arXiv AI By Sourena Khanzadeh, Daniel Platnick, Marjan Alirezaie, Hossein Rahnama

Share No More Than the Request Requires: Federated Disclosure for Perspective-Aware AI

Read the original on arXiv AI →

arXiv:2607. 22953v1 Announce Type: new Abstract: Modern AI systems bring societal risks such as mass surveillance, extreme concentrations of power, and loss of user autonomy---calling into question a model where third-parties collect and control massive amounts of user data.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv AI.

arXiv AI
Jun 19

Deontic Policies for Runtime Governance of Agentic AI Systems

arXiv:2606. 19464v1 Announce Type: new Abstract: Autonomous agentic AI systems driven by Large Language Models (LLMs) introduce a new class of security, privacy, and compliance challenges: an agent that can invoke tools, manipulate data, install software, and coordinate with peer agents across organizational boundaries must be constrained not just by authentication and access control, but by the full structure of enterprise governance.

By Anupam Joshi, Tim Finin, Karuna Pande Joshi, Lalana Kagal
arXiv AI
2d ago

Multi-Jurisdictional Legal Identity Assurance for Capability Gating: A Design-Science Proposal for Tiered, Reusable Identity Assurance of Natural, Juridical, and Machine Entities

The paper proposes a tiered, reusable identity assurance model that separates assurance state from capability gates, allowing participants to disclose only what is necessary for each act. It introduces a typed entity taxonomy, a two‑axis coordinate system for assertion scope and source, and a time‑indexed jurisdiction attribute, with reliance recorded in bitemporal snapshots. The design is evaluated against existing flat‑verification and per‑credential models, addressing cross‑border reuse and data‑erasure versus evidentiary retention concerns.

By Walter Kurz
arXiv AI
Aug 17

Mandato: Protocol-Level Enforcement of Digitally Signed Mandates on AI Agent Actions with Cryptographically Chained Audit Trails

arXiv:2608. 14074v1 Announce Type: new Abstract: AI agents increasingly act on external systems through standardized tool-calling protocols such as the Model Context Protocol (MCP), yet no infrastructure layer constrains their actions to what a principal has verifiably authorized: authorization logic lives in application code, is neither signed nor independently auditable, and the resulting logs lack evidentiary value.

By Giovanni Racioppi
arXiv AI
Sep 2

Delegation Without Trust: An Empirical Gap Analysis of Identity, Authorization, and Runtime Governance in Multi-Agent LLM Systems

The paper examines the security challenges of delegating authority to autonomous LLM agents that act on users’ behalf. It introduces a threat model with four adversaries and eight security requirements, demonstrates that current frameworks (LangGraph, CrewAI, AutoGen, MCP) fail to meet these standards, and presents an authorization broker that blocks all identified threats with minimal overhead. The broker is shown to resist numerous attacks and limits compromised sub‑agents to their delegated tasks, and its principles are implemented in VotalAI’s LLM Shield.

By Panduranga Sai Varma Dantuluri, Jyotirmoy Sundi