing unauthorized or out-of-order actions. 1. **Establishing robust observability and batch evaluation loops** (20:27) — Implementing continuous tracing and periodic evaluations against chat logs ensures accountability and measures ongoing agent performance. 1. **Combining probabilistic and deterministic controls for AI trust** (24:04) — Trust is established by building layered safety pipelines around the agent rather than inherently trusting the underlying model. 1. **Managing general purpose compute and sub-agent architecture** (26:13) — Limiting agent scope through specialized sub-agents mitigates context limits and improves overall system security and observability. ## Related Moments - [Why tool-using AI agents require behavioral governance](https://www.wearedevelopers.com/videos/100518-test-before-release-enforce-at-runtime-governance-for-tool-using-ai-agents) (from "Test Before Release, Enforce at Runtime: Governance for Tool-Using AI Agents") - [Best practices for implementing reliable AI agent frameworks](https://www.wearedevelopers.com/videos/1533-infrastructure-as-prompts-creating-azure-infrastructure-with-ai-agents) (from "Infrastructure as Prompts: Creating Azure Infrastructure with AI Agents") - [Architecting autonomous agents for production lifecycle management](https://www.wearedevelopers.com/videos/100273-the-agentic-enterprise-orchestrating-people-ai-and-european-sovereignty) (from "The Agentic Enterprise: Orchestrating People, AI, and European Sovereignty") - [Shattered security assumptions in the age of AI](https://www.wearedevelopers.com/videos/100607-the-new-security-stack) (from "The New Security Stack") - [Resolving developer challenges in AI agent implementation](https://www.wearedevelopers.com/videos/1532-agentic-ai-from-theory-to-practice-developing-multi-agent-ai-systems-on-azure) (from "Agentic AI - From Theory to Practice: Developing Multi-Agent AI Systems on Azure") - [Security integration and AI skepticism in developer tooling](https://www.wearedevelopers.com/videos/1830-wearedevelopers-live-speculaitions) (from "WeAreDevelopers LIVE - SpeculAItions") ## Related Articles - [ I Gave a Video Editor More Autonomy Than a Trading Bot. On Purpose.](https://www.wearedevelopers.com/magazine/773-i-gave-a-video-editor-more-autonomy-than-a-trading-bot-on-purpose) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Never delegate the understanding](https://www.wearedevelopers.com/magazine/749-never-delegate-the-understanding) - [From Prototype to Production: Build AI Agents with This Free 4-Course Learning Path](https://www.wearedevelopers.com/magazine/655-from-prototype-to-production-build-ai-agents-with-this-free-4-course-learning-path) ## Related Jobs - [Senior AI Developer](https://www.wearedevelopers.com/jobs/ext/2836034-senior-ai-developer) at **PwC** - [Senior AI/ML Engineer](https://www.wearedevelopers.com/jobs/48352-senior-ai-ml-engineer) at **PagerDuty** - [Head of Agentic AI / Lead AI Engineer](https://www.wearedevelopers.com/jobs/48488-head-of-agentic-ai-lead-ai-engineer) at **1st solution consulting gmbh** - [Partner Sales Director - AI Alliances - Model Providers](https://www.wearedevelopers.com/jobs/48429-partner-sales-director-ai-alliances-model-providers) at **Dynatrace** - [Director, AI & Data Solution Architect](https://www.wearedevelopers.com/jobs/ext/3542179-director-ai-data-solution-architect) at **PwC** - [Director, AI & Data Solution Architect](https://www.wearedevelopers.com/jobs/ext/3557941-director-ai-data-solution-architect) at **PwC**