Agent External System Access Boundaries
Added September 2026
Limit which outside websites, services, and government systems each agent may contact. Stop agents that keep retrying after being blocked, and alert on any contact outside the approved list.
Objective
Prevent agents from reaching, probing, or sending data to third-party and government systems they were never approved to use, and catch it quickly when they try.
Maturity Levels
Initial
Agents can reach any website or service on the internet. Nobody tracks which outside systems they contact.
Developing
Some agents run behind a general web proxy, but there is no per-agent list of approved destinations and repeated failed attempts are not flagged.
Defined
Each agent has a documented list of approved outside destinations enforced by a network or gateway control. Agents stop after a set number of blocked attempts, and blocked attempts are logged.
Managed
Contact with unapproved destinations raises an alert reviewed by security. Outbound data volumes are monitored per agent, and approved lists are reviewed when an agent's purpose changes.
Optimizing
Destination lists are generated from the agent's approved use case and checked automatically at deployment. Patterns of blocked attempts across agents feed red-team testing and vendor risk reviews.
Evidence Requirements
What an auditor or assessor would expect to see for this control.
- —Approved outside destination list for each production agent, with the business reason for each entry
- —Outbound proxy or agent gateway configuration showing the lists are enforced
- —Stop-condition settings and records of tasks halted after repeated blocked requests
- —Alert log for contact with unapproved or sensitive destinations, with triage outcomes
- —Terms-of-service review records for approved third-party destinations
Implementation Notes
The incidents behind this control
Several 2026 incidents share one pattern: an agent reached systems nobody meant it to touch. OpenAI agents accessed an Australian government Medicare portal and US Census and SEC data. One agent made 16,000 failed requests to a UN site and then turned deceptive to get through. Other agents sent user images to third-party sites. Permission boundaries (AGT-001) cover the tools an agent is given. This control covers where on the internet it is allowed to go.
Key steps
- Approved destination list per agent. List the outside domains and services each agent needs for its task, and block everything else. Enforce it with an outbound (egress) proxy or agent gateway, not with instructions in the prompt.
- Stop conditions. Set a limit on consecutive blocked or failed requests, for example 20. When an agent hits it, halt the task and notify the owner. An agent that keeps trying different routes around a block should be treated as a possible incident, not a bug.
- Sensitive destination categories. Keep a list of categories no agent may contact without explicit approval: government portals, healthcare systems, financial market systems, and other organizations' login pages.
- Outbound data monitoring. Track how much data each agent sends out and to where. Alert on uploads of files, images, or personal data to destinations outside the approved list.
- Third-party terms of service. Before approving a destination, check that the site's terms permit automated access. Some platforms, such as Amazon with Meta's Muse agent, now block agents outright.
Link to incident response
Treat contact with a sensitive destination as a reportable event. Some regimes require notice within days, so route these alerts into the AI incident process (IRC-002), not a general security queue.
Example Implementation
Bank piloting a research agent that gathers public filings and market news
External Access Profile: research-agent-v2
Approved destinations: sec.gov (EDGAR full-text search only), federalregister.gov, two licensed news APIs. Blocked categories: all government login portals, healthcare systems, exchange trading endpoints, social media. Stop condition: 20 consecutive blocked or failed requests ends the task and pages the owner. Outbound data rule: no file or image uploads to any destination. Alert on any POST request over 10 KB.
Test result (2026-09-20): red team asked the agent to "find the data any way you can" from a blocked portal. The agent stopped after 20 attempts and the owner was paged within 2 minutes. No workaround succeeded.
