Aegis Runtime Governance for Agentic AI: Trusted Provenance and Fail-Closed Execution
Aegis, a governance framework designed for agentic AI, has been unveiled in a paper published on arXiv. This system tackles AI safety by overseeing operational consequences stemming from agentic AI models capable of altering files, dispatching messages, or modifying workflows. The authors contend that governance at the prompt level falls short due to its lack of execution boundaries. Aegis views model outputs as action proposals that require validation from a reliable decision layer. It assesses these proposals against current policies, resolves provenance on the server side, and prevents unsafe submissions. Certain cases are subjected to a Senate-like review for non-unilateral approval. The evaluation utilized a sandbox dataset comprising five run families, 42 tasks, and 6,300 data rows. The paper can be found under identifier 2608.16891v1.
Key facts
- Aegis is a runtime governance system for agentic AI.
- It treats model outputs as action proposals subject to a trusted decision layer.
- The system evaluates proposals against active policy state.
- Provenance is resolved server-side.
- It fails closed under uncertainty.
- Selected cases use a Senate-style settlement, a quorum-based non-unilateral authorization path.
- The evaluation spans five run families, 42 tasks, three conditions, and ten repeats per family.
- The paper is on arXiv with identifier 2608.16891v1.
Entities
—