Apollo GraphQL launches Agent Services to put field-level access controls between AI agents and enterprise APIs
Apollo's new GraphOS Agent Services, unveiled at Apollo Summit 2026, give companies identity, policy, and audit controls over what AI agents can reach through their APIs.
Apollo GraphQL wants its supergraph to become the control plane for AI agents inside the enterprise. The company announced GraphOS Agent Services on October 7 at Apollo Summit 2026 in San Francisco, a set of services that put identity, policy, and audit controls between AI agents and the APIs they call. Intuit is piloting the services in private preview, and the company says GraphOS already orchestrates more than 2 trillion operations a month across its customers.
What it does
The pitch is straightforward. Agents need to call the same APIs that already run a business, but those APIs were designed for human developers. An API might return billing details or internal notes alongside the customer information an agent asked for, and the judgment about what is safe to pass along usually lives in a developer's head. Apollo's answer is to make that judgment explicit and enforce it on every call, with controls that can restrict what an agent sees and does down to the individual field, outside the model's decision loop.
GraphOS Agent Services are built on the company's GraphOS platform for connecting and orchestrating enterprise APIs. Apollo says the services translate each agent request into the right API calls, broker the credentials needed to invoke tools, and enforce governance policies. The MCP server, which exposes existing GraphQL APIs as tools AI agents can call directly, has been expanded from a single server into a full suite of agent-ready tools for building and managing the graph.
Apollo is also previewing a GraphOS Router update aimed at reducing the time and memory spent on query planning, and adding a set of AI skills plus an Operator for deploying the MCP server on Kubernetes. Agents will even be able to query the knowledge graph itself to check launch history, composition errors, lint results, and router status. PR Newswire carries the full announcement, and Techstrong.ai has an independent writeup of the launch.
Why this matters for developers
The interesting architectural call is where Apollo places authorization. Keeping the access decision out of the model means a prompt injection or a confused agent cannot talk its way into fields it should not see, because the enforcement happens in the graph layer, not in the LLM. That is a different trust model from bolting guardrails onto the agent itself.
The Summit agenda suggests this is landing with real enterprise traction. Sessions include Brex describing how it pointed an agent at dead code in its federated graph and deleted over 100,000 lines with no customer impact, and N-able explaining how it exposed its APIs to agents through the Apollo MCP Server. The session lineup leans heavily on agent governance patterns.
Claims to keep in context
Most of the hard numbers here are Apollo's own: the 2 trillion monthly operations figure is company-reported, and GraphOS Agent Services are in private preview with Intuit, so there is no public customer evidence yet of how the field-level controls hold up under production agent traffic. RuntimeWire's coverage makes the same point, noting that performance claims around the router improvements are unverified so far. Apollo Summit runs October 6-8 as part of SF Tech Week, and more customer sessions land this week.