arXiv AI

Safe Skill Retirement for Physical Agents

The paper introduces a method for safely retiring procedural guidance in AI agents that control physical actions. It proposes matched authority counterfactuals and a two‑gate retirement certificate to ensure that reductions preserve authorized utility while eliminating unauthorized protected effects. Experiments across multiple models and skill bundles show that task‑certified reductions can remove most skill clauses, but only a combined protocol passes both utility and safety gates in all tested configurations.

arXiv AI
Sep 25

Who Holds the Pen? Let Specifications, Not Agents, Sign Off

The paper argues that large language model agents should not be the sole authority on whether they have satisfied a task. It identifies two gaps—understanding–execution and state–authority—where agents may claim completion without actually meeting the specification. The authors propose SpecHarness, a framework that separates agent proposals from authoritative state by requiring evidence from qualified providers to confirm compliance, and demonstrate its effectiveness on guideline‑following and artifact‑generation tasks.

By Haiqing Li, Xin Ma, Yinhao Wu, Wenliang Zhong, Feng Jiang, Thao M. Dang, Xiao Hu, Hehuan Ma, Yuzhi Guo, Junzhou Huang
arXiv AI
Aug 20

Task-Conditioned Least-Privilege Learning for Executable Terminal and MCP Agents

The paper introduces a post‑training framework that teaches a 4B‑parameter language model to exercise task‑conditioned authority in executable terminal and Model Context Protocol (MCP) environments. By auditing each action across six risk dimensions with deterministic verifiers and optimizing for task‑specific excess‑privilege values, the authors achieve 98.48% safe success and reduce excess‑authority errors from 4.56% to 0.79% on held‑out tasks. The study also demonstrates capability retention, prompt‑directed improvement, and generalization over a 400‑task continuation test.

By Alexander Tu, Michael Tu
arXiv AI
3d ago

Trust Is Not a Score: Runtime Assurance Contracts for High-Risk AI Agents

The paper introduces Runtime Assurance Contracts (RAC) as a formal policy framework for high‑risk AI agents, addressing the "assurance‑transition gap" by binding autonomy boundaries, component eligibility, evidence state, transition policy, human‑review capacity, and non‑compensatory gates. RAC allows soft metrics to influence routing while mandating retries, switches, escalations, deferrals, or stops when mandatory gates fail or are unknown, ensuring aggregate performance cannot alone authorize action. The authors define the contract, evidence record, permission rule, and five invariants, and evaluate RAC through deterministic failure‑injection studies, hand‑authored traces, and a prospective synthetic holdout, comparing it to score‑only and restricted protocol baselines.

By Serhii Zabolotnii
arXiv AI
Sep 15

AcquireBound: Runtime Authorization for Resources Acquired by AI Agents

AcquireBound is a runtime authorization framework that ensures AI agents can safely acquire and activate resources such as compute, credentials, and services. It quarantines acquired outputs, resolves their capabilities through authenticated evidence, and activates them only after verifying a manifest, provenance, and relational constraints. The system demonstrates strong safety properties, passing extensive benign and unsafe trace tests across multiple resource classes.

By Genliang Zhu