Experimental evaluation reveals complete denial of unauthorized execution in governed autonomous agents, indicating robust containment through decoupled cognitive and authority planes.
GLAL v0.9 — Governance Layer for Agentic AI presents a vendor-neutral reference architecture for governing agentic AI systems across local, private, air-gapped, and controlled hybrid environments. Its central principle is that increasing cognitive capability must not automatically increase operational authority. GLAL therefore separates the Intelligence Plane, where models interpret information, retrieve context, reason, plan, and propose actions, from an independent Authority Plane, responsible for identity, evidence validation, policy enforcement, authorization, execution constraints, post-action verification, and auditability. Version 0.9 extends this architecture with two additional governance boundaries. The first is an Epistemic Gate, based on the principle that greater uncertainty should contract rather than expand permissible authority: insufficient verified evidence should lead to abstention, evidence retrieval, recommendation-only operation, or human escalation rather than execution based on model confidence alone. The second is a User Agency Boundary for anticipatory and person-specific behavioral inference: the ability to predict likely human behavior does not itself grant permission to persuade, intervene, alter targeting, or act on behalf of that individual. In short: uncertainty up → permissible authority down, and prediction does not imply permission. The study also incorporates model and data poisoning, latent backdoors, model-native communication, semantic canonicalization, uncertainty and abstention, monitor asymmetry, and longitudinal behavioral inference into the broader threat model. Prospective scenarios such as AI 2027 are used only as architectural stress tests and are explicitly separated from empirical evidence. The resulting framework does not require models to become perfectly aligned or infallible; instead, it seeks to prevent cognitive failures, uncertainty, or opaque internal representations from becoming unauthorized external effects. The experimental protocol compares four configurations where applicable: D0, deterministic automation; A, a local copilot without execution authority; B, a direct local agent with tool calling; and C, an agent governed through GLAL. In the exploratory Phase 0 evaluation, 30 synthetic task families were tested, including 18 adversarial cases. The frequency of unauthorized proposals remained similar between the direct-agent and governed-agent conditions, but their operational outcomes differed: configuration B executed seven unauthorized proposals, whereas configuration C received seven unauthorized proposals and denied all seven. These results provide exploratory functional evidence for the intended separation between cognition and authority, while not constituting production validation or evidence of zero residual risk. The work introduces metrics for unauthorized proposals and execution, policy containment, epistemic-gate reliability, behavioral-intervention restriction, attribution, data egress, operational cost, and human oversight. It also emphasizes deterministic baselines, least privilege, agent identity, structured intent, semantic canonicalization, Tool Gateways, blast-radius limits, rollback, kill switches, and reproducible audit trails as building blocks for governed autonomy. The architecture can be summarized by four distinctions:Capability ≠ Authority.Confidence ≠ Evidence.Prediction ≠ Permission.Opaque reasoning ≠ Opaque execution. GLAL v0.9 is intended as a technical study and reference architecture for researchers, cybersecurity practitioners, AI governance teams, and organizations exploring agentic automation while seeking to preserve explicit, bounded, auditable, and revocable authority over real-world effects.
No takes yet. Share an insight, caveat, or question.
Eduardo Parra (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: