LangChain outlines a governance framework for enterprises deploying AI agents, arguing that LLM gateways should act as a runtime control plane for cost, security, and compliance. The proposed operating model has five parts: govern, decide, protect, observe, and assure, covering requirements like authentication, audit logging, and data residency. It recommends applying controls to LLM calls, tool invocations, and agent-to-agent interactions, using pattern-based and model-based detection to protect sensitive information, and integrating gateway decisions with tracing and evaluation systems.
