Apollo GraphQL is betting that the next big enterprise infrastructure layer is not another model or another agent framework — it is the governance system that stands between AI agents and the APIs they call. The company introduced Apollo GraphOS Agent Services on October 7 at Apollo Summit 2026 in San Francisco, a new set of services designed to give AI agents secure, governed, and auditable access to enterprise systems and APIs, according to the announcement distributed by Apollo via PR Newswire.

The premise is a practical one. Companies racing to deploy AI agents keep hitting the same wall: agents need to call the same APIs that already run the business, but those APIs were designed for trusted human developers, not autonomous software. When an agent asks a customer database for a name and email, the API often returns billing details, internal notes, and other sensitive fields the agent was never meant to see — and those fields can end up in a chat window, a log, or a language model's context window, outside anyone's control.

Field-Level Policy Keeps the Model Out of the Judgment Loop

The centerpiece of Apollo GraphOS Agent Services is a set of capabilities that sit between agents and enterprise systems: search so agents can find the right data and tools, identity to manage credentials for agents acting on their own or on someone's behalf, policy controls that decide exactly what each agent can see and do down to an individual field, and audit logging for observability and compliance. According to the release, the system translates each agent request into the right API calls, brokers the credentials for each one, and enforces controls with no LLM in the judgment loop — the authorization decision is deterministic, not delegated to the model.

That design choice speaks directly to a concern analysts have been raising. Gartner projects that through 2028, at least 80% of unauthorized AI agent transactions will stem from internal policy violations — information oversharing and misguided AI behavior — rather than from external attacks, according to research cited in the announcement. If an agent can reach a field, it will; the only reliable fix is rules that hold every time, regardless of what the model decides.

Intuit is the first named enterprise putting the approach to the test. The financial software company is live in production with GraphOS and piloting Agent Services in private preview, according to the announcement, and Intuit executives described agents analyzing marketing spend against results and proposing changes in real time because the platform exposes only the fields those agents need — with an audit trail of everything. Intuit is joined by American Airlines, Block, and Expedia Group at Apollo Summit 2026 to share how Apollo's platform powers their AI agent work. The launch is being tracked across the industry: analysis of Apollo GraphOS Agent Services reported by RuntimeWire described it as an early but significant move to make API access control the governance layer for enterprise AI.

The launch is part of a broader pattern in the AI agent ecosystem: infrastructure vendors are racing to position themselves as the control plane for agents operating in production. SailPoint recently introduced autonomous agents to govern enterprise AI agents, and similar moves from established API and identity companies suggest the governance layer is becoming the competitive ground. Apollo's advantage is reach — GraphOS currently orchestrates more than 2 trillion API operations per month, according to the company, giving it an enormous existing surface to extend agent controls across.

Router 3.0 and a Full MCP Tool Suite

Alongside Agent Services, Apollo announced continued investment across the GraphOS platform. GraphOS Router 3.0, now in preview, introduces a new request pipeline and query planner that the company says will spend 95% less time on query planning than Router 2.0, with improvements exceeding 300x on the most complex graphs and up to 97% less memory usage, according to the announcement. For agent-heavy workloads, where every extra field also means extra token cost, leaner planning is not just a performance story — it is a cost story.

The GraphOS MCP Server has also grown into a full suite of agent-ready tools for building and managing the graph itself, reported by Apollo. The server now exposes more of the GraphOS Platform API to agents, so tasks like publishing schemas, running checks, and reading diagnostics can be driven in natural language instead of custom code. Apollo describes scenarios where an agent can check whether a graph is healthy using launch history, composition errors, lint, and metrics — the same diagnostics a platform engineer would run by hand, completed in minutes rather than an afternoon. As reported by the Apollo blog, the MCP Server and GraphOS were also named 2026 API Award winners.

Apollo's library of Skills, which teaches agents the company's expertise in areas like Federation, Connectors, and the Router, has grown to 14 skills with more than 47,000 installs, according to the company — evidence that development teams are already putting agents to work inside their GraphQL workflows. The GraphOS Operator for Kubernetes can now centrally deploy and manage the Apollo MCP Server alongside other GraphOS infrastructure.

The announcements arrive as Apollo Summit 2026 runs October 6–8 at The Midway in San Francisco, with more than 30 sessions framed around the idea that an API platform can, and should, become an AI platform. As part of the event, Apollo CEO Matt DeBergalis is hosting a fireside chat with Angie Jones of the Agentic AI Foundation on agentic standards and interoperability, reported by the company — a signal that governance and open standards, not just raw agent capability, are where the industry's attention is shifting.

For enterprises still deciding how much autonomy to grant their agents, Apollo's framing is worth noting: the question is no longer whether agents can access your systems, but what they can see and do once they do — and who can prove what happened. Field-level policy with an audit trail is Apollo's answer, and with Intuit piloting in preview, the market will soon see whether deterministic governance becomes the standard way AI agents touch production APIs.