Published September 21, 2026 | Version v1

Agentic Effectuation Boundary and Execution-Finality Architecture

Authors/Creators

Description

Abstract

As autonomous AI agents increasingly receive delegated authority to execute API mutations, settle financial payments, manage critical power grids, control robotic systems, and modify enterprise infrastructure, existing security architectures reveal a critical effectuation-boundary gap. Prevailing mechanisms—such as OAuth 2.0 delegation, Rich Authorization Requests (RAR), sender-constrained DPoP keys, transaction tokens, and RATS remote attestation—focus primarily on access permissions, key possession, token propagation, and execution-environment trustworthiness. However, these building blocks do not verify whether the exact consequential operation remains authorized at the specific commit instant.

An approved operation can become unsafe between planning and execution due to parameter substitution, stale external prerequisites, delegation expansion, policy epoch advances, replay races, or unmediated alternate-path bypasses. This specification defines an execution-finality architecture that addresses this vulnerability.

Under this framework, a proposed Candidate Act remains held in a strictly Non-Effective State. A protected enforcement point generates an act-bound Execution Handle cryptographically tied to the canonical parameters, policy epochs, anti-replay nonces, and the intended consequence boundary. Mediation terminates at a mandatory Finality Sink—such as a payment adapter, industrial interlock, motion-command gate, or database commit boundary—which independently reconstructs the live act, revalidates mutable dependencies, ensures path completeness, and executes an atomic check-and-consume commit. Missing or unverifiable lineage is treated as UNKNOWN and fails closed. Across diverse domains, the architecture guarantees that autonomous computation, valid credentials, and platform attestation alone do not constitute authority for irreversible physical or systemic consequence.

FLOW CHART

  [ Autonomous Model / Agent Workspace ]
                     │
                     │ Proposes exact Candidate Act
                     ▼
        ┌─────────────────────────┐
        │   Non-Effective State   │ ◄── Strictly held from effect
        └────────────┬────────────┘
                     │
                     │ Protected validation (Identity, RAR, RATS, Policy)
                     ▼
        ┌─────────────────────────┐
        │    Execution Handle     │ ──► [ Act Digest + Nonce + Epoch + Sink ID ]
        └────────────┬────────────┘
                     │
                     │ Evaluated at boundary
                     ▼
        ┌─────────────────────────┐
        │      FINALITY SINK      │ ◄── Reconstructs live act parameters
        │ (Command / Commit Gate) │
        └────────────┬────────────┘
                     │
           [ Atomic Check-and-Commit ]
                     │
         ┌───────────┴───────────┐
   Pass  │                       │ Fail / Stale / Unknown
         ▼                       ▼
  ┌──────────────┐        ┌──────────────┐
  │ IRREVERSIBLE │        │ FAIL-CLOSED  │
  │ EFFECTUATION │        │   (BLOCK)    │
  └──────────────┘        └──────────────┘

Series information

References 

Primary Specification

  • draft-das-agentic-effectuation-boundary-00: Das, S., "When AI Agents Hold the Keys: Threat Model and Execution-Finality Requirements for Autonomous High-Consequence Systems", Internet-Draft, Individual Submission, September 19, 2026.

Standards & RFC References

  • RFC 8705: Campbell, B., Bradley, J., Sakimura, N., and T. Lodderstedt, "OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens", RFC 8705, February 2020.

  • RFC 9110: Fielding, R., Nottingham, M., and J. Reschke, "HTTP Semantics", RFC 9110, June 2022.

  • RFC 9334: Birkholz, H., Thaler, D., Richardson, M., Smith, N., and W. Pan, "Remote ATtestation procedureS (RATS) Architecture", RFC 9334, January 2023.

  • RFC 9396: Lodderstedt, T., Richer, J., and B. Campbell, "OAuth 2.0 Rich Authorization Requests", RFC 9396, May 2023.

  • RFC 9449: Fett, D., Campbell, B., Bradley, J., Lodderstedt, T., Jones, M., and D. Waite, "OAuth 2.0 Demonstrating Proof of Possession (DPoP)", RFC 9449, September 2023.

  • RFC 9700: Lodderstedt, T., Bradley, J., Labunets, A., and D. Fett, "Best Current Practice for OAuth 2.0 Security", RFC 9700, January 2025.

  • RFC 9711: Lundblade, L., Mandyam, G., O'Donoghue, J., and C. Wallace, "The Entity Attestation Token (EAT)", RFC 9711, April 2025.

  • draft-ietf-oauth-transaction-tokens: Tulshibagwale, A., Fletcher, G., and P. Kasselman, "Transaction Tokens", Work in Progress, draft-ietf-oauth-transaction-tokens-11, July 2026.

Public Disclosures and Repositories

Industry Platform References

Files

Full-Technical Disclosure -draft-das-agentic-effectuation-boundary-00.xml