Published January 28, 2026 | Version 1.0
Publication Open

On Earned Autonomy - Delegating Network-Lethal Authority to Machines

Authors/Creators

Description

Autonomous defensive capabilities exist - EDR/XDR platforms, SOAR systems, and cloud security services already block known threats without human intervention. The gap is not capability but legitimacy: no framework exists for delegating authority to machines for novel threats that fall outside existing signatures and playbooks.

This paper introduces earned autonomy, a governance framework for delegating defensive authority to machines. Authority is granted not by vendor assertion or blind trust, but through demonstrated competence on real traffic, under real conditions, with continuous validation. We present IBSR (Inline Block Simulation Report) and Guard as a reference implementation: IBSR produces judgment through rehearsal on live traffic, Guard executes blocking at kernel level, and the separation ensures autonomous action is never taken without prior evidence of competence.

Files

earned_autonomy.pdf

Files (172.5 kB)

Name Size Download all
md5:b3b10c352c9b2b1402d988f32ba281b5
172.5 kB Preview Download

Additional details

Software

Repository URL
https://github.com/NullRabbitLabs/nr-ibsr/
Programming language
Rust
Development Status
Concept