Containment and border architecture for autonomous agents: two open standards, independently adoptable

AI agents already carry out filings, purchases and administrative work on behalf of people and companies. Two distinct problems stand in the way, and they are usually conflated. The first is that what gets executed exceeds what was asked. Not through deception: a task is decomposed, side steps appear that nobody enumerated — a file read along the way, a credential copied, a second endpoint called — and they execute like any other step. Nothing in the stack distinguishes the step that was requested from the step that was merely convenient. The second is that an agent cannot prove who authorized it or what it came for. The receiving service has no way to know who answers if something goes wrong, so it blocks — legitimate agents included, stopping exactly the work that was worth doing. This document presents two open standards, one for each problem. They are adopted separately. Guardalpha works inside, before the action leaves: the agent declares what it is going to do before doing it, action by action, and what executes matches what was enumerated. A step that was not on the list has no path out. It has two independent parts — one in software and one in hardware, the latter also making it possible to demonstrate that no action occurred without external authorization. GUARDAID works at the border, where the agent reaches someone else's service: it proves who authorized it and what for, read identically in any jurisdiction. It also has two parts adopted on their own — issuing the passport and reading it. Neither standard assumes anything about what the system wants. Every check compares, counts and collates; none judges intent or predicts consequence. A verifier with no notion of what a dam is performs all of them. That property is what keeps them from degrading as models improve. None of this reduces what the model can think, read or propose. What it establishes is that what executes matches what was declared, and that a third party can verify it. Both documents state with equal precision what they guarantee and what they do not. Both are open, free of charge and with nothing to sign: anyone may implement, adapt and operate them indefinitely, keeping attribution. Files. Two documents in English, which is the normative language: the map and the paper. A Spanish translation of the map is included as an informative version; where the translation and the English document differ, the English governs. Feedback. Corrections, implementation reports and findings of an error are welcome at [email protected]. A difference between two of these documents is a defect in one of them, and reporting it is the fastest way it gets fixed.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-08
DOI
https://doi.org/10.5281/zenodo.23224788
Primary Topic
Access Control and Trust
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
preprint

Containment and border architecture for autonomous agents: two open standards, independently adoptable

Fabiana Andrea Gómez Martínez
Zenodo (CERN European Organization for Nuclear Research)
Access Control and Trust
preprint

Containment and border architecture for autonomous agents: two open standards, independently adoptable

Fabiana Andrea Gómez Martínez
preprint en

Abstract

AI agents already carry out filings, purchases and administrative work on behalf of people and companies. Two distinct problems stand in the way, and they are usually conflated. The first is that what gets executed exceeds what was asked. Not through deception: a task is decomposed, side steps appear that nobody enumerated — a file read along the way, a credential copied, a second endpoint called — and they execute like any other step. Nothing in the stack distinguishes the step that was requested from the step that was merely convenient. The second is that an agent cannot prove who authorized it or what it came for. The receiving service has no way to know who answers if something goes wrong, so it blocks — legitimate agents included, stopping exactly the work that was worth doing. This document presents two open standards, one for each problem. They are adopted separately. Guardalpha works inside, before the action leaves: the agent declares what it is going to do before doing it, action by action, and what executes matches what was enumerated. A step that was not on the list has no path out. It has two independent parts — one in software and one in hardware, the latter also making it possible to demonstrate that no action occurred without external authorization. GUARDAID works at the border, where the agent reaches someone else's service: it proves who authorized it and what for, read identically in any jurisdiction. It also has two parts adopted on their own — issuing the passport and reading it. Neither standard assumes anything about what the system wants. Every check compares, counts and collates; none judges intent or predicts consequence. A verifier with no notion of what a dam is performs all of them. That property is what keeps them from degrading as models improve. None of this reduces what the model can think, read or propose. What it establishes is that what executes matches what was declared, and that a third party can verify it. Both documents state with equal precision what they guarantee and what they do not. Both are open, free of charge and with nothing to sign: anyone may implement, adapt and operate them indefinitely, keeping attribution. Files. Two documents in English, which is the normative language: the map and the paper. A Spanish translation of the map is included as an informative version; where the translation and the English document differ, the English governs. Feedback. Corrections, implementation reports and findings of an error are welcome at [email protected]. A difference between two of these documents is a defect in one of them, and reporting it is the fastest way it gets fixed.

Zenodo (CERN European Organization for Nuclear Research)
Estonian Association for Applied Linguistics (EE)
Access Control and Trust
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.