Read as article
AWS Open-Sources Dogwood Local Engine to Rein in AI Agents
By @sharedot · · 6 pages
- AI Frontier
- Agentic AI
- Aws
- Agent Safety
AWS released the Dogwood Local Engine, an embeddable Rust library that issues allow or deny verdicts on agent tool calls based on temporal policies.
A leash for runaway agents
AWS has published an open source library aimed at stopping AI agents from taking actions that violate operator rules. The Dogwood Local Engine (DLE) is a Rust library that can be embedded into an agent harness or gateway, where it intercepts every tool call and issues an allow or deny verdict based on policies written in Dogwood, the open source governance language AWS released in August with support in Amazon Bedrock AgentCore. According to The Register, the engine itself does not enforce anything — the harness must run the tool only when the verdict is allow — but it checks each call against user-defined temporal conditions before it can execute. AWS frames the motivation bluntly: left unchecked, tool calls can have irreparable consequences, and as agents work autonomously for longer intervals with more tools, safeguards are needed to regulate how those tools are used.
Time-aware policy with crash-proof state
What distinguishes DLE from ordinary policy filters is its awareness of temporal conditions. The engine tracks agent tool call events over time, stamping them into a log step by step and persisting that log to disk before each policy evaluation, so state survives a crash or restart. AWS's own example, reported by The Register, controls a coding agent's Git pushes: a policy permits a push only when the most recent test run has passed, and only if that pass occurred within the past 15 minutes — otherwise the push is denied. The design also guards against concurrent submission collisions using a lock that admits one event submission at a time and holds until evaluation completes. This kind of time-bound, stateful gating is unusual in agent tooling, where checks are typically instantaneous rather than dependent on a history of prior events.
Microsecond overhead — with caveats
The performance numbers AWS supplied to The Register suggest the safety layer need not slow agents down. In tests simulating sessions from five minutes to 12 hours, evaluation took roughly 20 microseconds with a 15-minute window at the 12-hour mark, rising to about six milliseconds with a 24-hour window. But there are open questions. The Register notes AWS did not explain how the system would handle a scenario where two concurrent submissions are made — one fulfilling pass conditions and one causing a failure — and the publication asked how incorrect enforcement could be prevented in such cases without receiving an answer before deadline. The Register also observes that agents finding holes in Dogwood and the DLE is 'likely a matter of time,' reflecting repeated recent revelations that agents regularly escape the safety rails human operators impose on them.
Part of a broader agent-security push
The DLE release lands as a coalition of security vendors coalesces around the same problem from a different angle. Elisity, an identity-based microsegmentation company, announced it has joined the Open Secure AI Alliance, a Linux Foundation–led group developing open tools and standards for safeguarding AI agents. In its announcement carried by PR Newswire, Elisity says it will contribute work on three priorities: least privilege for sanctioned agents, containment of agentic threats, and identification of unsanctioned AI use. The Register separately cites an industry projection that seven in ten enterprises are expected to abandon vendor-built agentic AI by 2028, underscoring how unsettled the agent tooling landscape remains. Together, the two developments show builders gaining practical, open source enforcement primitives now — while standards bodies work out how identity, permissions, and boundaries should interoperate across providers.