Microsoft shipped FIDES (Flow Integrity Deterministic Enforcement System) as an experimental feature in Agent Framework. Every piece of content is labeled with integrity (trusted/untrusted) and confidentiality (public/private) tags; labels propagate automatically through tool calls; policies are enforced before sensitive tools run.
FIDES stops prompt injection by making security deterministic rather than probabilistic. Instead of relying on defensive prompts or allowlists—both of which fail silently—the framework checks labels before each tool call, preventing the model from reaching privileged operations even if it is tricked by injected instructions in untrusted data.
In a concrete example, a GitHub issue triage agent can read untrusted issue bodies (labeled as such) but is prevented from calling post_comment if private content is in scope, and completely blocked from calling write_file with untrusted context. Human approval prompts surface policy violations when approval_on_violation is enabled.
Ask the AI about this article →
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Visko raised $10 million in pre-seed funding from Llama Ventures and opened public access to its first foundat…
AI company Runway has unveiled Solaris, the first model in a new category it calls "Interface World Models." I…

Google's AI search gave advice to call emergency services for users alone with an African, Indian, or Pakistan…

John Deere introduced JD, a conversational AI tool that lets farmers ask open-ended questions about their hist…

Nvidia CEO Jensen Huang said on Fox Business that AI is creating 'hundreds of thousands' of jobs, including in…

Israeli startup DataAgent Ltd