The moment
What Section 2.2.2 of API Policy 4.2026a actually says.
SAP defines an "agent" with unusual precision in the policy text:
"(semi-)autonomous or generative AI systems that plan, select, or execute sequences of API calls"
- SAP API Policy 4.2026a, agent definition
And then prohibits direct API access for anything matching that definition. If your AI agent talks to SAP, the policy applies to you. If it plans, selects, or executes a sequence of calls, it's an agent under SAP's own definition. And if it hits SAP's APIs directly, it's now non-compliant.
What changed
- Undocumented interfaces - gone. Removed entirely.
- ODP large-scale extraction - restricted. The bulk-pull pattern AI vendors had been using is now governed.
- Direct AI agent API access - prohibited. Section 2.2.2 closes the door.
The policy's four preamble goals
The policy preamble names four things its controls exist to do:
- Safeguard solution health and security.
- Promote equitable access.
- Prevent API misuse.
- Support the enforcement of this API Policy.
All four are tractable with the right control layer. AegisAI is that layer.