Operational Identity: A Finite Audit of Declared and Implemented Rules of Sameness
arXiv:2607. 20729v1 Announce Type: cross Abstract: A record system declares when two records refer to the same entity, occurrence, scope, or rule.
arXiv:2601. 16152v2 Announce Type: replace-cross Abstract: Data systems increasingly operate under persistent legal, political, and analytic disagreement, where no single interpretive authority can be assumed.
arXiv:2607. 20729v1 Announce Type: cross Abstract: A record system declares when two records refer to the same entity, occurrence, scope, or rule.
arXiv:2601. 14271v2 Announce Type: replace Abstract: Shared accountability records are often used by parties who may never agree about causation, responsibility, or normative interpretation.
The paper proposes a tiered, reusable identity assurance model that separates assurance state from capability gates, allowing participants to disclose only what is necessary for each act. It introduces a typed entity taxonomy, a two‑axis coordinate system for assertion scope and source, and a time‑indexed jurisdiction attribute, with reliance recorded in bitemporal snapshots. The design is evaluated against existing flat‑verification and per‑credential models, addressing cross‑border reuse and data‑erasure versus evidentiary retention concerns.
arXiv:2605. 23922v2 Announce Type: replace-cross Abstract: The EU Artificial Intelligence Act (AIA) establishes a lifecycle governance regime for high-risk AI systems built around ex-ante conformity assessment, post-market monitoring, and re-assessment upon "substantial modification.
arXiv:2609.22961v1 Announce Type: cross Abstract: Agentic systems increasingly invoke tools, services, data, and other agents across organizational boundaries, yet a relying party cannot assess a del...
arXiv:2608. 10601v1 Announce Type: cross Abstract: Two instruments of EU digital law place inference at their centre and mean different things by it.
The paper introduces a claim‑anchored execution contract that binds a tool‑using agent’s emitted claim to its exact source span, the ordered execution prefix that produced it, and the source version and access state observed. Each receipt contains deterministic anchors, source identifiers, offsets, hashes, quotes, and a domain‑separated execution commitment, allowing a verifier to reconstruct these bindings before semantic or task labels are joined. The contract defines seven independently testable properties and demonstrates high detection rates against cross‑object attacks, with strong performance on conflict‑aware support guard evaluations.
The paper introduces Persona‑Execution Separation (PES), an architecture pattern that splits an LLM agent’s persona—its instructions, tone, and self‑presentation—from its execution—stateful, auditable work—by placing them in distinct trust domains linked through a governed contract bridge. PES allows the persona to evolve freely while keeping execution traceable, using mechanisms such as an approval matrix, data‑loss‑prevention exceptions, and continuous identity. A pilot implementation on a regulated digital‑employee platform demonstrated that PES successfully decouples persona drift from execution audit, preventing re‑validation or fingerprinting of hard‑asserted fields.
arXiv:2606. 12320v1 Announce Type: new Abstract: Enterprise security was built to govern data boundaries: the protected surface was data at rest and in transit, and the controls -- access control, data-loss prevention, perimeter inspection -- governed crossings of that boundary.
arXiv:2607. 00220v1 Announce Type: cross Abstract: Artificial intelligence (AI) systems are routinely modified after deployment through retraining and changes in their environments.
The paper investigates how multiple pre‑action controls—authority, resource, and evidence gates—interact in agentic AI systems. It formalizes remediation‑induced control coupling, showing that remediation can invalidate earlier judgments and that the order of remediation matters. The authors propose a remediate‑and‑regate protocol to restore soundness, analyze non‑commuting remediation operators, and demonstrate the approach on a deterministic open‑data artifact with three published engines.
The paper presents a framework for causal attribution in agentic AI systems, outlining estimators and conditions where they fail. It distinguishes between marginal total effects and common‑random‑number total effects, introduces a natural direct effect under pinned downstreams, and derives a coupling method to keep direct effects estimable. The authors also propose a traceability specification to meet upcoming regulatory requirements for high‑risk AI systems.