Containment and border architecture for autonomous agents: two open standards, independently adoptable
AI agents already carry out filings, purchases and administrative work on behalf of people and companies. Two distinct problems stand in the way, and they are usually conflated. The first is that what gets executed exceeds what was asked. Not through deception: a task is decomposed, side steps appear that nobody enumerated — a file read along the way, a credential copied, a second endpoint called — and they execute like any other step. Nothing in the stack distinguishes the step that was requested from the step that was merely convenient. The second is that an agent cannot prove who authorized it or what it came for. The receiving service has no way to know who answers if something goes wrong, so it blocks — legitimate agents included, stopping exactly the work that was worth doing. This document presents two open standards, one for each problem. They are adopted separately. Guardalpha works inside, before the action leaves: the agent declares what it is going to do before doing it, action by action, and what executes matches what was enumerated. A step that was not on the list has no path out. It has two independent parts — one in software and one in hardware, the latter also making it possible to demonstrate that no action occurred without external authorization. GUARDAID works at the border, where the agent reaches someone else's service: it proves who authorized it and what for, read identically in any jurisdiction. It also has two parts adopted on their own — issuing the passport and reading it. Neither standard assumes anything about what the system wants. Every check compares, counts and collates; none judges intent or predicts consequence. A verifier with no notion of what a dam is performs all of them. That property is what keeps them from degrading as models improve. None of this reduces what the model can think, read or propose. What it establishes is that what executes matches what was declared, and that a third party can verify it. Both documents state with equal precision what they guarantee and what they do not. Both are open, free of charge and with nothing to sign: anyone may implement, adapt and operate them indefinitely, keeping attribution. Files. Two documents in English, which is the normative language: the map and the paper. A Spanish translation of the map is included as an informative version; where the translation and the English document differ, the English governs. Feedback. Corrections, implementation reports and findings of an error are welcome at [email protected]. A difference between two of these documents is a defect in one of them, and reporting it is the fastest way it gets fixed.
Authors
- Fabiana Andrea Gómez Martínez (ORCID: https://orcid.org/0009-0006-5518-1365)
Institutions
- Estonian Association for Applied Linguistics (EE)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-10-08
- DOI
- https://doi.org/10.5281/zenodo.23224788
- Primary Topic
- Access Control and Trust
- Type
- preprint