acceptodds
Under review as a conference paper at ICLR 2027

Tool Exposure Is Not Free: Admission and Execution of Tool Calls in LLM Agents

Abstract

Tool-augmented large language model (LLM) agents are evaluated as though offering a tool were free, and work on tool overuse refines that price only in tokens. However, on a mixed workload of reasoning and exact-computation requests, merely making a Python tool available costs a large share of the accuracy on requests that never needed one, and nearly every tool-exposing method we measure pays some version of that price. Exposure is therefore a two-sided decision, not a resource to ration. Two facts follow. Benefiting from a tool implies needing one but not conversely, so even a perfect necessity predictor over-exposes, and the headroom of any admission policy equals the rate at which exposure breaks requests, which makes the value of admission measurable per workload. In this paper, we propose AgentRT, a runtime control plane that decides exposure from serving state before the model generates a token, so the decision costs no forward pass, and that constructs and executes the payload itself for request classes admitting a typed plan. Against ten baselines, AgentRT is the only policy that keeps accuracy on the requests that need no tool intact while solving every request that needs one. It leads every baseline on both accuracy and energy per correct answer, by up to 28 accuracy points and 69% less energy, and by 11 points against the strongest, and the lead holds on paraphrased requests and across 7B-class models. On newer models whose tool policy breaks almost nothing, admission has no headroom, as the analysis predicts, and AgentRT remains the cheapest policy per correct answer on every one of them.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.