OpenAgentFlow Secures Heterogeneous AI Agent Fleets System-Wide

Dongsheng Chen, Xiangyu Zhao, Xin Yao, Xuetao Wei· September 2, 2026 View original

Key takeaways

  • Managing safety in heterogeneous AI agent fleets requires a system-level action governance approach.
  • OpenAgentFlow provides a control-plane/action-plane architecture for unified safety enforcement.
  • It normalizes all agent actions into a single stream, routed through a shared Policy Enforcement Point.
  • The system enables dynamic policy updates, auditability, and consistent safety without modifying individual agents.

Who benefits

AI DevelopmentCybersecurityEnterprise SoftwareRoboticsAutomation

Summary

OpenAgentFlow introduces a control-plane/action-plane architecture that enforces system-level safety boundaries for diverse AI agent fleets by normalizing all agent-generated actions into a unified stream and routing them through a shared policy enforcement point. This allows for consistent action governance, auditability, and dynamic policy updates across heterogeneous agents.

As AI agents evolve from isolated assistants to complex, heterogeneous systems where multiple agents, planners, and execution backends interact within a shared environment, ensuring safety becomes a critical system-level challenge. Existing safeguards often operate in silos, leading to fragmented enforcement, obscured risks in multi-step action flows, and limited support for auditing or evolving policies. OpenAgentFlow addresses these issues by proposing a novel control-plane/action-plane architecture. This system unifies all agent-generated actions—including GUI actions, API calls, tool calls, and LLM-generated invocations—into a single "AgentEvent" stream. Each event is then routed through a shared Policy Enforcement Point before being committed, allowing for consistent governance. The control plane maintains provenance, session state, audit records, and updatable policies, enabling new rules to take effect without modifying individual agents, prompts, models, or execution paths. Demonstrated on Android, OpenAgentFlow achieved high accuracy (94.0%) and attack block rates (95.3%) on an action-event benchmark, and successfully adapted to dynamic policy changes. These results confirm that OpenAgentFlow provides a practical, shared enforcement boundary for managing safety across diverse AI agent fleets.

Why it matters

For organizations deploying multiple AI agents, ensuring system-wide safety, compliance, and auditability is paramount. OpenAgentFlow offers a crucial architectural solution to manage and govern agent actions centrally, mitigating risks and enabling scalable, responsible AI deployment.

How to implement this in your domain

  1. 1Evaluate your current AI agent deployments for fragmented safety controls and potential system-level risks.
  2. 2Explore integrating an architecture like OpenAgentFlow to establish a unified action governance framework for your agent fleet.
  3. 3Define clear, updatable safety policies that can be enforced at a central Policy Enforcement Point.
  4. 4Implement robust logging and auditing mechanisms for all agent-generated actions to ensure transparency and accountability.
  5. 5Pilot OpenAgentFlow or similar control-plane solutions in a controlled environment to test its effectiveness in managing heterogeneous agents.

Original post by Dongsheng Chen, Xiangyu Zhao, Xin Yao, Xuetao Wei

"arXiv:2609.00015v1 Announce Type: new Abstract: AI agents powered by large language models are evolving from isolated assistants into heterogeneous systems in which multiple agents, planners, controllers, and execution backends operate over the same user or enterprise environment…"

View on X

Originally posted by Dongsheng Chen, Xiangyu Zhao, Xin Yao, Xuetao Wei on X · view source

Want to go deeper?

Turn these trends into skills with Learnijoy's hands-on AI & tech courses.

Explore courses