Tigera advocates for a dual-layer security approach for AI agents, combining L7 gateway policies that enforce authorization intent with kernel-level policies that constrain runtime behavior. By expressing both layers in the same Cedar policy language translated to eBPF, organizations can address security gaps that single-layer approaches leave vulnerable to compromise.