I-D Action: draft-agentic-ai-tool-execution-finality-00.txt

[email protected]
Newsgroups gmane.ietf.announce
Message-ID <178788837706.488.11309165696976906919@dt-datatracker-6669c7b496-s9mrn>
Internet-Draft draft-agentic-ai-tool-execution-finality-00.txt is now
available.

   Title:   Execution Finality for Agentic AI: Stopping Unauthorized Tool Calls, Memory Writes, and Real-World Consequences Before They Happen (DAS -- Decoupled Authorisation System)
   Author:  Sangam Das
   Name:    draft-agentic-ai-tool-execution-finality-00.txt
   Pages:   30
   Dates:   2026-08-27

Abstract:

   Agentic AI systems now call tools, write memory, move money, change
   infrastructure, and trigger physical actions.  Most safety layers
   still decide permission upstream and then trust the downstream path.
   Once that path is compromised, or once the approved request is
   widened, replayed, or substituted, the act becomes real before any
   audit can stop it.

   This document specifies a protected execution-finality architecture
   of the Decoupled Authorisation System (DAS).  It is built on four
   mechanisms: (1) two-instance binding that separates collection-time
   evidence from execution-time validation, (2) mutually load-bearing,
   cross-committed protected evidence so that no single artifact
   authorizes effectuation, (3) scoped non-bearer finality authority
   whose possession alone is never enough, and (4) independent Finality
   Sink reconstruction that re-derives the actual pending operation at
   the effectuation boundary and permits the act only when every
   required condition still matches.

   A Candidate Act remains in a Non-Effective State until the Finality
   Sink has reconstructed the operation, verified the protected evidence
   against sink-local monotonic state, and advanced that state.  Failure
   at any step produces fail-closed denial before effectuation rather
   than post-event remediation.  The architecture is applicable to
   agentic tool use, MCP and connector frameworks, RAG and vector-memory
   systems, cloud control planes, financial settlement, telecom routing,
   and cyber-physical control.

   The document elaborates the problem space, compares the approach with
   representative existing techniques, presents the detailed solution
   and its advantages, supplies JSON Schema definitions for core
   protected objects, and includes an industry-relevance section.
   Related Indian provisional applications and PCT filings appear in the
   final appendix.

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-agentic-ai-tool-execution-finality/

There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-agentic-ai-tool-execution-finality-00.html

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts


_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.