Story · arXiv
Runtime Governance for Agentic AI: Action-Boundary Control with Trusted Provenance and Fail-Closed Execution (arXiv)
paper · Story page

Aegis treats model outputs as action proposals and puts a trusted, fail-closed runtime between them and tool execution, with server-side provenance and a quorum path for selected cases. In sandbox runs, governed rows recorded zero risky side-effect completions; prompt-only conditioning produced 79 risky leakage rows.
In plain words
- Researchers built Aegis, a control layer that checks proposed software actions before allowing them to run.
- It checks current rules and trusted server records, refusing uncertain requests instead of guessing.
- Selected requests require agreement from several authorizers, preventing one party from approving them alone.
- In controlled test environments, Aegis recorded zero risky completed actions, while instruction-only safeguards recorded 79 risky leakage cases.
- This matters for organizations letting artificial intelligence change files or send messages because safety checks remain outside the system proposing actions.
Appeared in
- Malicious skills hijack agents mid-task, and debate training curbs reward hacking
Aug 20, 2026 · in the sections
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.
