Krti Tallam
Proposes a five-plane reference architecture for runtime governance of production AI agents, controlling risk through intent adjudication and four enforcement planes.
Traditional enterprise security is based on data boundary protection, but AI agents perform sequential actions inside workflows, making them uncontrollable by existing policy engines. Agentic systems require stateful evaluation and capability attenuation through delegation chains.
Decomposes into five planes (intent adjudication plane, network/identity/endpoint/data enforcement planes), introduces stop-anywhere mediation, composite principals with capability attenuation, and a structured audit substrate. Defines six interruption primitives (generalizing allow/deny) and four correctness invariants, and blocks seven threats across five workflows.
In a reference implementation, attenuation correctness and evidence reconstructability held on every trial, adjudication ran in single-digit microseconds, and the audit substrate's tamper-evidence behaved as designed. Scope is limited to governance of delegated action, not model behavior.