From Model Capability to Governed Action: An Architecture for Secure Agentic AI

Autonomous AI is becoming a systems-security problem, not only a model-safety problem. Modern agents combine foundation models with persistent context, tools, execution environments, credentials, networks, subagents, memory, and increasingly long-running operational loops. Recent frontier-lab disclosures and academic research show why this surrounding architecture matters. A capable model may generate a valid-looking action, discover a path that designers did not anticipate, or execute a sequence of individually permissible steps whose cumulative effect violates a system-level constraint. This article examines three emerging ideas through the lens of governed autonomous systems. First, the runtime or agent harness is becoming a critical boundary between model capability and real-world effect. Second, capability is not authority: knowing how to perform an action does not mean an autonomous system should be permitted to execute it. Third, per-action authorization may be necessary but insufficient when an evolving sequence of actions creates cumulative risk, privilege, or impact. The article introduces the Governed Execution Boundary as a public research framing for the architectural separation between model-generated intent and consequential action. It also examines trajectory-level assurance, governance of reduced-safeguard evaluation environments, machine-speed enforcement, and the relationship between model alignment and external architectural control. The central proposition is: Model capability is not governed authority. A secure autonomous system must decide not only whether an individual action is permissible, but whether the authority remains valid, the evolving trajectory remains acceptable, the resulting effect matches what was authorized, and the behavior remains attributable, revocable, and evidentiary.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-18
DOI
https://doi.org/10.5281/zenodo.22837908
Primary Topic
Ethics and Social Impacts of AI
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

From Model Capability to Governed Action: An Architecture for Secure Agentic AI

Aridio Silva
Zenodo (CERN European Organization for Nuclear Research)
Ethics and Social Impacts of AI
article

From Model Capability to Governed Action: An Architecture for Secure Agentic AI

Aridio Silva
article en

Abstract

Autonomous AI is becoming a systems-security problem, not only a model-safety problem. Modern agents combine foundation models with persistent context, tools, execution environments, credentials, networks, subagents, memory, and increasingly long-running operational loops. Recent frontier-lab disclosures and academic research show why this surrounding architecture matters. A capable model may generate a valid-looking action, discover a path that designers did not anticipate, or execute a sequence of individually permissible steps whose cumulative effect violates a system-level constraint. This article examines three emerging ideas through the lens of governed autonomous systems. First, the runtime or agent harness is becoming a critical boundary between model capability and real-world effect. Second, capability is not authority: knowing how to perform an action does not mean an autonomous system should be permitted to execute it. Third, per-action authorization may be necessary but insufficient when an evolving sequence of actions creates cumulative risk, privilege, or impact. The article introduces the Governed Execution Boundary as a public research framing for the architectural separation between model-generated intent and consequential action. It also examines trajectory-level assurance, governance of reduced-safeguard evaluation environments, machine-speed enforcement, and the relationship between model alignment and external architectural control. The central proposition is: Model capability is not governed authority. A secure autonomous system must decide not only whether an individual action is permissible, but whether the authority remains valid, the evolving trajectory remains acceptable, the resulting effect matches what was authorized, and the behavior remains attributable, revocable, and evidentiary.

Zenodo (CERN European Organization for Nuclear Research)
Peace, Justice and strong institutions
Openalex Percentile: Top 7%
Ethics and Social Impacts of AI
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.