Large language model (LLM) agents increasingly execute stateful programs rather than isolated prompts: they reason across dependent turns, invoke tools, retain mutable state, and produce external effects. Yet the infrastructure beneath them often exposes execution through request-level or RPC-like interfaces that discard task, workflow, authority, or effect semantics. Across recent systems, this mismatch produces a recurring architectural response: selectively expose execution semantics across an abstraction boundary so that a downstream component can optimize or enforce a property that is otherwise invisible. Examples include program-aware scheduling, session-aware cache management, intent-aware tool validation, information-flow control, semantics-aware checkpointing, and task-scoped transactions. This survey organizes this emerging literature around semantic interfaces. Our structured evidence map, frozen on 27 August 2026, codes 25 primary systems, security, runtime, benchmark, and standardization works, while 11 adjacent surveys are analyzed separately for scope positioning. We separate what semantics are exposed - identity/scope, structure/dependency, state/mutation, intent/authority/trust, and effect/lineage/transaction - from how they are exposed through identifiers, hints, directives, program graphs, policies/capabilities, labels, and transactional boundaries. We further distinguish four operational roles: predictive, directive, normative, and recovery semantics. This two-axis view allows serving optimizations and runtime guarantees to be compared within a common design space. Our synthesis suggests that the central design problem is not unrestricted cross-layer visibility. Rich semantics can become stale, privacy-sensitive, overprivileged, or tightly coupled to a particular framework. We therefore formulate selective, trustworthy semantic exposure as a design principle: expose the minimum semantic projection required for a target optimization or guarantee, bind it to producer, provenance, scope, lifetime, and trust, and invalidate it when the underlying execution state changes. We conclude with open problems in minimal semantic contracts, semantic attestation, cross-layer coherence, dynamic authorization, transactionality, and end-to-end evaluation of reliability-efficiency-control trade-offs.
No takes yet. Share an insight, caveat, or question.
Yue Qin (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: