Environment Steering: Runtime Safety for LLM Agents via Data Flow Control
A new research approach, called Environment Steering, proposes enforcing safety for LLM agents at runtime by steering agents toward safe alternatives based on data flow policy checks, rather than merely blocking unsafe actions or relying on agent behavior pre-execution.
Existing methods for making LLM agents safer—such as constraining them before execution, modifying tool inputs/outputs, or using LLM judges—can falter because they depend on the agent's behavior or simply block unsafe actions without supporting agent recovery or task completion.

Environment Steering introduces data flow control at the execution environment level: it models the agent and its harness state as database tables and monitors record-level data flows, checking them against declarative safety policies during runtime. When a policy violation is detected, the system steers the agent toward safer alternatives with tailored feedback, instead of just blocking the action.
Experiments on the AgentDyn benchmark show that Environment Steering can simultaneously achieve a 0% attack success rate and improve task completion rates compared to setups with no defense.
