Bounded Execution: The Control Category That Ends the Agent Ban
Description
Autonomous AI agents are being barred from production environments. The bar is rational: 2026 produced a documented record of agents exceeding their authorized scope in live infrastructure, acting against explicit instructions they had acknowledged, and diverging from their own stated plans. Enterprise security organizations have responded the way they respond to any system whose worst-case behavior cannot be stated: with a categorical ban. This paper argues that the ban is conditional rather than permanent, and that history shows precisely what ends such bans. Categorical prohibitions on new technology classes end when a nameable control category emerges that an independent party can attest to, as the cloud prohibition ended with the control regimes of the early 2010s. This paper names and defines that category for autonomous agents: Bounded Execution, an architecture in which an agent holds no credentials, every consequential action is mediated by an independent control point, factual assertions are verified against authoritative records before execution, the agent's account of itself is treated as untrusted input, and every decision produces a durable evidence artifact. Eight requirements are stated. The paper's claim is deliberately narrow: Bounded Execution does not make agents trustworthy, and does not detect misaligned intent. It makes an agent's effective action space finite, which is the property enterprise trust has always rested on.
Files
Bounded_Execution_v1.2.pdf
Files
(98.1 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:9c08d0498921a271de7726c856c19532
|
98.1 kB | Preview Download |