Home Blog Page 19

Generate single title from this title Top AI Agent Development Companies for US Clients: 2026 Guide in 100 -150 characters. And it must return only title i dont want any extra information or introductory text with title e.g: ” Here is a single title:”

Write an article about

Hundreds of software companies now claim to build AI agents. Most only added “agentic AI” to their pitch deck in 2023 – long before they had time to deploy, harden, and iterate on systems that survive real traffic, edge cases, and business pressure. Gartner predicts that over 40% of agentic AI projects will be canceled by the end of 2027. That number isn’t a technology problem. It’s a vendor selection problem. This guide exists to help you solve it: 15 AI agent development companies for US clients that have actually shipped to production — not just to a demo stage.

Choosing the right partner means filtering out vendors who can stage a slick presentation from those who can keep an agent stable at six, twelve, and eighteen months after launch. That’s when shortcuts around data, integration, and governance surface as broken workflows, rising costs, or quiet failures nobody warned you about.

What you’ll find in this guide:

  • Why most AI agent projects fail — and the specific warning signs to look for during vendor evaluation
  • The five criteria used to select every company on this list
  • 15 vetted AI agent development companies, each with a clear “best for” so you can build a shortlist fast
  • A side-by-side comparison table covering pricing, deployment options, and key differentiators
  • Real-world use cases where production AI agents are delivering measurable ROI in 2026
  • A practical framework for choosing the right partner based on your industry, stack, and scale

 

Why AI Agent Projects Fail and What Good Development Partners Do Differently

If you’ve already run discovery calls with AI agent vendors, you’ve probably heard the same script: proprietary frameworks, big-name client logos, and a polished demo. What almost never comes up is where these projects usually break, and the truth is, they tend to fail in the same ways.

AI Agents Built for the Demo

An agent that looks impressive in a controlled demo with clean data and a fixed prompt may break once it encounters real customers, messy inputs, and live systems. When a team optimizes for the presentation rather than everyday operations, the weak spots only surface after going‑live. This frequently happens around the six‑month mark, when a rebuild is the only realistic path forward.

Shallow Integration

An AI agent that can’t connect cleanly to your CRM, ERP, data warehouse, or operational tools is just another silo. Production‑grade solutions rely on deep, often unglamorous integration work. Vendors without that experience under‑scope or delay integrations to keep proposals appealing, and the gaps later show up as manual workarounds and broken processes.

Governance Added Too Late

Agents launched without solid logging, drift detection, and clear escalation paths don’t stay reliable for long. Data changes, products evolve, and edge cases multiply. Organizations should plan to spend 15-20% of the initial build cost each year on retraining and model‑drift corrections. That investment only makes sense if governance and observability were designed in from the start; when they’re not, fixes are slower, risk is higher, and costs climb quickly.

The Budget Reality Most Vendors Skip

Data preparation often consumes around 30% of an AI agent project budget before a model is even selected. Cleaning, labeling, and structuring data so an agent can use it safely is real work, and it has to be done somewhere in the project. If a vendor’s estimate doesn’t account for that effort, it’s a clear sign they’ve never taken an agent from concept to stable production.

What a Real Engagement Looks Like

A serious AI agent development partner follows a clear path: 

  • Scoping and use‑case validation. 
  • Agent architecture design.
  • Model and tooling choices. 
  • Integrations with your systems. 
  • Memory and orchestration logic.
  • Governance and monitoring setup. 
  • Phased rollout. 
  • Ongoing iteration. 

Each stage depends on the strength of the one before it. When any of them are skipped or rushed, you end up with a system that cracks the moment real conditions change.

 

How We Selected the Top AI Agent Development Companies in the US for this List 

Every firm on this list was evaluated against five criteria: 

  1. Agent maturity. Can they build agents that handle multi-step workflows, call external tools, retain useful memory, and adapt based on outcomes? The baseline test is simple: do they have real production deployments to point to? 
  2. Enterprise readiness. A focused agent handling support ticket routing can be live in 3 to 6 weeks. A multi-system agent with compliance requirements usually takes 3 to 6 months. The companies here have operated across the full range and know what each stage really costs in terms of time and budget.
  3. Integration depth. An agent that can’t connect cleanly to your CRM, ERP, data warehouse, or operational APIs creates a new silo instead of removing one. We prioritized firms with proven integration work across the systems their clients use, not vague “API-ready” claims.
  4. Governance and observability. Logging, drift detection, performance monitoring, and human escalation paths have to be designed in from the very beginning. Vendors that treat governance as an afterthought tend to ship agents that quietly degrade and become expensive to maintain.
  5. Industry specialization. Compliance-heavy agents for healthcare and financial services typically cost around 25% more than generic deployments and demand deep domain knowledge. We weighted sector-specific experience heavily in verticals where regulation shapes data architecture and model choices.

 

The Best AI Agent Development Companies for US Clients to Consider in 2026 

The companies listed below were selected based on the criteria above. The list intentionally spans different sizes and engagement models because the right partner depends on your scale, industry, and how much of the build you want them to own. Each entry includes a clear “best for” so you can see, at a glance, which firms are worth a closer look.

Company HQ/delivery Hourly rate Min. project Deployment Key differentiator
LITSLINK Palo Alto, CA $50–$99/hr $5,000+ Cloud (AWS, Azure, GCP) Single team for AI, backend, infra, and deployment. No handoffs or subcontractors
LeewayHertz San Francisco, CA $50–$99/hr $10,000+ Cloud, client infra via ZBrain ZBrain platform — agents run on the client’s own data, no third-party exposure
SoluLab Los Angeles, CA Under $50/hr $25,000+ Cloud Fastest path to MVP — no discovery phase gate before build starts
Markovate San Francisco, CA $50–$99/hr $50,000+ Cloud Rapid POC in weeks before full build commitment — lowers financial risk
Master of Code Global Victoria, Canada / US clients $50–$99/hr $25,000+ Cloud 20 years of conversational AI delivery; LOFT framework cuts setup effort by 43%
Deviniti Poland/global $50–$99/hr $25,000+ Cloud, self-hosted, on-premise Fully self-hosted deployment as standard — data never leaves client infrastructure
Intellectyx Denver, CO/India delivery $25–$49/hr $25,000+ Cloud, hybrid AgentOps framework — monitoring and optimization built in, not bolted on post-launch
Azilen Technologies Irving, TX/global $25–$49/hr $10,000+ Cloud Pre-built integrations with HiBob, Workday, SAP — platform depth before the engagement starts
BotsCrew US + Ukraine $50–$99/hr $10,000+ Cloud #1 Clutch chatbot ranking 6 years running; CourtAvenue-backed; Forbes 30 Under 30 founders
Inoxoft Philadelphia, PA/Europe delivery $25–$49/hr $25,000+ Cloud 1–4 week deployment for scoped agents; 5.0/5 Clutch across 74 verified reviews
Neurons Lab UK/Singapore/North America On request $100,000+ Cloud (AWS), regulated infra ARKEN platform purpose-built for FSI — not adapted from a general-purpose framework
Intuz US/global delivery $25–$49/hr $10,000+ Cloud 17+ years of delivery across 40+ countries — cross-regulatory experience built into standard practice
DevCom Florida, US/Ukraine delivery $25–$49/hr $25,000+ Cloud US legal entity + Ukraine delivery rates — domestic accountability without offshore-only economics
TRooTech US/global delivery $25–$49/hr $25,000+ Cloud Agents embedded into Salesforce, HubSpot, Dynamics — not deployed as separate tools
Azumo US/Latin America delivery $25–$49/hr $10,000+ Cloud, self-hosted, VPC Self-hosted and VPC deployment — built for buyers where data residency is a hard procurement requirement

LITSLINK: Best AI Agent Development Company for Full-Stack Delivery

LITSLINK is one of the best AI agent development companies in the US. Founded in 2014 and headquartered in California, it has shipped 300+ products across HealthTech, FinTech, SaaS, and enterprise software. Its AI practice spans the full stack, from agent architecture and LLM integration to machine learning, AI-as-a-Service, and cloud infrastructure on AWS, Azure, and GCP, so one team owns the build end-to-end instead of stitching together subcontractors. If this sounds like the model you’ve been looking for, the team is easy to reach.

What they build

LITSLINK develops custom AI agents end-to-end, from use case scoping and agent architecture through LLM integration, backend engineering, system connectivity, and cloud deployment. Their agents span autonomous workflow agents, AI copilots, LLM‑powered chatbots, and AIaaS setups that plug into existing products and operations. On the compliance side, their HealthTech and FinTech work means they’ve already handled HIPAA‑regulated builds and sensitive data environments, not just generic automation projects.

Why they stand out

Most development firms hand projects off between separate AI, backend, and infrastructure teams. LITSLINK runs a single team across the full stack, which cuts the coordination overhead that usually stalls mid-build. Clients don’t juggle a fragmented vendor chain; one group owns the work from scoping through go-live and post-launch iteration. For companies without internal AI engineering depth, that structure directly lowers the risk of the failure modes outlined above.

A practical differentiator: LITSLINK publishes an AI Cost Estimation Calculator, making it one of the few US development firms to offer budget transparency before a discovery call. In a market where most vendors insist on a scoping engagement before sharing numbers, that level of upfront clarity signals a different kind of relationship with the buyer.

Core services: 

  • AI agent architecture and development.
  • LLM integration. AI chatbot development. 
  • Machine learning services. 
  • AI-as-a-Service. 
  • Cloud-native deployment. 
  • Custom software development

Industries served: HealthTech, FinTech, SaaS, e-learning, and real estate.
Best for: Startups and mid-market companies that need a US-based partner to own the full build, from agent architecture through production deployment, without enterprise overhead, offshore handoffs, or a long procurement cycle.

 

LeewayHertz: Best for Multi-Agent Enterprise Systems

LeewayHertz has been building AI and software solutions since 2007. Headquartered in San Francisco with a team of 250+ engineers and designers, the firm has delivered more than 160 solutions for clients ranging from funded startups to Fortune 500 companies. In late 2024, The Hackett Group (NASDAQ: HCKT) acquired LeewayHertz, adding institutional backing and broader enterprise reach to an already established delivery operation. Gartner named the company a representative vendor in its 2024 Hype Cycle for Generative AI, and Forbes ranked it among the top 10 AI consulting firms. Its compliance credentials include SOC 2 Type II, ISO/IEC 27001:2022, HIPAA, and GDPR, all verified rather than self-reported.

What they build

The centerpiece of LeewayHertz’s AI agent practice is ZBrain, a proprietary platform that lets enterprises build, deploy, and manage LLM-powered agents on their own data without routing it through third-party models. This matters for regulated buyers where data sovereignty is non-negotiable. 

Beyond ZBrain, the team builds multi-agent systems with tools like CrewAI and AutoGen Studio, covering everything from strategy and LLM selection to deployment and ongoing optimization. In one documented project, LeewayHertz partnered with compliance platform Scrut to create an LLM-powered tool that streamlined access to audit benchmarks and regulatory data, significantly improving query response times and decision-making accuracy for Scrut’s enterprise clients.

Why they stand out

Most orchestration tools on the market are third-party; ZBrain is not. For enterprises with sensitive data or strict regulatory requirements, the ability to run agents entirely within their own infrastructure removes a risk category that most vendors expect clients to accept. Its four active, independently verified compliance certifications reduce procurement friction for regulated buyers.

Core services:

  • AI agent development and multi-agent orchestration. 
  • ZBrain platform deployment.
  • LLM application development and RAG implementation. 
  • Generative AI consulting. 
  • ML engineering. 

Industries served: Finance, healthcare, e-commerce, manufacturing, logistics, and legal.
Best for: Mid-to-large enterprises that need a proprietary agent platform with verified compliance credentials and the institutional backing of an established strategic consultancy.

 

SoluLab: Best for Fast MVP Delivery

Based in Los Angeles, SoluLab has built a reputation as a pragmatic delivery partner for companies that need working AI agents quickly. Its ISO 27001 certification, 4.9/5 Clutch rating, and engineering rates under $50 per hour make it a cost-competitive choice for teams that want enterprise-grade security without enterprise-scale budgets. Disney and Goldman Sachs are among its named enterprise clients. 

What they build

SoluLab builds custom AI agents using Vertex AI Agent Builder, AutoGen Studio, and CrewAI, covering the full lifecycle from strategy and LLM integration through CRM and ERP connectivity, behavioral training, and post-launch optimization. Operationally, they stand out for speed: they move quickly on MVPs and iterate based on real production feedback instead of stretching discovery phases. 

Their AI and blockchain expertise come together in fintech and decentralized platform work, where intelligent automation must operate within complex financial architectures. 

Why they stand out

Clutch reviewers consistently highlight that SoluLab starts writing code without forcing clients through a long, paid discovery phase. That is a real differentiator in a market where many firms gate the actual build behind weeks of scoping. Their ISO 27001 certification means that speed does not come at the expense of security or compliance.

Core services:

  • Custom AI agent development.
  • LLM integration and chatbot development.
  • Workflow automation and copilot development.
  • Blockchain and Web3 integration.
  • CRM and ERP connectivity. 

Industries served: FinTech, healthcare, e-commerce, logistics, SaaS, and legal.
Best for: Funded startups and mid-market companies that need a production-ready AI agent on a defined timeline, not a six-month discovery cycle.

 

Markovate: Best for Product-Embedded AI

San Francisco-based Markovate was founded in 2015. With a team of 50+ engineers and more than 300 digital products delivered, the company holds ISO 9001:2015 and ISO/IEC 27001:2022 certifications and is both GDPR- and HIPAA-ready. Before co-founding Markovate, CEO Rajeev Sharma led AI initiatives at AT&T and IBM, a background that shapes the firm’s delivery approach: business outcomes first, technical complexity second.

What they build

Markovate builds generative AI agents, intelligent copilots, and workflow automation systems for manufacturing, healthcare, finance, and SaaS. Their rapid POC framework gets clients to a working validation in weeks rather than months, which matters when internal stakeholders need proof of value before approving full build budgets. 

Why they stand out

Dual ISO certification and HIPAA readiness in a firm of 50+ engineers is unusual; most companies that size either don’t have the certifications or lack the engineering depth to support them. Markovate has both. Their POC-first model reduces financial risk by allowing you to commit to a full build only after validating the use case in your actual environment.

Core services:

  • Agentic AI development and generative AI consulting.
  • Intelligent AI agents and copilots.
  • MLOps and data engineering.
  • Custom AI model development.
  • AI POC development.

Industries served: Manufacturing, healthcare, finance and banking, insurance, construction, retail, and SaaS.
Best for: Mid-market and enterprise companies that want AI embedded directly into their product or operational workflows, with measurable outcomes defined before the build begins.

 

Master of Code Global: Best for Customer-Facing AI

Founded in 2004, Master of Code Global has been building conversational AI longer than most companies on this list have been in business. Over two decades, they have delivered more than 1,000 projects for clients including T-Mobile, Burberry, Tom Ford, Estée Lauder, Jo Malone, and the Golden State Warriors, with solutions that now reach over one billion users worldwide. The company operates with ISO 27001 certification and maintains a 9.2/10 customer satisfaction score across its client base.

What they build

Master of Code builds conversational AI agents, voice bots, and customer-facing intelligent systems across web, mobile, and messaging channels. Their proprietary LOFT framework reduces AI project setup effort by 43%, optimizes pre-MVP budgets by up to 20%, and enables support delivery 3x faster. 

What separates their work from standard chatbot projects is the depth of UX and conversation design in every agent: interactions are not just functional, but genuinely engaging. 

Why they stand out

Two decades of conversational AI delivery is an advantage that can’t be replicated by firms that launched their AI practice in 2023. That history shows up in how they handle edge cases, conversation breakdowns, and post-launch optimization. These are the areas where less experienced teams tend to underestimate scope.

Core services:

  • Conversational AI agents and voice bots.
  • GenAI application development.
  • AI copilots and LLM integration.
  • AI strategy consulting.
  • Ongoing agent optimization.

Industries served: Retail, e-commerce, healthcare, finance, automotive, hospitality, insurance, and telecom.
Best for: Mid-to-large enterprises where the AI agent is customer-facing and conversion rates, CSAT, and response quality are the primary success metrics.

 

Deviniti: Best for Compliance-Heavy, Self-Hosted Deployments

Deviniti has been in enterprise software since 2004. Based in Poland with a global client roster, they are an Atlassian Platinum Solution Partner with a deep track record in regulated sectors including finance, banking, legal, and healthcare. Their minimum project size is $25,000, with hourly rates of $50–$99. Clutch reviewers regularly highlight their responsiveness, governance discipline, and ability to integrate AI into existing enterprise software environments without disrupting day-to-day operations.

What they build

Deviniti builds secure, self-hosted AI agents that keep data within the client’s own infrastructure, a non-negotiable for many regulated buyers. Their agent work includes intelligent routing and triage systems, legal contract analysis agents, AI-based reporting assistants, and field inspection tools that use computer vision. 

Every engagement covers the full lifecycle: discovery, PoC, MVP, integration, deployment, and post-deployment optimization. 

Why they stand out

Self-hosted deployment is still uncommon. Most AI agent vendors require cloud connectivity that places client data in environments the client does not fully control. Deviniti’s on-premise and self-hosted model directly addresses the requirement that removes many vendors from regulated-sector procurement before technical evaluation begins. Their contribution to the open-source Bielik LLM project also signals real technical investment in the space, not just service branding.

Core services:

  • Custom AI agent development and self-hosted LLM deployment.
  • AI model fine-tuning.
  • PoC and MVP development.
  • Multi-agent systems.
  • Enterprise system integration.
  • AI consulting and workshops.

Industries served: Finance, banking, insurance, legal, public sector, and healthcare.
Best for: Mid-to-large enterprises in regulated industries where data privacy requirements demand on-premise or self-hosted agent deployment. 

 

Intellectyx: Best for Data-Driven Enterprise Automation

Headquartered in Denver, Intellectyx was founded in 2010 and operates with offshore delivery centers in India. Their recognition spans Gartner, IAOP, Inc. 5000, and TiE50, a mix of analyst validation and growth awards that is harder to assemble than a single badge. Hourly rates run from $25 to $49, with dedicated resource models starting at $5,000 per month. Named clients include DQLabs, Arria NLG, Helix.ai, and ComplyKEY.

What they build

Intellectyx builds domain-specific AI agents for high-volume enterprise workflows, including invoice processing, expense validation, data reconciliation, reporting automation, and customer interaction management. 

Their work runs on AgentOps frameworks, structured systems for continuous monitoring and optimization that help agents evolve with changing business rules rather than degrade over time. 

Why they stand out

Intellectyx maps every AI agent initiative to measurable KPIs before a single line of code is written, leading to agents designed for business impact rather than technical completeness. Their AgentOps framework makes post-launch performance a built-in commitment, not a separate consulting upsell.

Core services:

  • Custom AI agent development.
  • AgentOps frameworks and continuous optimization.
  • Enterprise AI integration (ERP, CRM).
  • Multi-agent orchestration.
  • Agentic strategy consulting.
  • Data engineering and AI PoC development.

Industries served: Financial services, wealth management, healthcare, retail, public sector, and media.
Best for: Mid-to-large enterprises with high-volume operational workflows (invoicing, reconciliation, reporting, and data validation) that need agents tied to measurable business outcomes.

 

Azilen Technologies: Best for HRTech and FinTech Workflows

Azilen Technologies was founded in 2009 and is headquartered in Irving, Texas, with 400+ engineers across North America, Asia, and Europe. Their delivery track record spans more than 400 enterprise projects. In 2025, Corporate Vision named them Best HR Software Development Company, and they won the 20th Annual Globee Award for Technology. Strategic partnerships with HiBob, The Cloud Connectors, and pharmaceutical firm Augmenticon AG reflect where their AI agent depth actually sits.

What they build

Azilen builds autonomous, goal-driven AI agents that integrate with ERP, CRM, data platforms, and APIs, executing multi-step workflows with minimal human intervention. Their strength in HRTech, FinTech, and manufacturing is backed by real deployments: a talent acquisition agent that cut cost-per-hire by 40% and increased diversity hires by 34%; smart insurance claim processors; AI-enabled health assistants; and logistics agents that forecast demand and route loads efficiently. 

Why they stand out

Sector-specific integration depth is rare. Azilen’s HRTech partnerships with HiBob and The Cloud Connectors, and their pharmaceutical AI work with Augmenticon, mean they are building agents into ecosystems they already understand, not learning the domain during the engagement. For companies where the AI agent needs to operate inside platforms like Workday or SAP, that existing depth matters.

Core services:

  • Agentic AI development and generative AI solutions.
  • AI and data engineering.
  • MLOps and intelligent automation.
  • Custom AI agents.
  • HRTech and FinTech platform integration.

Industries served: HRTech, FinTech, Manufacturing, RetailTech, ClimateTech, Insurance, and Healthcare.
Best for: Enterprises in HR, finance, and manufacturing that need agents integrated into specific platform ecosystems. 

 

BotsCrew: Best for Conversational and Agentic AI

BotsCrew was founded in 2016 in Lviv, Ukraine, after starting at a hackathon, winning a series of them, and landing its first client before officially launching. Today, the company operates across the US (San Francisco, Austin, San Diego) and Europe. In January 2025, US digital agency CourtAvenue (Inc. 5000, ranked #58) acquired a majority stake, expanding BotsCrew’s infrastructure and US market access while keeping all three co-founders in leadership. Clutch has ranked BotsCrew the #1 Chatbot Development Company for six consecutive years and named it a Top Generative AI Company in both 2024 and 2025. 

What they build

BotsCrew develops custom AI agents, conversational AI systems, agentic RAG architectures, and LLM-powered copilots for enterprises that need agents with real conversational depth, not just functional response handling. Every engagement starts with use-case discovery and validation before the architecture is defined. 

Why they stand out

A decade of conversational AI delivery produces a different quality of output than a firm that added “agent development” to its service page eighteen months ago. BotsCrew has already identified the edge cases, conversation failures, and post-launch optimization challenges that most teams only discover in production. Moreover, it has solved them at scale before your project begins.

Core services:

  • Custom AI agents and copilots.
  • Conversational AI and voice bots.
  • Agentic RAG systems.
  • LLM application development.
  • Generative AI consulting.
  • Enterprise AI integration.

Industries served: Healthcare, e-commerce, travel, automotive, retail, nonprofit, and government.
Best for: Enterprises that need AI agents with a strong conversational layer (e.g., customer-facing bots, voice agents, and internal knowledge systems), built by a team with a decade of production deployments under its belt.

 

Inoxoft: Best for Startups and SMBs

Philadelphia-headquartered Inoxoft was founded in 2014 by engineers and now operates as an international delivery partner with 200+ in-house engineers and more than 200 completed projects. Their credentials are specific: ISO 27001 certified, Microsoft Gold Partner, Google Cloud Partner, a 5.0/5 rating on Clutch, an 94% client retention rate beyond initial projects, and 70% of new clients coming through referrals. Hourly rates range from $25 to $49. Manifest ranks them among the top 100 AI companies globally.

What they build

Inoxoft builds domain-specific AI agents for customer support, process automation, data analysis, and industry-specific workflows. Their delivery model uses pre-trained AI foundations and automated fine-tuning, cutting training time by about 40%, enabling them to consistently deploy in 1 to 4 weeks instead of months. Before launch, agents go through two full days of real-world simulation testing. 

Why they stand out

A 5.0 Clutch rating across 70+ verified reviews at $25–$49 per hour, combined with Microsoft Gold and Google Cloud partnership status, is hard to find in a single firm. Inoxoft occupies a specific niche: enterprise-grade credentials at startup-accessible pricing, which is exactly what early-stage and growth-stage companies need from an AI development partner.

Core services:

  • Custom AI agent development.
  • ML model development and NLP solutions.
  • Process automation and AI consulting.
  • QA and software testing.
  • Cybersecurity.

Industries served: Automotive, Healthcare, FinTech, education, real estate, logistics, retail, and marketing.
Best for: Startups and SMBs that need fast, secure, domain-specific AI agents on startup timelines and budgets, without sacrificing compliance credentials or post-launch support.

 

Neurons Lab: Best for Financial Services

Neurons Lab is an AI consultancy headquartered in the UK and Singapore, with delivery teams serving North America, Europe, and Asia. Their AWS Advanced Tier Partner status includes competencies in both Generative AI and Financial Services, a dual certification that signals production capability in regulated cloud environments rather than simple vendor enrollment. Named clients include HSBC, Visa, and AXA, and the firm has delivered more than 100 AI projects since 2019.

What they build

Neurons Lab designs and builds agentic AI systems for financial institutions where regulatory compliance, data sovereignty, and audit trail requirements shape the architecture from day one, not as additions during QA. Their ARKEN platform is a proprietary multi-agent accelerator built specifically for wealth management and complex financial services environments. In one documented case, a wealth management firm found that off-the-shelf tools such as Claude and Perplexity lacked the workflow depth and compliance controls that their relationship managers needed. 

Their 500+ engineering team brings deep experience across RAG, orchestration, NLP, MLOps, and LangOps.

Why they stand out

Most AI development firms treat financial services compliance as a configuration step. Neurons Lab treats it as the primary architecture constraint, which is the right posture for banks and insurers operating under GDPR, MiFID II, Basel IV, and similar frameworks. The ARKEN platform also means they are not starting from zero on each financial services engagement; there is an accelerator layer already validated in production.

Core services:

  • Agentic AI consultancy and ARKEN platform deployment.
  • Multi-agent system design.
  • RAG and NLP implementation.
  • MLOps and LangOps.
  • Regulated AI deployment.

Industries served: Banking, insurance, wealth management, asset management, and financial services.
Best for: Financial institutions — mid-to-large banks, insurers, wealth managers — that need production-grade agentic AI built around regulatory compliance from the first architecture decision.

 

Intuz: Best for Cross-Industry Enterprise AI

Intuz was founded in 2008, which gives them more than 17 years of enterprise software delivery before most competitors even launched their AI practices. US-based and trusted by SMBs and Fortune 500 clients in over 40 countries, they bring a depth of cross-industry production experience that newer firms simply have not had time to build. Their client base spans healthcare, e-commerce, finance, EV, legal, and logistics.

What they build

Intuz builds custom AI agents, multi-agent systems, and LLM orchestration solutions focused on workflow automation, customer service, and operational decision-making. Their work includes autonomous workflow agents, document summarization and insight extraction bots, AI-enabled SaaS platforms for case management, and dynamic pricing systems. 

Technical depth across LLMs, NLP, and computer vision enables them to build agents that handle multi-step, cross-system workflows, not just isolated task automation. Their work with companies in more than 40 countries has also produced real cross-cultural and cross-regulatory delivery experience that is hard to manufacture.

Why they stand out

17 years of enterprise delivery across 40+ countries creates a very different kind of institutional knowledge than a firm that has operated for three. Intuz has already seen the integration failures, compliance edge cases, and organizational adoption challenges that derail AI projects, and they have structured their delivery model to avoid them rather than learn on the client’s dime.

Core services:

  • Custom AI agent development.
  • Multi-agent systems and LLM orchestration.
  • Workflow automation.
  • AI-powered SaaS development.
  • Chatbot development and AI consulting.

Industries served: Healthcare, e-commerce, finance, EV, legal, logistics, and D2C.
Best for: Companies that need a development partner with genuine enterprise delivery maturity, cross-industry references, and the flexibility to work across the full spectrum from early-stage startups to established enterprise clients.

 

DevCom: Best for Custom Builds on Flexible Terms

DevCom is a Florida-based software development company with a delivery center in Ukraine. They consistently rank highly in third-party AI agent development rankings for their close-collaboration delivery model, which is a deliberate contrast to the large-team, periodic-update approach common among enterprise vendors. Their Florida headquarters gives US clients a domestic legal and contractual relationship, while the Ukraine delivery center provides competitive engineering rates.

What they build

DevCom builds custom AI agents from the ground up: agent architecture, LLM integration, workflow design, system integration, and post-deployment support, all within a single engagement rather than handed between separate teams. 

They work across the standard agentic AI stack (LangChain, LlamaIndex, OpenAI, Claude), connecting agents to existing CRM, ERP, and operational systems instead of building alongside them. Technical transparency is a core part of their model, so clients know what is being built and why at each stage, not just at delivery milestones.

Why they stand out

For mid-market companies that want US-based accountability with offshore economics, DevCom’s structure is genuinely differentiated. Most vendors offer one or the other: a US-based firm at US rates, or an offshore firm with a US sales contact. DevCom’s Florida incorporation and Ukraine delivery team combine both without the coordination overhead of managing two separate vendors.

Core services:

  • Custom AI agent development.
  • LLM integration and workflow automation.
  • Full-cycle software support.
  • Enterprise system integration.
  • AI consulting.

Industries served: SaaS, financial services, healthcare, retail, logistics.
Best for: Companies that need custom AI agents built collaboratively on flexible terms, without the large-firm overhead or the risk of fully offshore delivery.

 

TRooTech: Best for CRM-Integrated Agentic Systems

TRooTech is a full-scale enterprise technology partner with more than a decade of experience in software engineering and AI development. They appear in multiple 2026 enterprise agentic AI rankings for their ability to move companies from AI pilot projects to production-ready autonomous systems, a transition that stalls more often than vendors admit.

What they build

TRooTech builds agentic AI systems that integrate directly into enterprise CRM environments such as Salesforce, HubSpot, and Microsoft Dynamics. Agents operate inside the workflows where sales, support, and operations teams already work, rather than forcing teams to adopt new tools. 

Their architecture covers multi-agent orchestration, autonomous reasoning, governance frameworks, and enterprise-grade deployment. The emphasis is on full integration from day one: agents that read and write to existing systems, respect existing permissions, and surface outputs where users already look.

Why they stand out

CRM-embedded agents reduce the single biggest adoption risk in enterprise AI: getting teams to change their behavior. When an agent surfaces its output in Salesforce rather than a separate dashboard, adoption is not a change management project; it happens naturally. TRooTech has built that integration depth into their standard delivery model.

Core services:

  • Agentic AI development and multi-agent orchestration.
  • CRM-integrated AI agents.
  • Enterprise AI governance.
  • Autonomous workflow design.
  • AI consulting.

Industries served: Enterprise SaaS, financial services, healthcare, and retail.
Best for: Mid-to-large enterprises where AI agents need to operate inside existing CRM and enterprise software environments. 

 

Azumo: Best for Compliance-Sensitive Deployments

Azumo is a US-based AI and software development company with a specific technical differentiator that matters for regulated buyers: self-hosted and VPC deployment options that keep data entirely within the client’s own infrastructure. CTO Juan Pablo Lorandi brings more than 20 years of experience in software architecture and engineering leadership. The team builds in a nearshore model with Latin American engineers, enabling US clients to collaborate in their time zone at competitive rates.

What they build

Azumo develops custom AI agents with deployment flexibility at the architecture level, including cloud, self-hosted, and dedicated-cloud setups for clients whose regulatory requirements demand tight data control. Their agents span customer service automation, internal workflow agents, and enterprise knowledge systems. 

The combination of self-hosted deployment options and on-demand human escalation paths, built into the agent architecture rather than added after launch, makes them a strong fit for healthcare, legal, and financial services buyers where data residency and human oversight are non-negotiable. They build on top of the standard LLM stack and integrate with existing enterprise systems, so agents stay embedded in workflows. 

Why they stand out

Self-hosted deployment is still uncommon. Most AI agent vendors require cloud connectivity that places client data in environments the client does not fully control. Azumo’s architecture-level flexibility directly addresses procurement blockers, eliminating many vendors from regulated-sector shortlists before technical evaluation even begins.

Core services:

  • Custom AI agent development.
  • Self-hosted and VPC deployment.
  • Enterprise knowledge agents.
  • Customer service AI automation.
  • LLM integration and system connectivity.

Industries served: Healthcare, legal, financial services, enterprise software, and retail.
Best for: Companies in regulated industries where data residency requirements, privacy mandates, or security policies make standard cloud-hosted AI agent solutions non-viable from the start.

 

What AI Agent Development Solutions Are Used For in 2026

Businesses across the US are moving past pilots and putting AI agents into core operations. The use cases below show where production deployments deliver the clearest, most measurable returns, and where companies now allocate most of their AI agent development budgets.

Customer Service and Support Automation

Customer service was the first area where AI agent development solutions in the USA gained real enterprise traction. In 2026, production-ready agents go far beyond basic FAQ bots. They handle complex multi-turn conversations, process refunds, reroute shipments, escalate based on sentiment, and update CRM records without human intervention. 

Companies running mature customer service agents report about a 25% reduction in support costs. BT Group’s agents manage up to 60,000 interactions per week, while Bank of America’s Erica handles more than one million daily queries and cuts service costs by around 10%.

Sales, CRM, and Pipeline Intelligence

Sales teams still spend a lot of time on tasks that do not require human judgment: updating records, drafting follow-ups, scoring leads, and scheduling meetings. AI agents built for CRM environments now handle much of that routine workload. They work directly within Salesforce, HubSpot, or Dynamics, surface high-intent prospects, and recommend next-best actions so reps can focus on conversations rather than admin. 

In documented deployments, AI agents that analyze email, call transcripts, and CRM data have shortened sales cycles by about 20%. For companies that treat pipeline velocity as a primary growth lever, that time savings shows up directly in revenue.

Finance and Back-Office Operations

Finance operations combine high volume, strict rules, and little margin for error. That mix makes them a natural fit for AI agent development solutions in the USA. Production agents now process invoices, validate expenses, reconcile data across systems, support working capital decisions, and help prepare regulatory reports, work that once required dedicated analyst teams. 

One global wealth and capital markets firm used an AI finance engine to connect ERP and credit models and gain real-time liquidity insight. Around 67% of C-level executives now point to automation as their main lever for cutting operational costs, and back-office finance is often where they see the first clear ROI.

Healthcare: For Scheduling, Records, and Clinical Decision Support

Healthcare is one of the most challenging environments for AI agent development in the USA. HIPAA rules, sensitive data, and clinical accuracy shape every architecture decision. In production, agents now support patient scheduling, insurance pre-authorization, electronic health record management, and clinical documentation. That reduces clinicians’ administrative load and shortens delays in care caused by manual processing. 

In settings where agents support clinical decisions with real-time data analysis, deployments have helped lower diagnostic errors by about 20%. For providers under pressure from rising patient volumes and limited staff, that combination of automation and decision support changes how care teams work.

Software Engineering and Internal Development Tooling

Within software teams, coding agents have shifted from experimental to standard tools. Products like Cursor and Claude Code sit alongside custom internal agents that engineering leaders commission for their own stacks. These agents write, test, debug, and document code and, in more advanced setups, break down tasks and work within large existing codebases instead of generating isolated snippets. Companies also deploy agents that automate code review, manage CI/CD pipelines, generate test suites, and enforce security policies. 

Teams that rely on mature coding agents report a 30–40% reduction in time spent on routine development work, which frees engineers to focus on architecture, product quality, and user experience.

Manufacturing and Supply Chain

Manufacturing and supply chain operations generate continuous streams of sensor, logistics, and demand data that human teams can’t parse in real time. AI agent development solutions in the USA now sit atop that data and serve as an operational control layer. In factories, agents analyze signals from thousands of IoT sensors, fine-tune machine settings, detect early signs of equipment failure, and trigger maintenance workflows before downtime occurs. 

 

Final Thoughts

The gap between companies that run AI agents successfully and those that rebuild from scratch 6 months later almost never comes down to the technology. The best AI Agent Development Companies for US Clients combine strong LLM engineering with real-world deployment discipline.

The companies on this list have proved they can move past the demo stage. Each one brings a specific kind of depth: proprietary platforms, compliance credentials, sector experience, deployment flexibility, or a delivery model that addresses the failure modes that sink most AI agent projects. The right choice depends on your scale, your industry, your existing stack, and how much of the build you expect your partner to own.

Not sure where to start? Talk to the LITSLINK team directly about what you are building.

 

Frequently Asked Questions

Why do most AI agent projects fail before reaching production, and how do top US developers prevent this?

Most AI agent projects stall in the “demo-to-production gap” because they lack the infrastructure to handle real-world edge cases. In a controlled demo, an agent works perfectly; in production, issues such as nondeterministic outputs, API rate limits, and data drift break the system. 

Top US development agencies prevent this by shifting focus from the AI model itself to the surrounding architecture. They implement Agent Ops (specialized observability), robust error handling, human-in-the-loop (HITL) fallback mechanisms, and scenario-based evaluation frameworks to ensure the agent behaves predictably at scale.

How do enterprise-grade AI agents safely integrate with legacy systems like CRMs and ERPs?

Integration is rarely plug-and-play. Connecting an autonomous agent to decades-old on-premise databases or fragmented SaaS tools creates severe security and compatibility challenges. 

Production-focused agencies solve this by building custom orchestration layers and secure API wrappers. Rather than giving an agent raw database access, developers build highly restricted “tools” the agent can call, using strict authentication (OAuth, SAML) and enforcing Role-Based Access Control (RBAC). Thus, the agent can only fetch or modify what it is authorized to touch. 

Can AI agents guarantee predictable outcomes in a production environment?

Because Large Language Models (LLMs) are probabilistic by nature, they are not inherently deterministic. However, elite AI development companies enforce predictability through strict guardrails. They achieve this by:

  • Separating the reasoning logic from the execution logic.
  • Using programmatic validation to check the agent’s output before it takes action.
  • Keeping prompts, tool configurations, and system instructions strictly under version control.
  • Utilizing smaller, task-specific models (SLMs) for rigid workflows rather than relying on a single, highly creative LLM for everything.

How are production costs managed when an AI agent requires continuous, multi-step LLM calls?

Multi-agent systems can burn through compute budgets rapidly if an LLM is prompted for every minor sub-task. Top development firms optimize ROI through strategic routing and caching. They implement semantic caching (storing answers to frequent requests so the model doesn’t have to regenerate them) and use router models to direct simple, repetitive tasks to cheaper, faster Small Language Models (SLMs), reserving expensive, heavy-duty LLMs only for complex reasoning and edge cases.

What is Agent Ops, and why is it critical for post-deployment?

Traditional IT monitoring (like checking server uptime) is useless for AI agents. If an agent hallucinates a reasoning step and sends an incorrect email to a client, the server will still show as 100% healthy. 

Agent Ops is the discipline of monitoring the agent’s cognitive workflow. Development partners implement this to trace the agent’s internal “thoughts,” log the exact tools it attempted to use, monitor the latency of external API calls, and detect behavioral drift over time, allowing engineers to debug black-box AI logic instantly.

How do US agencies secure AI agents against prompt injection and unauthorized actions?

As agents transition from passive chatbots to active systems capable of executing code or spending money, security becomes the top priority. Developers aligning with frameworks like the NIST AI Risk Management Framework (RMF) secure agents by:

  • Implementing strict “least privilege” access to enterprise tools.
  • Using shadow deployments (running new agent versions silently in the background alongside current ones) to test safety.
  • Deploying input/output sanitization filters to block malicious prompt injections that attempt to hijack the agent’s core instructions.

.Organize the content with appropriate headings and subheadings ( h2, h3, h4, h5, h6). Include conclusion section and FAQs section with Proper questions and answers at the end. do not include the title. it must return only article i dont want any extra information or introductory text with article e.g: ” Here is rewritten article:” or “Here is the rewritten content:”

Generate single title from this title Control which domains your AI agents can access in 100 -150 characters. And it must return only title i dont want any extra information or introductory text with title e.g: ” Here is a single title:”

0

Write an article about

AI agents that can browse the web open powerful possibilities—from research automation to real-time data gathering. However, giving an AI agent unrestricted internet access raises security and compliance concerns. What if the agent accesses unauthorized websites? What if sensitive data is exfiltrated to external domains?

Amazon Bedrock AgentCore provides managed tools that enable AI agents to interact with the web (Browser), execute code (Code Interpreter), and host agents (Runtime). When deployed in an Amazon Virtual Private Cloud (Amazon VPC), you can control tool network access using AWS Network Firewall to implement domain-based filtering. AWS Network Firewall also provides you with managed rules to help reduce access to botnets, known-malware domains, and other high-risk resources.

In this post, we show you how to configure AWS Network Firewall to restrict AgentCore resources to an allowlist of approved internet domains. You can use this architecture to:

  • Permit access only to specified domains (for example, wikipedia.org, stackoverflow.com)
  • Explicitly block certain categories (e.g., social media sites) using rule templates
  • Log the connection attempts for audit and compliance alignment
  • Apply a default-deny policy for unspecified domains

This post focuses on domain-level filtering using SNI inspection — the first layer of a defense-in-depth approach. For DNS-level filtering and content inspection techniques, see Going further at the end of this post. For inbound access control (restricting who can invoke your agents), you can also see Resource-based policies for Amazon Bedrock AgentCore. These support conditions like aws:SourceIp, aws:SourceVpc, and aws:SourceVpce. These controls are complementary layers in a defense in depth strategy.

Why this matters: Enterprise security requirements

Customers deploying AI agents in regulated industries have consistent security requirements around network ingress and egress control:

Enterprise organizations with high security requirements

Customers in regulated industries conducting security reviews for AI agent deployments consistently ask about network isolation and egress control, requiring detailed explanations of how agent traffic is controlled and audited. These customers want assurance that agent runtime endpoints remain private, and that additional security controls like web application firewall protections are available.

Multi-tenant SaaS providers

Enterprise software as a service (SaaS) providers require DNS-level allowlisting and denylisting because their multi-tenant architectures need per-customer network policies. For example, Customer A might need to allow domains that Customer B blocks. Common requirements include:

  • Execution-specific blocking (prevent access to certain domains during specific browser launches)
  • Regional restrictions (block website categories in specific regions)
  • Category-based rules (disable gambling or social media sites through pre-packaged rule sets)

Security vulnerability mitigation and compliance audit requirements

Security teams evaluating AI agents have identified that agents can be tricked into navigating to unintended sites through prompt injection attacks. Custom URL allowlists reduce the attack surface by restricting the browser to approved domains, regardless of what the agent is instructed to do. Domain-based egress filtering provides the logging and access control visibility that security teams often need for their security monitoring processes.

Solution overview

The solution deploys AgentCore Browser in a private subnet with no direct internet access. The outbound traffic routes through AWS Network Firewall, which inspects TLS Server Name Indication (SNI) headers to determine the destination domain and apply filtering rules. You can also monitor Network Firewall actions taken to restrict traffic through the native Network Firewall integration with Amazon CloudWatch metrics.

Figure 1: AgentCore deployment with AWS Network Firewall and domain-based egress filtering

The architecture includes:

  • Private subnet: Hosts AgentCore Browser instances with no public IP addresses
  • Public subnet: Contains the NAT Gateway for outbound connectivity
  • Firewall subnet: Hosts the Network Firewall endpoint
  • Four route tables: Control traffic flow through the firewall for both outbound requests and return traffic

Traffic flow

  1. AgentCore Runtime executes the agent and invokes the AgentCore Browser tool
  2. AgentCore Browser initiates an HTTPS request from the private subnet
  3. The private subnet route table directs traffic to the NAT Gateway in the public subnet
  4. The NAT Gateway translates the private IP address and forwards the request to the Network Firewall endpoint
  5. Network Firewall inspects the TLS SNI header to identify the destination domain
  6. If the domain matches an allowlist rule, the firewall forwards traffic to the Internet Gateway
  7. The Internet Gateway routes approved traffic to the external destination
  8. Return traffic follows the symmetric path back through the firewall to the agent

This architecture helps make sure that the browser traffic is inspected and filtered, regardless of the destination.

Note: SNI-based filtering helps control which domains agents connect to at the TLS layer. For DNS-level control, including controls to help prevent DNS tunneling and exfiltration, pair this with Amazon Route 53 Resolver DNS Firewall. DNS Firewall helps address a limitation of SNI inspection: an agent could potentially resolve a blocked domain through DNS and connect by IP address directly.

Prerequisites

Before you begin, make sure that you have:

  • An AWS account with permissions to create VPC resources, Network Firewall, and IAM roles
  • AWS Command Line Interface (AWS CLI) version 2.x configured with appropriate credentials
  • Access to Amazon Bedrock AgentCore
  • Basic familiarity with VPC networking concepts

Walkthrough

For the complete step-by-step VPC and Network Firewall setup, see the Amazon Bedrock AgentCore VPC configuration documentation.

This section highlights the AgentCore Browser-specific configuration.

Step 1: Deploy resources using the CloudFormation template

Launch the CloudFormation template from the repository. You can keep the stack default values. However, make sure to add a stack name (for example, “agentcore-egress“) to the “Stack name” field, choose an Availability Zone on the “Availability Zone” menu, and include a valid existing bucket name on the “BucketConfigForOutput” parameter. Wait for the stack creation to complete, which typically takes 10 minutes. Continue with the following steps after the stack status changes to CREATE_COMPLETE.

Step 2: Review the IAM execution role

AgentCore Browser requires an IAM role with a trust policy for the Amazon bedrock-agentcore.amazonaws.com service:

{
“Version”: “2012-10-17”,
“Statement”: [
{
“Effect”: “Allow”,
“Principal”: {
“Service”: “bedrock-agentcore.amazonaws.com”
},
“Action”: “sts:AssumeRole”
}
]
}

Step 3: Configure the Network Firewall allowlist

Create a stateful rule group with your approved domains. Note the leading dot (.) to match subdomains:

cat > allowlist-rules.json << 'EOF' { "RulesSource": { "RulesSourceList": { "Targets": [ ".wikipedia.org", ".stackoverflow.com", ".docs.aws.amazon.com", ".amazonaws.com", ".pypi.org", ".pythonhosted.org" ], "TargetTypes": ["HTTP_HOST", "TLS_SNI"], "GeneratedRulesType": "ALLOWLIST" } }, "StatefulRuleOptions": { "RuleOrder": "STRICT_ORDER" } } EOF aws network-firewall create-rule-group \ --rule-group-name browser-allowed-domains \ --type STATEFUL \ --capacity 100 \ --rule-group file://allowlist-rules.json \ --region us-east-2

Important: Include .amazonaws.com in your allowlist if the browser requires AWS service access or use VPC Endpoints as an alternative.

Security consideration: The .amazonaws.com domain is a broad allowlist that permits access to hosted endpoints on AWS, including public Amazon Simple Storage Service (Amazon S3) buckets, Amazon API Gateway endpoints, and AWS Lambda function URLs. For tighter control, use VPC Endpoints for AWS service access and allowlist only the specific external domains your agents need.

For Code Interpreter: Consider adding “.pypi.org” and “.pythonhosted.org” if you need a pip package installation. Most common packages are pre-installed, making these domains optional for your use case.

Step 4: Configure the firewall policy

The firewall policy must use aws:drop_established as the default action. This allows TCP handshakes to complete (required for TLS SNI inspection) while dropping connections to non-allowed domains:

cat > firewall-policy.json << 'EOF' { "StatelessDefaultActions": ["aws:forward_to_sfe"], "StatelessFragmentDefaultActions": ["aws:forward_to_sfe"], "StatefulRuleGroupReferences": [ { "ResourceArn": "arn:aws:network-firewall:us-east-2:ACCOUNT_ID:stateful-rulegroup/browser-allowed-domains", "Priority": 1 } ], "StatefulEngineOptions": { "RuleOrder": "STRICT_ORDER" }, "StatefulDefaultActions": ["aws:drop_established"] } EOF

Do not use aws:drop_strict because it blocks TCP SYN packets before the TLS handshake, preventing SNI inspection.

Step 5: Create the security group

Create a security group that allows outbound traffic. The Network Firewall handles domain filtering, so the security group permits the egress:

# Create security group
aws ec2 create-security-group \
–group-name agentcore-egress-sg \
–description “AgentCore tools – egress only, filtered by Network Firewall” \
–vpc-id vpc-XXXXXXXXX \
–region us-east-2

# Allow all outbound traffic (Network Firewall handles filtering)
aws ec2 authorize-security-group-egress \
–group-id sg-XXXXXXXXX \
–protocol -1 \
–port -1 \
–cidr 0.0.0.0/0 \
–region us-east-2

# Remove default inbound rules if present (AgentCore tools don’t need inbound)
aws ec2 revoke-security-group-ingress \
–group-id sg-XXXXXXXXX \
–protocol -1 \
–port -1 \
–cidr 0.0.0.0/0 \
–region us-east-2

Step 6: Create the AgentCore Browser

Create the browser with VPC configuration pointing to your private subnet:

aws bedrock-agentcore-control create-browser \
–name my_secure_browser \
–execution-role-arn arn:aws:iam::ACCOUNT_ID:role/AgentCoreBrowserExecutionRole \
–network-configuration ‘{
“networkMode”: “VPC”,
“vpcConfig”: {
“securityGroups”: [“sg-XXXXXXXXX”],
“subnets”: [“subnet-XXXXXXXXX”]
}
}’ \
–region us-east-2

Step 6b: Create AgentCore Code Interpreter (Optional)

You can also deploy AgentCore Code Interpreter in the same VPC with the same firewall protection:

aws bedrock-agentcore-control create-code-interpreter \
–name my_secure_code_interpreter \
–network-configuration ‘{
“networkMode”: “VPC”,
“vpcConfig”: {
“securityGroups”: [“sg-XXXXXXXXX”],
“subnets”: [“subnet-XXXXXXXXX”]
}
}’ \
–region us-east-2

AgentCore Code Interpreter uses the same network path as Browser. If you need pip to install packages, make sure .pypi.org and .pythonhosted.org are in your allowlist.

Step 6c: Deploy agent on AgentCore Runtime (Optional)

For container-based agent deployments, use the same VPC configuration:

aws bedrock-agentcore-control create-agent-runtime \
–agent-runtime-name my_vpc_agent \
–role-arn arn:aws:iam::ACCOUNT_ID:role/AgentCoreRuntimeRole \
–agent-runtime-artifact ‘{
“containerConfiguration”: {
“containerUri”: “ACCOUNT_ID.dkr.ecr.us-east-2.amazonaws.com/my-agent:latest”
}
}’ \
–network-configuration ‘{
“networkMode”: “VPC”,
“networkModeConfig”: {
“securityGroups”: [“sg-XXXXXXXXX”],
“subnets”: [“subnet-XXXXXXXXX”]
}
}’ \
–protocol-configuration ‘{“serverProtocol”: “HTTP”}’ \
–region us-east-2

AgentCore Runtime domain requirements depend on your model provider. Include .amazonaws.com for Amazon Bedrock model API calls or add the appropriate domains for other model providers your agent uses. Additionally, allow custom domains that your agent must access.

Step 7: Test the Configuration

Start a browser session and verify that the firewall rules work correctly:

# Start browser session
aws bedrock-agentcore start-browser-session \
–browser-identifier my_secure_browser-ABC123xyz \
–region us-east-2

Use the returned WebSocket URL with a browser automation tool like Playwright to test both allowed and blocked domains:

# test_firewall_rules.py

from playwright.sync_api import sync_playwright
import boto3
from botocore.auth import SigV4Auth
from botocore.awsrequest import AWSRequest

WEBSOCKET_URL = “wss://your-session-url” # From start-browser-session response
REGION = “us-east-2″

# Sign the WebSocket URL with SigV4
session = boto3.Session(region_name=REGION)
credentials = session.get_credentials().get_frozen_credentials()
request = AWSRequest(method=”GET”, url=WEBSOCKET_URL.replace(“wss://”, “https://”))
SigV4Auth(credentials, “bedrock-agentcore”, REGION).add_auth(request)
headers = dict(request.headers)

def test_domain(page, url, expected_success):
try:
response = page.goto(url, timeout=10000)
success = response and response.status < 400 status = "PASS" if success == expected_success else "FAIL" print(f"{status}: {url} - {'loaded' if success else 'blocked'}") return success == expected_success except Exception as e: success = False status = "PASS" if not expected_success else "FAIL" print(f"{status}: {url} - blocked ({type(e).__name__})") return not expected_success with sync_playwright() as p: browser = p.chromium.connect_over_cdp(WEBSOCKET_URL, headers=headers) page = browser.new_page() # Test allowed domains (should load) test_domain(page, "https://wikipedia.org", expected_success=True) test_domain(page, "https://docs.aws.amazon.com", expected_success=True) # Test blocked domains (should timeout/fail) test_domain(page, "https://example.com", expected_success=False) test_domain(page, "https://twitter.com", expected_success=False) browser.close()

Expected results:

  • Allowed domains (.wikipedia.org, .amazonaws.com) should load successfully.
  • Blocked domains should time out after the TCP handshake or return connection errors.

Note: Some allowed domains like docs.aws.amazon.com depend on CDN resources from domains such as awsstatic.com and cloudfront.net. If pages on allowed domains fail to render fully, add the required CDN domains to your allowlist.

You can also check the firewall logs in CloudWatch for blocked connection attempts:

# View recent alert logs (blocked connections)
aws logs filter-log-events \
–log-group-name “/aws/network-firewall/agentcore-egress/alerts” \
–filter-pattern ‘{ $.event.alert.action = “blocked” }’ \
–region us-east-2 \
–start-time $(($(date +%s) – 300))000

# Verify firewall sync status before testing
aws network-firewall describe-firewall \
–firewall-name agentcore-egress-firewall \
–region us-east-2 \
–query ‘FirewallStatus.ConfigurationSyncStateSummary’

Troubleshooting: If allowed domains are blocked, verify:

  1. Firewall sync status shows IN_SYNC (rule changes take a few minutes)
  2. Domain entries include the leading dot (.wikipedia.org not wikipedia.org)
  3. Route tables are configured correctly for symmetric routing
  4. If you receive HTTP 403 errors on allowed domains, this is typically bot detection by the destination site, not a firewall block. Check CloudWatch ALERT logs to confirm—blocked connections will have explicit alert entries.

Best practices

  • Use STRICT_ORDER evaluation: This facilitates predictable rule processing when combining allowlists and denylists.
  • Include .amazonaws.com for AWS service access: Or use VPC Endpoints to avoid routing AWS API calls through the internet.
  • Configure the IGW ingress route table: This is critical for symmetric routing. Without it, return traffic bypasses the firewall.
  • Enable both ALERT and FLOW logs: ALERT logs capture blocked connections; FLOW logs provide connection metadata for the traffic.
  • Wait for firewall sync: Rule changes take a few minutes to propagate. Verify ConfigurationSyncStateSummary: IN_SYNC before testing.
  • Configure HOME_NET for multi-VPC architectures: By default, Network Firewall domain inspection only filters traffic originating from the deployment VPC’s Classless Inter-Domain Routing (CIDR) range. If you use a centralized firewall with AWS Transit Gateway to inspect traffic from multiple VPCs, you must configure the HOME_NET variable in your rule group to include the source CIDR ranges. Without this, traffic from other VPCs can bypass domain filtering.

Limitations and cost considerations

  • Content inspection requires TLS inspection: By default, domain filtering operates on unencrypted TLS metadata (SNI headers) and can’t inspect encrypted request or response bodies. To inspect HTTPS content, enable TLS inspection on your Network Firewall and add Suricata rules that match on HTTP body content. SNI/Host header bypass risk: Network Firewall uses TLS SNI headers and HTTP Host headers—not IP addresses—to determine destination domains. If these headers are manipulated, traffic could bypass domain filtering. For high-security deployments, combine domain rules with IP-based rules for critical blocked destinations, or add DNS filtering as an additional layer. Additionally, consider pairing SNI-based rules with Route 53 DNS Firewall to help prevent agents from resolving blocked domains through DNS and connecting by IP address directly.
  • HOME_NET scope in multi-VPC deployments: By default, Network Firewall domain inspection only applies to traffic originating from the deployment VPC’s CIDR range. If you use a centralized firewall with AWS Transit Gateway (multiple VPCs routing through a shared firewall), you must configure the HOME_NET variable in your rule group to include the source CIDR ranges. Without this, traffic from spoke VPCs bypasses domain inspection. See Stateful domain list rule groups for details.
  • Costs will vary based on your usage. See NAT Gateway pricing and Network Firewall pricing for current rates.

Clean up

Delete resources in this order to avoid ongoing charges:

  1. Delete the AgentCore Browser
  2. Delete the Network Firewall (disable protection settings first)
  3. Delete the NAT Gateway
  4. Release the Elastic IP address
  5. Delete the subnets and route tables
  6. Detach and delete the Internet Gateway
  7. Delete the VPC

Note: AgentCore Browser and Code Interpreter create elastic network interfaces in your VPC. After deleting these resources, wait a few minutes for the network interface to release before deleting the security group, subnet, or VPC. If deletion fails, check for lingering network interfaces in the subnet and wait for them to detach.

Related resources

For more information, see the following resources.

Going further

Domain filtering through SNI inspection is one layer of egress security. Depending on your requirements, consider these additional mitigations:

Technique What it does Helps in scenarios where Reference
Route 53 DNS Firewall Helps block or allow DNS queries by domain and prevent DNS tunneling and exfiltration. You need DNS-level filtering or protection against DNS-based data exfiltration. Protect against advanced DNS threats
TLS inspection + Suricata DLP Decrypt HTTPS, inspect request/response bodies with Suricata rules, help block sensitive data patterns (PII, credentials). You need data loss prevention (DLP) for agent-generated traffic. TLS inspection for encrypted egress traffic
Centralized inspection architecture Route traffic from multiple VPCs through a shared inspection VPC with Network Firewall. You run multiple AgentCore deployments and want centralized policy enforcement. Deploy centralized traffic filtering

When using TLS inspection, configure custom certificates on your AgentCore resources to trust the Network Firewall’s re-signing CA.

Conclusion

By combining Amazon Bedrock AgentCore tools with AWS Network Firewall, you can give AI agents controlled web access while maintaining security and compliance alignment. The domain-based filtering approach helps you define precisely which websites agents can access, block unwanted destinations, and log the connection attempts for audit purposes. This architecture addresses the security concerns raised by enterprise customers:

  • FSI compliance: Provides the network isolation and audit logging required for CISO-level security reviews.
  • Multi-tenant control: Enables per-customer or per-execution domain policies for SaaS providers.
  • Prompt injection defense: Restricts agent navigation to approved domains, helping reduce the attack surface for prompt injection.
  • Audit evidence: Generates CloudWatch logs that support compliance audit requirements.

For enterprises deploying AI agents that need internet access for research, data gathering, or API integrations, this pattern provides a production-ready approach to maintaining strict control over where that access leads. Rather than maintaining custom squid proxies or complex network infrastructure, you can use AWS managed services to implement enterprise-grade egress filtering in hours, not weeks.

For more information about AgentCore Browser, see the AgentCore Browser documentation.

About the authors

Kosti Vasilakakis

Kosti Vasilakakis is a Principal PM at AWS on the Agentic AI team, where he has led the design and development of several Bedrock AgentCore services from the ground up, including Runtime, Browser, Code Interpreter, and Identity. He previously worked on Amazon SageMaker since its early days, launching AI/ML capabilities now used by thousands of companies worldwide. Earlier in his career, Kosti was a data scientist. Outside of work, he builds personal productivity automations, plays tennis, and enjoys life with his wife and kids.

Evandro Franco

Evandro Franco is a Sr. Data Scientist working on Amazon Web Services. He is part of the Global GTM team that helps AWS customers overcome business challenges related to AI/ML on top of AWS, mainly on Amazon Bedrock AgentCore and Strands Agents. He has more than 18 years of experience working with technology, from software development, infrastructure, serverless, to machine learning. In his free time, Evandro enjoys playing with his son, mainly building some funny Lego bricks.

Kevin Orellana

Kevin Orellana is a Software Development Engineer at Amazon Web Services on the Bedrock AgentCore team, based in Seattle. He builds and operates core infrastructure powering agentic AI capabilities, including Browser, Code Interpreter, and Runtime. Earlier in his career, Kevin worked on the Bedrock inference team hosting frontier models. In his free time, he enjoys hiking with his Goldendoodle, experimenting with multi-agent simulations, and working toward building a personal AI assistant that speaks English, Spanish, and Mandarin.

Yan Marim

Yan Marim is a Sr. GenAI Specialist Solutions Architect at Amazon Web Services, based in Brazil. As part of the LATAM Specialist team, he guides customers through their generative AI adoption journey, focusing on Amazon Bedrock and agentic AI solutions. In his free time, Yan enjoys spending quality time with his wife and dog, and watching soccer games.

.Organize the content with appropriate headings and subheadings ( h2, h3, h4, h5, h6). Include conclusion section and FAQs section with Proper questions and answers at the end. do not include the title. it must return only article i dont want any extra information or introductory text with article e.g: ” Here is rewritten article:” or “Here is the rewritten content:”

Generate single title from this title How educators are shaping the future of edtech in 100 -150 characters. And it must return only title i dont want any extra information or introductory text with title e.g: ” Here is a single title:”

Write an article about

Key points:

Every school year brings an influx of IT solutions designed to reinvent K-12 education. Schools are primed to jump on the latest technologies to address the issues most impacting our students. Yet, in districts’ rush to innovate, we often allow technology and convenience to replace the curiosity and joy in learning.

What if the latest trends in edtech aren’t related to new products pitched to us, but to new ways we as educators can shape innovation? Instead of being passive customers, we can become co-designers and decision-makers in building the future of education.

I recently spoke with two tech leaders who shared firsthand insights from the field, highlighting tech trends on the horizon and how school leaders can thoughtfully leverage them for their students.

Universal access is no longer just be a nice-to-have

One of the most significant shifts in education is moving beyond “who” has access to IT toward usable access for all, while at the same time, prioritizing privacy and security. Schools are increasingly investing in technology that promotes a Universal Design for Learning (UDL), erasing barriers and embracing flexibility and adaptability. 

At the same time, procurement teams have become far more discerning. Rather than be swayed by overpromises, they are focused on securing tools offering single sign-ons, offline modes, and built-in inclusive features like adjustable interfaces, screen readers, and text-to-speech support. With IT asset management solutions, districts can understand how and where devices and tools are used in order to make smarter decisions that best support learners’ different needs.

Just as important as choosing the right tools is reshaping how students engage with technology. According to Jen Hall, content integration specialist for Atlanta Public Schools, the district has focused on developing best practices for using AI rather than establishing policies and guidelines. The key has been providing extensive training to teachers and students on the safe and ethical use of technology.

Students will become conductors of their learning

Educators are understandably concerned about students’ over-reliance on AI shortcuts. Technology has allowed them the luxury of cognitive offloading, stifling their critical thinking, independent research, and analysis skills. Students need mental struggle to learn and retain information–instead, the reliance on instant answers actually weakens the brain’s neural connectivity. 

As AI lowers the floor for routine tasks, educators need to raise the bar for deeper thinking, allowing opportunities for inquiry, critique, design, and impact. Dr. Stacy Hawthorne, executive director of the EdTech Leaders Alliance, recommends focusing less on tests and more on activities that activate higher-order learning skills. 

It’s simple for AI to create a test and familiar for the students to take them. It’s much more challenging–and at the same time, more motivating–when students take ownership of demonstrating mastery, whether that’s writing extended chapters of a book they just studied, launching a letter-writing campaign about a policy issue, or relating a math concept to a hobby they are interested in. The goal is to lean into tools and resources that allow students to explore and become experts.

The walls of the traditional classroom are starting to come down

New innovations are pushing education toward greater flexibility in student learning. Teachers have to unlearn what a traditional classroom should look like, embracing the mindset that exploration flows when students can connect with technology and each other.

In Atlanta, Verizon Innovative Learning Labs have been launched in Title 1 schools throughout the district. In these collaborative spaces, students can easily transform information learned from textbooks into hands-on projects that offer a tactile learning experience, from designing 3D models to coding programs. For instance, augmented reality (AR) tools in the lab allow students who are studying the solar system to explore the physical features and orbits of each planet.

This approach to greater student autonomy, turning learners into creators, is central to the district’s 21st Century Classroom initiative, centered on building future-ready skills through critical thinking, creativity, communication, and collaboration.

Districts will hand the keys to learning back to teachers

To effectively integrate AI and technology into the classroom, more districts are empowering teachers with the space and autonomy to innovate. Instead of administrator-led classroom observations that evaluate compliance and surface-level learning, many schools have leaned into personalized coaching centered on experimentation and creativity, offering support rather than judgment.

As part of this effort, teachers should be encouraged to adopt a simple three-phase approach when trying something new. In phase one, the goal is exploration–if a new strategy isn’t harming student learning, but shows genuine promise, that’s a win. Phase two focuses on refinement–reiterating, adjusting, and improving. And in phase three, share what works with colleagues who might benefit. When educators build on one another’s successes, that’s when innovation truly takes off.

In today’s tech-driven world, there will always be an initiative du jour that captures our attention. But with the influx of new products and services headed our way, it’s important to remember that when working with AI, we can’t abandon HI–the human, intelligence part of learning. The greatest innovations come from the teachers who remove the guardrails of learning and show their students the joy and excitement in trying something new.

Latest posts by eSchool Media Contributors (see all)

.Organize the content with appropriate headings and subheadings ( h2, h3, h4, h5, h6). Include conclusion section and FAQs section with Proper questions and answers at the end. do not include the title. it must return only article i dont want any extra information or introductory text with article e.g: ” Here is rewritten article:” or “Here is the rewritten content:”

Generate single title from this title RPA matters, but AI changes how automation works in 100 -150 characters. And it must return only title i dont want any extra information or introductory text with title e.g: ” Here is a single title:”

Write an article about

RPA (robotic process automation) is a practical and proven way to reduce manual work in business processes without AI systems. By using software bots to follow fixed rules, companies can automate repetitive tasks like data entry and invoice processing, and to a certain extent, report generation. Adoption grew quickly in many sectors, especially in finance, operations, and customer support.

In recent years the technology has matured. While RPA is still used, business processes can become more complex. Many systems handle unstructured data, like messages and documents. Rule-based automation struggles to handle these inputs, since it depends on predefined steps and structured formats. RPA works best in stable environments where processes do not change often. When conditions change or inputs vary, bots can fail or need updating, adding maintenance overhead and reducing the value of automation over time.

Gartner has pointed to more adaptive automation systems on the market, designed to handle variation and uncertainty, combining automation with machine learning or language models, allowing them to process a broader set of inputs.

From RPA rules to AI-driven automation

AI has changed how companies think about automation, as systems from vendors already known in the RPA space, like Appian and Blue Prism, can now interpret context and adjust their activities, especially relevant for tasks that involve text or images.

Large language models’ ability to summarise documents and extract important details, and respond to queries in natural language offers automation in areas previously difficult to manage. McKinsey & Company research suggests generative AI could automate decision-making and communication work tasks, not routine data handling.

The change does not replace automation, but rather modifies it. Rather than building chains of rules, businesses could use AI to handle variations in input media. Automation becomes more flexible, with systems able to adjust to different inputs without reconfiguration.

That’s the theory. AI systems produce inconsistent outputs, and their behaviour is not predictable. Firms can combine AI with existing automation tools, using each where it fits best. Getting the balance right – intelligent automation – is a hot topic at industry events and on the pages of the RPA and AI media outlets.

Where RPA still fits with AI

Despite these changes, RPA remains relevant in many settings. Tasks that involve structured data and stable workflows still benefit from rule-based automation. Common examples include payroll processing and compliance checks, as well as system integrations.

In these circumstances, RPA’s predictability can be an advantage. Bots follow defined steps and produce consistent results, which is useful in regulated environments. Financial reporting and auditing processes, for example, frequently require strict control and traceability.

Rather than being replaced, RPA is often used with AI. Automation workflows may begin with AI systems that interpret input, then pass structured data to RPA bots for execution. The combination allows companies to extend automation without discarding existing systems.

Blue Prism and the change toward intelligent automation

Vendors that built their business around RPA are adapting to this change. Blue Prism, now part of SS&C Technologies, has expanded its focus to include what it describes as intelligent automation. This approach combines RPA with AI tools capable of processing more complex inputs.

Platforms combine automation with abilities like document processing and decision support, frequently through integrations with AI tools.

The move toward AI-enabled automation also changes how platforms get used. Workflows bring together data sources and decision points, along with execution steps in a single process.

A gradual transition, not a full replacement

Many organisations continue to rely on existing RPA systems, especially where processes are stable and well understood. Replacing these systems would take time and money, which may not always be justified.

Instead, the transformation is gradual. Companies can add AI abilities to extend what automation can handle, while RPA is still in place for tasks where it still works well. This may change how automation is designed and deployed over time, but rule-based systems will remain necessary.

See also: AI agents enter banking roles at Bank of America

Want to experience the full spectrum of enterprise technology innovation? Join TechEx in Amsterdam, California, and London. Covering AI, Big Data, Cyber Security, IoT, Digital Transformation, Intelligent Automation, Edge Computing, and Data Centres, TechEx brings together global leaders to share real-world use cases and in-depth insights. Click here for more information.

AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

.Organize the content with appropriate headings and subheadings ( h2, h3, h4, h5, h6). Include conclusion section and FAQs section with Proper questions and answers at the end. do not include the title. it must return only article i dont want any extra information or introductory text with article e.g: ” Here is rewritten article:” or “Here is the rewritten content:”

Generate single title from this title 7 Free Web APIs Every Developer and Vibe Coder Should Know in 100 -150 characters. And it must return only title i dont want any extra information or introductory text with title e.g: ” Here is a single title:”

Write an article about


Image by Author

 

Introduction

 
The fastest way to make an artificial intelligence (AI) app genuinely useful is to connect it to live web data. That usually means giving it the ability to search the web, extract content from pages, and generate grounded answers based on current information. When an app can do that well, it becomes far more practical, relevant, and reliable.

This article looks at seven free-to-start web application programming interfaces (APIs) that can help developers build smarter machine learning workflows with real-time web access. These tools make it easier to bring live retrieval into local agents, coding assistants, and automation setups, whether you are building side projects, prototypes, or more serious production tools.

We will explore what makes each option useful, the key features it offers, and how it can fit into a data science stack. We will also look at how easy they are to integrate into local AI agents using Python or JavaScript software development kits (SDKs), REST APIs, Model Context Protocol (MCP) support, and, in some cases, agent skills that make installation and setup much simpler.

 

1. Firecrawl

 
Firecrawl has improved a lot in a very short time. Early on, it felt slower and less reliable for web search, but it has quickly become one of the most popular tools for AI agents. What makes it stand out is that it does not just scrape pages. It can search the web, crawl sites, map URLs, extract clean large language model (LLM)-ready content, and even support agent workflows through MCP and its own skill setup.

 

// Key Features

  • Scrape URLs into markdown, HTML, or structured JSON
  • Search the web and optionally scrape results
  • Map websites to discover important pages
  • Crawl sites for larger-scale extraction
  • LLM-ready output for agent workflows
  • MCP Server and Firecrawl Skill support
  • Browser sandbox for interactive web tasks

 

// Simple Usage Command

 

npx -y firecrawl-cli@latest init --all --browser

 

2. Tavily

 
Tavily started out as a fast web search tool for AI models, but it has slowly grown into a more complete web API platform. It now supports search, extraction, crawling, mapping, and research workflows, which makes it much more useful for real AI agents. It is especially popular with vibe coders because it is fast, built for large action models, and easy to connect through its managed MCP server and agent skill support.

 

// Key Features

  • Fast web search API
  • Extract API for webpage content
  • Crawl API for larger website discovery
  • Map API for URL discovery
  • Research API for deeper multi-step research
  • Managed MCP server
  • Agent Skills support

 

// Simple Usage Command

 

npx skills add https://github.com/tavily-ai/skills

 

3. Olostep

 
Olostep stands out as one of the most complete web APIs built specifically for AI and research agents. Instead of focusing on just one layer such as search or scraping, it brings together search, scrape, crawl, map, answers, structured data, files, scheduling, and custom agents in one platform. That broader product surface makes it especially compelling for developers who want to build end-to-end research and automation workflows without stitching together multiple tools.

 

// Key Features

  • Search API for live web search
  • Scrape API for LLM-ready extraction
  • Crawl API for recursive site crawling
  • Map API for URL discovery
  • Answers API for grounded answers with sources
  • Batch API for processing many URLs
  • Agents API for custom research workflows
  • Files and sandbox support for broader agent use cases

 

// Simple Usage Command

 

env OLOSTEP_API_KEY=your-api-key npx -y olostep-mcp

 

4. Exa

 
Exa feels like one of the most AI-native tools on this list. It is fast, accurate, and built for agent workflows from the start. It is especially strong for focused search across areas like company research, people lookup, news, financial reports, research papers, and code documentation. It also stands out for offering dedicated Agent Skills, including a Company Research Agent Skill for Claude Code, which makes it even more useful for research-heavy agent workflows.

 

// Key Features

  • Fast web search built for AI agents
  • Strong support for company, people, news, and code research
  • Website contents and crawling tools
  • Structured outputs for extraction workflows
  • MCP and Agent skills support

 

// Simple Usage Command

 

claude mcp add --transport http exa https://mcp.exa.ai/mcp

 

5. Bright Data

 
Bright Data feels more enterprise than most tools on this list, but it has become increasingly useful for AI agents too. It is not just a scraping API. It gives you a full web data stack with search, unblocking, browser automation, crawling, and structured extraction, which makes it a strong option when simple scraping tools start to break on harder websites. Its Web MCP is also a big plus for agent workflows, especially when you need live web access without getting blocked.

 

// Key Features

  • Web Access APIs for search, crawling, browser automation, and unblocking
  • Unlocker API for bypassing tougher anti-bot protections
  • Browser API with Playwright and Puppeteer style automation
  • Structured data extraction and ready-to-use web data workflows
  • Web MCP with multiple tool groups for AI agents

 

// Simple Usage Command

 

 

6. You.com

 
You.com has grown from a search product into a much more complete platform for AI agents. It now gives developers web-grounded search, live content retrieval, research workflows, MCP support, and Agent Skills, which makes it a strong option for coding agents and research agents. One of its biggest strengths is how easy it is to plug into agent environments, whether the goal is fast search, page extraction, or deeper citation-backed research.

 

// Key Features

  • Web and news search with advanced filtering
  • Content extraction from URLs in markdown or HTML
  • Research tool for citation-backed answers
  • MCP server for agent workflows
  • Agent Skills for tools like Claude Code, Cursor, Codex, and OpenClaw
  • Python and TypeScript SDKs

 

// Simple Usage Command

 

npx skills add youdotcom-oss/agent-skills

 

7. Brave Search API

 
Brave Search API remains one of the most used web search APIs among developers and vibe coders because it is fast, simple, and gives results from an independent web index instead of relying on the same mainstream sources. That makes it especially useful for AI agents that need fresher, more grounded, and sometimes different search results. It has also expanded beyond standard search with AI Answers, local enrichments, and official Agent Skills support for coding agents and research workflows.

 

// Key Features

  • Web Search API powered by an independent Brave index
  • AI Answers API with source-backed answers
  • Local and rich data enrichments
  • Strong fit for agentic search and grounding
  • Official Agent Skills for coding agents and AI tools

 

// Simple Usage Command

 

npx openskills install brave/brave-search-skills

 

Comparison Table

 
Now we will compare these web APIs by best use case, core strengths, and free tier model.

 

API Best For Main Strengths Free Access
Firecrawl All-in-one agent web workflows Search, scrape, crawl, map, LLM-ready extraction One-time 500 credits
Tavily Fast AI search and research Search, extract, crawl, map, research, managed MCP Monthly1,000 credits
Olostep Broad agent workflows in one API Search, scrape, crawl, map, answers, batches, agents One-time500 requests
Exa AI-native search and research Semantic search, code search, MCP, Agent Skills Monthly1,000 free requests
Bright Data Hard sites and enterprise scraping Unblocking, browser automation, extraction, web access tools Monthly5,000 MCP requests
You.com Citation-backed research agents Search, content retrieval, research API, MCP, Agent Skills One-time\$100 credits
Brave Search API Independent search results Brave index, AI Answers, fresh search results, agent fit Monthly\$5 credits

 
 

Abid Ali Awan (@1abidaliawan) is a certified data scientist professional who loves building machine learning models. Currently, he is focusing on content creation and writing technical blogs on machine learning and data science technologies. Abid holds a Master’s degree in technology management and a bachelor’s degree in telecommunication engineering. His vision is to build an AI product using a graph neural network for students struggling with mental illness.

.Organize the content with appropriate headings and subheadings ( h2, h3, h4, h5, h6). Include conclusion section and FAQs section with Proper questions and answers at the end. do not include the title. it must return only article i dont want any extra information or introductory text with article e.g: ” Here is rewritten article:” or “Here is the rewritten content:”

Generate single title from this title Maximize AI Infrastructure Throughput by Consolidating Underutilized GPU Workloads in 100 -150 characters. And it must return only title i dont want any extra information or introductory text with title e.g: ” Here is a single title:”

0

Write an article about

In production Kubernetes environments, the difference between model requirements and GPU size creates inefficiencies. Lightweight automatic speech recognition (ASR) or text-to-speech (TTS) models may require only 10 GB of VRAM, yet occupy an entire GPU in standard Kubernetes deployments. Because the scheduler maps a model to one or more GPUs and can’t easily share across GPUs across models, expensive compute resources often remain underutilized. 

Solving this isn’t just about cost reduction—it’s about optimizing cluster density to serve more concurrent users on the same world-class hardware. This guide details how to implement and benchmark GPU partitioning strategies, specifically NVIDIA Multi-Instance GPU (MIG) and time-slicing to fully use compute resources.

Using a production-grade voice AI pipeline as our testbed, we show how to combine models to maximize infrastructure ROI while maintaining >99% reliability and strict latency guarantees. 

Addressing GPU resource fragmentation

By default, the NVIDIA Device Plugin for Kubernetes shows GPUs as integer resources. A pod requests nvidia.com/gpu: 1, and the scheduler binds it to a physical device.

Large language models (LLMs) like NVIDIA Nemotron, Llama 3, or Qwen 7B/8B require dedicated compute to maintain low time to first token (TTFT) and high batch throughput. However, support models in a generative AI pipeline—embedding models, ASR, TTS, or guardrails—often use only a fraction of a card. Running these lightweight models on dedicated GPUs results in:

  • Low utilization: GPU compute utilization often hovers near 0-10%.
  • Cluster bloat: More nodes need provisioning to run the same number of pods.
  • Scaling friction: Adding a new capability requires a new physical GPU.

To solve this, we must break the 1:1 relationship between pods and GPUs.

Architecture: Partitioning strategies

We evaluated two primary strategies for GPU partitioning supported by the NVIDIA GPU Operator.

Software-based partitioning: Time-slicing and MPS

Time-slicing enables multiple NVIDIA CUDA processes to share a GPU by interleaving execution. It functions similarly to a CPU scheduler: context A runs, pauses, and context B runs.

  • Mechanism: Software-level scheduling through the CUDA driver.
  • Pros: Maximizes utilization. Enables “bursting”—if Pod A is idle, Pod B can use 100% of the GPU’s compute cores.
  • Cons: No hardware isolation. A memory overflow (OOM) in one pod may impact the shared execution context,  and heavy compute in one pod can throttle neighbors (the “noisy neighbor” effect).

In addition to time-slicing, NVIDIA Multi-Process Service (MPS) offers an alternative software-based approach. MPS enables multiple processes to share GPU resources concurrently by using a server-client architecture. This provides more flexibility than MIG and is more resilient to certain issues like memory leaks compared to standard time-slicing. 

However, in production, both methods share a single execution context, limiting isolation. While modern MPS provides isolated virtual address spaces, it lacks hardware-level fault isolation. This means a fatal execution error or illegal memory access in one process will propagate across the shared context, potentially leading to a GPU reset that affects other processes sharing the card.

MIG: The hardware approach to partitioning

MIG physically partitions the GPU into separate instances, each with its own dedicated memory, cache, and streaming multiprocessors (SMs). To the OS and Kubernetes, these look like separate PCI devices.

  • Mechanism: Hardware-level isolation.
  • Pros: Strict quality of service (QoS). One workload can’t impact the performance or memory stability of another.
  • Cons: Rigid sizing. If a partition is idle, its compute resources can’t be “borrowed” by a neighbor.

While time-slicing offers flexibility, MIG is preferred for production environments where strict hardware-level fault isolation is required to meet enterprise SLAs. Hardware partitioning ensures that a memory error in one model cannot cause a cascading failure across the shared GPU—a critical requirement for mission-critical Voice AI.

Experimental setup: The voice AI pipeline

A technical architecture diagram of a multimodal Voice AI pipeline. It shows a User interacting with a Voice Gateway-Orchestrator that manages data flow between an ASR NIM, LLM NIM, and TTS NIM. The system includes Redis for session context and a monitoring namespace with Prometheus and Grafana.

Figure 3: Voice-to-voice AI workflow

To validate these strategies in a production-realistic scenario, we used a multimodal voice-to-voice AI pipeline. This workload is ideal for benchmarking because it mixes three distinct traffic patterns:

Before optimizing, it’s critical to understand our latency profile. In our voice-to-voice pipeline, the LLM is the dominant bottleneck. Under heavy loads, the LLM accounts for ~9 seconds of the total processing time. This delay can fluctuate significantly based on context length; for instance, high-input scenarios (like training users) or growing conversation histories increase processing overhead compared to short prompts. As history accumulates, the LLM must process more tokens before generating a response, extending the bottleneck that support models must be masked behind.

Consolidating support models like ASR and TTS provides a strategic path to maximize hardware utilization while maintaining end-to-end responsiveness. While consolidation may introduce a slight latency adjustment of 100-200 ms, the gains in infrastructure throughput and ROI are significant.

Our hypothesis

Consolidating ASR and TTS workloads on a single GPU preserves latency and jitter while freeing compute for additional LLM instances.

Experiment

A visual representation of the three experimental setups: baseline (three GPUs), time-slicing (two GPUs), and MIG partitioning (two GPUs).

Figure 4. Experimental topology configurations 

We designed three distinct configurations for testing. In each round, we used three voice samples, waiting for the first response from LLM+TTS to complete. The setup used a Kubernetes cluster, models deployed using NVIDIA NIM, and managed by the NVIDIA NIM Operator. The worker node had access to three NVIDIA A100 Tensor Core GPUs.

  • Experiment 1: Baseline with three GPUs
    • Setup: One dedicated GPU for each model (LLM, ASR, TTS).
    • Goal: Establish the “gold standard” for latency and throughput against which to measure optimization.
    • Resource: nvidia.com/gpu: 1 per pod.
  • Experiment 2: Time-slicing with two GPUs
    • Setup: LLM retains a dedicated GPU. ASR and TTS share GPU 0 using software-level time-slicing.
    • Goal: Test if dynamic scheduling can handle the “noisy neighbor” contention between streaming ASR and bursty TTS.
    • Resource: nvidia.com/gpu: 1 (Shared via replicas: 2).
  • Experiment 3: MIG Partitioning with two GPUs
    • Setup: LLM retains a dedicated GPU. GPU 0 is physically partitioned into two isolated instances.
    • Goal: Test if hardware isolation provides better stability than software scheduling.
    • Resource: nvidia.com/mig-3g.40gb: 1 per pod.

Configuration Note: To achieve these topologies, we used specific configurations within the NVIDIA GPU Operator.

  • For Experiment 2, we used the timeSlicing configuration to advertise multiple replicas per physical GPU.
  • For Experiment 3, we applied a custom mig-configs ConfigMap to partition the GPU into two 3g.40gb instances.

(For the exact kubectl commands and YAML manifests used to reproduce this setup, please see the Implementation Appendix at the end of this post.)

Results

To evaluate resource fragmentation, we tested the system with two distinct traffic patterns:

  • Light load: 5 concurrent users simulating ~135 seconds of sustained interaction.
  • Heavy load: 50 concurrent users simulating ~375 seconds of sustained interaction. 

A bar chart comparing GenAI inference throughput in requests per second per GPU across light and heavy loads. Under heavy load, Experiment 3 (MIG) achieves the highest efficiency at 1.00 Req/Sec, compared to 0.74 for the Baseline and 0.76 for Time-Slicing.

Figure 5. Throughput comparison

Figure 5 compares generative AI inference throughput across traffic patterns. The data shows how partitioning affects process requests as concurrency increases, across baseline (dedicated GPUs), time-slicing (software sharing), and MIG (hardware partitioning) under light and heavy loads. All experiments have a 100% success rate, no failures. The current req/s is the reason for the LLM bottleneck in the pipeline.

Mean latency metrics

A bar chart showing the mean latency in milliseconds for ASR, LLM TTFT, and TTS under heavy load. ASR latency is approximately 511–516ms across all tests; LLM TTFT remains steady around 46–48ms; and TTS latency varies between 144.7ms for Time-Slicing and 168.2ms for MIG.

Figure 6. Heavy load latency

A bar chart measuring pipeline component latency during light load (5 concurrent users). ASR latency is between 476.4ms and 490.2ms; LLM TTFT ranges from 36.7ms to 38.6ms; and TTS latency ranges from 99.7ms to 106.3ms across the three experiments.

Figure 7: Light load latency

The following analysis evaluates how different GPU partitioning strategies impact overall system efficiency and responsiveness.

Throughput compared to latency

Consolidating ASR and TTS workloads onto a single GPU results in an optimized pipeline, enabling the cluster to support more simultaneous AI streams. However, our benchmarks reveal a critical performance divergence between the two partitioning strategies:

  1. MIG (hardware): Highest efficiency 

Experiment 3 achieved the highest per-unit productivity, reaching ~1.00 req/s per GPU. By providing dedicated hardware paths for each instance, MIG eliminates resource contention. Organizations can achieve near-full system capacity while effectively freeing up an entire GPU for other heavy LLM workloads.

  1. Time-slicing (software): Higher density with overhead 

Experiment 2 showed that software-level sharing can also improve per-GPU density compared to the baseline, achieving ~0.76 req/s per GPU. However, the CUDA driver’s management of rapid context switches between streaming and bursty models introduces scheduling overhead. While functional, this software-based approach doesn’t reach the aggregate throughput efficiency provided by hardware partitioning.

Latency and the bursty factor 

Time-slicing handles individual bursty tasks slightly faster, with a mean TTS latency of 144.7 ms compared to MIG’s 168.2ms. However, this 23.5 ms difference represents a small fraction of the total end-to-end pipeline response time at the present scale. Under heavy load, the LLM accounts for the vast majority of the total interaction time. Because the end-user cannot perceive a 20ms delta within a multi-second response, the throughput stability of MIG is a more valuable production metric.

Recommendations for partitioning

Based on the benchmark data, we recommend the following decision matrix:

  1. Default to MIG for production scale and stability
    • Experiment 3 showed that MIG handles higher request volumes (2 req/s) with only a minor latency trade-off.
    • Strict hardware-level fault isolation prevents a memory overflow in one process from crashing the other.
    • Best for production environments where throughput and 100% reliability are the priorities.
  2. Use time-slicing for development or low-concurrency apps
    • This involves a 32% reduction in total throughput and shared-resource dependencies.
    • Best for development, CI/CD, and PoCs to run a full pipeline on a minimal hardware footprint.

Get started

  1. Experiment further: Try the repository.
  2. Implement partitioning: Follow our Implementation Guide to configure MIG profiles and use the provided YAML manifests to eliminate resource fragmentation in your cluster.
  3. Scale with NIM: Deploy NVIDIA NIM pipelines to fully utilize your ASR, TTS, and LLM workloads for maximum ROI.

.Organize the content with appropriate headings and subheadings ( h2, h3, h4, h5, h6). Include conclusion section and FAQs section with Proper questions and answers at the end. do not include the title. it must return only article i dont want any extra information or introductory text with article e.g: ” Here is rewritten article:” or “Here is the rewritten content:”

Generate single title from this title A developer’s guide to age-appropriate safety architecture in 100 -150 characters. And it must return only title i dont want any extra information or introductory text with title e.g: ” Here is a single title:”

Write an article about

Key points:

When I shipped Gramms AI to the App Store, I ran straight into a question that every developer building for kids will eventually face: What does “age-appropriate” actually mean in practice? And how do you build systems that enforce it reliably?

Gramms is a bedtime story app. It generates personalized tales narrated in a grandparent’s cloned voice. Sounds simple enough. But the safety architecture behind it was anything but.

This is a practitioner’s account of the decisions behind Gramms, written to be useful to anyone building AI-powered products for children ages 3–10. None of this is legal advice, but all of it is hard-won.

1. Age bands: Not all children are the same audience

The most important design decision you’ll make is abandoning the idea of a single “kid-safe” content level. A story that works for a 9-year-old (mild conflict, narrative tension, multi-step moral reasoning) may genuinely frighten a 3-year-old. And a 9-year-old will check out in about 30 seconds if the content feels like it was made for a 4-year-old.

Gramms uses three developmental age bands, each with its own prompt engineering layer:

  • Ages 3–5: Simple vocabulary, 200–400 word stories, single-protagonist narratives, repetitive structure, no conflict that requires resolution. Themes like friendship, animals, magical helpers. Language complexity targets a kindergarten Lexile range.
  • Ages 6–8: Richer vocabulary, light challenge and resolution, two- to three-character dynamics, mild suspense that resolves happily. Stories run 400–600 words. Introduces simple cause-and-effect morality.
  • Ages 9–10: Near-chapter-book structure, multi-step plots, humor that requires inference, protagonist agency and consequence. Stories can reach 600–800 words. Begins to introduce ambiguous situations with nuanced resolution.

These bands are encoded directly into the system prompt sent to the language model. The child’s age isn’t just metadata. It’s a hard constraint that shapes every element of generation: word choice, sentence structure, thematic scope, and narrative stakes.

2. Parental consent architecture for COPPA compliance

COPPA (the Children’s Online Privacy Protection Act) requires verifiable parental consent before collecting personal information from children under 13. In an AI app, “personal information” is broadly interpreted. A child’s name, age, and interests all qualify.

Apple reinforces this with its own App Store Review Guidelines (Section 5.1.4), which require explicit disclosure of which third-party AI services process user data. Gramms surfaces this at the point of parental consent. Before any profile is saved, the parent sees a screen naming OpenAI and Cartesia as our AI vendors, explaining what data each receives, and requiring active acknowledgment. This isn’t a terms-of-service checkbox. It’s a blocking action gate.

Two practical notes for developers building something similar:

First, design consent as a parent-first flow. The child’s profile creation should be gated behind an account that an adult controls. Not a frictionless onboarding flow that a seven-year-old could complete alone.

Second, store consent timestamps and vendor lists server-side. If your AI vendor changes (we migrated our text-to-speech provider mid-development), you need an audit trail and a mechanism to re-surface consent disclosures to existing users.

3. Automated content moderation: Defense-in-depth

Prompt engineering reduces risk, but doesn’t eliminate it. Language models are probabilistic systems. A carefully constructed prompt can still produce output that slips through. For a children’s product, “mostly safe” is not an acceptable quality bar.

Gramms implements a two-pass system. The first pass is prompt-level: the system prompt for each age band explicitly prohibits violence, fear-inducing antagonists, romantic content, and real-world geographic or political references. The second pass is post-generation moderation. Before a story is delivered to the parent or child, the full text is evaluated by a content moderation API against a children’s content policy.

When a story fails moderation, the user sees a simple “generating a new story” message. No error state, no explanation. The regeneration is silent. A parent should never encounter a moment where the app exposes them to content that required filtering.

One pattern worth calling out: moderating the narration script separately from the story text matters. The narration script (which adds dramatic pacing cues and emotional directions for the voice synthesis) can introduce tonal elements not present in the raw story. If your pipeline separates generation from narration formatting like ours does, apply moderation to both outputs independently.

4. Apple App Store review: Lessons for AI child data apps

Apple’s review process for apps in the Kids category is meaningfully stricter than for general apps, and AI features invite extra scrutiny.

Name every AI vendor explicitly. Apple will ask. Your privacy policy, your App Store description, and your in-app disclosures should all reference the specific companies whose APIs process user data. Not just the category of technology. “We use AI” is insufficient. “We use OpenAI’s GPT-4o-mini for story generation and Cartesia Sonic for voice synthesis” is what reviewers need to see.

Keep child data out of training. Confirm (in writing to reviewers if asked) that your AI provider contracts include data processing agreements that prohibit using child-associated data for model training. Both major providers offer this. You may need to select the appropriate API tier.

Separate child profiles from adult accounts at the data layer. The parent’s account owns the child profiles. Child data should never be independently addressable. It should only be accessible in the context of an authenticated parent session. This architecture is both a COPPA best practice and a common App Review inquiry.

Test with real children before submission. Not because App Review requires it, but because age-appropriateness is easier to calibrate empirically than theoretically. A 4-year-old’s reaction to a story you thought was gentle is a better signal than any content audit rubric.

The bigger picture

Building AI products for children isn’t harder than building them for adults. It’s differently hard. The technical constraints are manageable. The design empathy required is substantial. Every age-band decision, every consent flow, and every moderation threshold represents a judgment about what’s appropriate for a specific child at a specific developmental stage.

Here’s the good news, though: Families are ready for well-built AI children’s products. The anxiety isn’t about AI itself. It’s about carelessness. Demonstrating that you’ve thought carefully about safety architecture, named your vendors, built real moderation, and designed consent for parents rather than for frictionless sign-ups is how you earn that trust.

Robin Singhvi, Gramms AI

Robin Singhvi is the solo founder of Gramms AI (gramms.ai), an iOS app that generates personalized bedtime stories narrated in a grandparent’s cloned voice. Gramms is available on the Apple App Store. He can be reached at robin@gramms.ai.

Latest posts by eSchool Media Contributors (see all)

.Organize the content with appropriate headings and subheadings ( h2, h3, h4, h5, h6). Include conclusion section and FAQs section with Proper questions and answers at the end. do not include the title. it must return only article i dont want any extra information or introductory text with article e.g: ” Here is rewritten article:” or “Here is the rewritten content:”

AI system learns to keep warehouse robot traffic running smoothly | MIT News

0

Inside a giant autonomous warehouse, hundreds of robots dart down aisles as they collect and distribute items to fulfill a steady stream of customer orders. In this busy environment, even small traffic jams or minor collisions can snowball into massive slowdowns.

To avoid such an avalanche of inefficiencies, researchers from MIT and the tech firm Symbotic developed a new method that automatically keeps a fleet of robots moving smoothly. Their method learns which robots should go first at each moment, based on how congestion is forming, and adapts to prioritize robots that are about to get stuck. In this way, the system can reroute robots in advance to avoid bottlenecks.

The hybrid system utilizes deep reinforcement learning, a powerful artificial intelligence method for solving complex problems, to figure out which robots should be prioritized. Then, a fast and reliable planning algorithm feeds instructions to the robots, enabling them to respond rapidly in constantly changing conditions.

In simulations inspired by actual e-commerce warehouse layouts, this new approach achieved about a 25 percent gain in throughput over other methods. Importantly, the system can quickly adapt to new environments with different quantities of robots or varied warehouse layouts.

“There are a lot of decision-making problems in manufacturing and logistics where companies rely on algorithms designed by human experts. But we have shown that, with the power of deep reinforcement learning, we can achieve super-human performance. This is a very promising approach, because in these giant warehouses even a 2 or 3 percent increase in throughput can have a huge impact,” says Han Zheng, a graduate student in the Laboratory for Information and Decision Systems (LIDS) at MIT and lead author of a paper on this new approach.

Zheng is joined on the paper by Yining Ma, a LIDS postdoc; Brandon Araki and Jingkai Chen of Symbotic; and senior author Cathy Wu, the Class of 1954 Career Development Associate Professor in Civil and Environmental Engineering (CEE) and the Institute for Data, Systems, and Society (IDSS) at MIT, and a member of LIDS. The research appears today in the Journal of Artificial Intelligence Research.

Rerouting robots

Coordinating hundreds of robots in an e-commerce warehouse simultaneously is no easy task.

The problem is especially complicated because the warehouse is a dynamic environment, and robots continually receive new tasks after reaching their goals. They need to be rapidly redirected as they leave and enter the warehouse floor.

Companies often leverage algorithms written by human experts to determine where and when robots should move to maximize the number of packages they can handle.

But if there is congestion or a collision, a firm may have no choice but to shut down the entire warehouse for hours to manually sort the problem out.

“In this setting, we don’t have an exact prediction of the future. We only know what the future might hold, in terms of the packages that come in or the distribution of future orders. The planning system needs to be adaptive to these changes as the warehouse operations go on,” Zheng says.

The MIT researchers achieved this adaptability using machine learning. They began by designing a neural network model to take observations of the warehouse environment and decide how to prioritize the robots. They train this model using deep reinforcement learning, a trial-and-error method in which the model learns to control robots in simulations that mimic actual warehouses. The model is rewarded for making decisions that increase overall throughput while avoiding conflicts.

Over time, the neural network learns to coordinate many robots efficiently.

“By interacting with simulations inspired by real warehouse layouts, our system receives feedback that we use to make its decision-making more intelligent. The trained neural network can then adapt to warehouses with different layouts,” Zheng explains.

It is designed to capture the long-term constraints and obstacles in each robot’s path, while also considering dynamic interactions between robots as they move through the warehouse.

By predicting current and future robot interactions, the model plans to avoid congestion before it happens.

After the neural network decides which robots should receive priority, the system employs a tried-and-true planning algorithm to tell each robot how to move from one point to another. This efficient algorithm helps the robots react quickly in the changing warehouse environment.

This combination of methods is key.

“This hybrid approach builds on my group’s work on how to achieve the best of both worlds between machine learning and classical optimization methods. Pure machine-learning methods still struggle to solve complex optimization problems, and yet it is extremely time- and labor-intensive for human experts to design effective methods. But together, using expert-designed methods the right way can tremendously simplify the machine learning task,” says Wu.

Overcoming complexity

Once the researchers trained the neural network, they tested the system in simulated warehouses that were different than those it had seen during training. Since industrial simulations were too inefficient for this complex problem, the researchers designed their own environments to mimic what happens in actual warehouses.

On average, their hybrid learning-based approach achieved 25 percent greater throughput than traditional algorithms as well as a random search method, in terms of number of packages delivered per robot. Their approach could also generate feasible robot path plans that overcame congestion caused by traditional methods.

“Especially when the density of robots in the warehouse goes up, the complexity scales exponentially, and these traditional methods quickly start to break down. In these environments, our method is much more efficient,” Zheng says.

While their system is still far away from real-world deployment, these demonstrations highlight the feasibility and benefits of using a machine learning-guided approach in warehouse automation.

In the future, the researchers want to include task assignments in the problem formulation, since determining which robot will complete each task impacts congestion. They also plan to scale up their system to larger warehouses with thousands of robots.

This research was funded by Symbotic.

Generate single title from this title Databricks Enters Cybersecurity Market With Lakewatch SIEM Platform in 100 -150 characters. And it must return only title i dont want any extra information or introductory text with title e.g: ” Here is a single title:”

Write an article about

Databricks is stepping into the cybersecurity space with Lakewatch, an agentic SIEM platform designed to run on top of its lakehouse architecture and extend it into security operations. Lakewatch is available in private preview.

With this move, the San Francisco-based company is positioning its lakehouse as a central control layer for enterprise data. The move reflects a broader trend in the industry where vendors increasingly incorporate security as part of the data platform itself – and not a separate stack.

Lakewatch brings together security telemetry, threat detection, and incident response directly into the Databricks environment. What this means for users is that they can look at security data in the same place where their other data already sits, instead of sending logs to a separate system before they can figure out what is going on.

(bluestork/Shutterstock)

Many security teams still use SIEM tools that charge based on how much data you send in. Using that method often requires filtering logs or deleting them sooner than they would like just to keep costs down. Databricks is taking a different approach with the lakehouse model. It argues that organizations should be able to keep all their data and look at it when needed, instead of deciding ahead of time what is worth saving.

“Security teams can no longer rely on manual workflows to outpace AI-driven attacks,” said Ali Ghodsi, co-founder and CEO of Databricks. “With Lakewatch, we are giving enterprises a new open data architecture and agentic capabilities to replace stagnating SIEM tools. Defenders must have even better visibility and speed than today’s agent attackers.”

Databricks claims that Lakewatch is designed to handle petabyte-scale telemetry while lowering the cost of security operations by separating storage from compute. This is exactly the architectural approach that Databricks has long promoted in analytics.

Those who have been following Databricks over the years would know that the company has spent years making the same argument for data warehousing and AI workloads, so bringing that model into security feels like a natural next step rather than a completely new direction for the company. 

(La1n/Shutterstock)

The launch also comes with a broader push to build an ecosystem around the platform. Databricks said Lakewatch will be part of what it calls an Open Security Lakehouse Ecosystem, with partners including Akamai, Okta, Palo Alto Networks, Zscaler, Wiz, Deloitte, and others contributing telemetry and integrations. The company is also expanding its work with Anthropic, whose Claude models are being used to power some of the agentic investigation and response capabilities. 

“As the volume of security data grows, organizations need new ways to analyze and act on that information quickly and at scale,” said Karthik Venkatesan, Security Engineering Lead at Adobe. “Databricks provides the foundation needed to move from data-driven to AI-driven approaches for security operations, and Lakewatch is an important step toward bringing security intelligence closer to where data already lives.”

Databricks also disclosed acquisitions of Antimatter and SiftD.ai, two startups focused on agent security and large-scale detection engineering, moves that suggest the company is serious about building a full security stack rather than just adding another feature to the lakehouse.

If you want to read more stories like this and stay ahead of the curve in data and AI, subscribe to BigDataWire and follow us on LinkedIn. We deliver the insights, reporting, and breakthroughs that define the next era of technology.

The post Databricks Enters Cybersecurity Market With Lakewatch SIEM Platform appeared first on BigDATAwire.

.Organize the content with appropriate headings and subheadings ( h2, h3, h4, h5, h6). Include conclusion section and FAQs section with Proper questions and answers at the end. do not include the title. it must return only article i dont want any extra information or introductory text with article e.g: ” Here is rewritten article:” or “Here is the rewritten content:”

Generate single title from this title Student use of AI for homework rises as concerns grow about critical thinking skills in 100 -150 characters. And it must return only title i dont want any extra information or introductory text with title e.g: ” Here is a single title:”

Write an article about

Key points:

Student use of AI for homework increased in 2025, even as more students are worried the technology may be harming their ability to think critically, according to a new RAND report.  

Between May and December 2025, the percentage of middle school, high school, and college students using AI for homework rose from 48 percent to 62 percent, based on nationally representative survey data from RAND’s American Youth Panel. The increase was driven largely by middle and high school students, as use among college students remained relatively steady.

“Students are clearly embracing AI as a learning tool, but they’re also conflicted about what it means for their own learning,” said Heather Schwartz, vice president of RAND’s Education, Employment and Infrastructure division. “They’re using AI to look up answers, get explanations, brainstorm and revise writing, but at the same time, more of them now believe it’s eroding students’ critical-thinking skills.”

According to the survey, 67 percent of students said using AI for schoolwork harmed critical thinking, up from 54 percent earlier in the year. Concern was even higher among students who do not use AI, with 78 percent saying it harmed critical thinking, compared with 60 percent among AI users.

Beyond homework, 71 percent of students reported using at least one type of AI tool for school-related activities. Chatbots were by far the most commonly tool used (60%), followed by writing helpers such as Grammarly or Quill (21 percent) and general homework help platforms like Chegg, Brainly or Course Hero (15 percent). Among specific tools, ChatGPT was the most widely used (53 percent), though use of Google Gemini (28 percent) more than doubled between May and December. 

Students most often reported using AI to get better explanations of assignments (38 percent), brainstorm ideas (35 percent), look up facts (33 percent) and draft or revise writing (33 percent). The survey found that older students were more likely than younger students to use AI for these purposes, with the exception of fact-checking. 

Except for getting direct answers to homework–which 45 percent of students believe to be cheating–most students did not consider many common uses of AI to be cheating. Nearly 80 percent said that using AI to understand an assignment was not cheating, while 72 percent and 67 percent said the same about brainstorming ideas and looking up facts, respectively. 

The survey also found many schools lack clear rules about AI use. Only about one-third of students said their school had a schoolwide policy, and many, especially college students, said rules varied by teacher. Similarly, older students were more likely to believe their teachers checked homework for AI use and to worry about being accused of using AI to cheat.  

Male and female students were equally likely to use AI, but female students expressed greater concern about its effects. According to the survey, 75 percent of female students said AI harmed critical thinking skills, compared with 59 percent of male students, and they were more likely to worry about cheating.

“These findings suggest schools need to be explicit about when and how AI can be used,” Schwartz said. “Students are already using these tools. The question is whether schools can help them use AI in ways that deepen, rather than erode, their critical thinking.”

Supported by Gates Foundation, the survey was conducted in December 2025 and included responses from more than 1,000 students ages 12 to 29 enrolled in school during the 2025–26 academic year. It is part of RAND’s American Youth Panel, a subset of the American Life Panel.

Melissa Kay Diliberti also contributed to the report.

The RAND Education, Employment, and Infrastructure division aims to improve educational opportunity, economic prosperity, and civic life for all. Its analysis offers solutions to strengthen instructional quality in schools, improve the affordability and effectiveness of college and career training, modernize infrastructure, and improve the U.S. justice system.

This press release originally appeared online.

eSchool Media staff cover education technology in all its aspects–from legislation and litigation, to best practices, to lessons learned and new products. First published in March of 1998 as a monthly print and digital newspaper, eSchool Media provides the news and information necessary to help K-20 decision-makers successfully use technology and innovation to transform schools and colleges and achieve their educational goals.

eSchool News StaffLatest posts by eSchool News Staff (see all)

.Organize the content with appropriate headings and subheadings ( h2, h3, h4, h5, h6). Include conclusion section and FAQs section with Proper questions and answers at the end. do not include the title. it must return only article i dont want any extra information or introductory text with article e.g: ” Here is rewritten article:” or “Here is the rewritten content:”