Research Index

AOI Runtime Governance Evidence Map

A continuously maintained index of primary research, technical architectures, standards, market developments, and adjacent work contributing to the emerging discipline of Runtime Governance.

The map catalogs supporting, overlapping, adjacent, and challenging work. Inclusion does not imply endorsement.

The Evidence Map describes the state of the literature, not the state of AO Integrity.

Schema v744 sources9 claims

Corpus facts

Derived from stored corpus records.

44

Total sources

35

Primary sources

0 external contributions recorded.

Classification metrics

Counts depend on AOI's current taxonomy.

25

Overlap flagged

23

Challenge or complicate

Claim Map

Stored claims and source relationships.

Coverage statements are rendered exactly as stored in the Schema v7 corpus.

ClaimLabelTypeCoverageSources
EL

Execution Legitimacy

Whether a specific execution remains a legitimate exercise of conferred authority at the moment it occurs. The five conditions operationalize this determination.

determinationFourteen sources. Three added 2026-08-03, all as support or complement rather than competition: aviation dispatch release as a two-party determination made against current conditions, financial settlement finality as an ex ante determinate irrevocability point, and certificate-bound admission as a conditional-execution model. Support remains strongest from outside AI. Competing treatments continue to address individual conditions rather than the integrated five.
RA

Runtime Admissibility

The determination of whether execution should proceed right now. Not whether memory, data, context, or a consequence is admissible — those may be inputs or subordinate questions, but RA governs execution.

gateTwenty-one sources. Six added 2026-08-03. The certificate-bound admission and execution pair (arXiv 2606.11632, 2606.20520) is the corpus's first two-paper treatment separating proposal, admission, and execution with a signed artifact carried between them, with prototype measurements on AWS and Kubernetes. Foundational support continues to come from runtime verification and monitorability literature, now joined by financial settlement-finality standards on the ex ante determinacy of the irrevocability point. No enterprise-scale operational case study found.
AC

Authority Continuity

The preservation of valid, correctly scoped, and traceable authority across identity, delegation, context, and execution as conditions change over time. Broader than delegation-chain correctness: includes whether authority remains legitimate through the interval between grant and effect.

continuityTwenty sources. Four added 2026-08-03. arXiv 2607.23586 addresses grant survival under agent mutation under the name authorization continuity, with a fixed transition envelope and effect ceiling; arXiv 2606.20520 revalidates against live state at execution rather than at grant. Aviation dispatch regulation (14 CFR 121.533 and 121.663) supplies a long-standing regulatory analogue in which release authority is joint, continuously revisited between release and completion, and non-delegable at the dispatch level. Catalogued treatments continue to address subsets of the claim: agent mutation, infrastructure state, or delegation structure, rather than authority across identity, delegation, organizational context, and execution together. Delegation chains remain structurally representable without non-widening enforced by construction in any deployed standard.
AD

Authority Drift

The divergence, over time, between authority a system retains and the authority current organizational circumstances would justify. Not privilege accumulation — a technically correct entitlement may still be illegitimate in current context.

failureThree sources, unchanged this week. No competing treatments found, and none of the seven sources added 2026-08-03 competes with the canonical definition. arXiv 2606.20520 checks live-state drift at execution against a certified contract, but that comparison is infrastructure state against a contract rather than retained authority against current organizational circumstances, and it was not tagged AD. No standardized business-state event vocabulary exists. No unit of measure, continuous formulation, or threshold located in any source. AD remains the thinnest claim in the corpus by competing coverage and an open search lane.
CD

Capability Drift

Change in an autonomous system's effective ability to produce consequences without a corresponding reevaluation of the authority governing those capabilities. Arises through learned skills, tool composition, memory, model updates, reusable behaviors, delegation, or environmental change.

failureThree sources, up from one. Two added 2026-08-03 substantively address capability evolution rather than state persistence: a state-bound authorization model that fixes an immutable effect ceiling at grant time and proves that mutation cannot amplify protected effects beyond it, where the mutations enumerated include acquiring skills and tools, revising workflows, and delegating work (arXiv 2607.23586); and a lifecycle-time upgrade governance pipeline with interface, policy, behavioral, and recovery compatibility checks, gated activation, shadow deployment, online monitoring, and rollback, measured on an embodied-agent testbed (arXiv 2604.08059). Both report formal or quantitative results; neither uses the term Capability Drift. A third source added this week, arXiv 2605.26542, is catalogued under AC and RA rather than CD: it governs authority attenuation across a composed tool chain within a session, which is adjacent compositional attenuation rather than change over time in effective ability to produce consequences. Still absent from the record: any enterprise deployment case study, any continuous measure or threshold for capability change, and any treatment tying capability change to organizational rather than technical authority.
GE

Governance Evidence

Independently reviewable evidence showing what legitimacy determination was made, which authority and contextual signals informed it, and why the execution was permitted, denied, escalated, or attested. Logs may contribute evidence; event records alone do not establish governance reasoning.

evidenceThirteen sources. Three added 2026-08-03. Signed decision and outcome records bound to a certified execution contract (arXiv 2606.20520) and evidence-digest binding at admission (arXiv 2606.11632) extend the catalogued set of cryptographically bound evidence models. The signed dispatch release under 14 CFR 121.663 is the corpus's first regulatory instance of a governance artifact that two named parties must both sign before an operation may begin. Regulatory demand remains documented with no finalized technical standard.
OBJ

Evaluation Object

The composite execution event: principal, delegation chain, agent, action, target, context, intent, and provenance relevant to a specific execution. Treated as an adopted and refined architecture choice, not a novelty claim.

designNine sources. One added 2026-08-03: arXiv 2606.11632 compiles agent proposals into typed execution contracts bound to evidence digests and policy versions, adding a fifth independent 2026 work locating governance at an execution, admission, or bind boundary.
PE

Policy vs Enforcement

The distinction between governance that is declared and governance that is operationally established in the execution path. A supporting claim, not AOI-originated.

supportingWell covered externally. Primary source is Cavallo's described-versus-established framing; supported by practitioner and distributed-systems material.
MKT

Market Conditions

External technical, regulatory, operational, and commercial developments that increase the need for Runtime Governance but do not themselves establish its architecture.

contextAmple. NHI ratios, over-permissioning rates, IAM capability gaps, and regulatory timelines all documented from multiple sources.

Showing 19 of 44 sources.

Clear filters

e001

Runtime Governance for AI Agents: Policies on Paths

Permalink
Source
arXiv 2603.16586
Source type
research
Primary or secondary status
Primary
Domain
Runtime
Published
2026-03-17
Claims
OBJ, RA
Conditions
OBJ
Stance
complicates
Relation
differentiates
Strength
supporting
Overlap flag
prior_art

Argues the execution path is the central object for runtime governance and formalizes compliance policy as a deterministic function mapping agent identity, partial path, proposed next action, and organizational state to a violation probability. Claims prompt-level instructions and static access control are special cases of this framework. Policy examples drawn from the AI Act; reference implementation discussed. Bears on OBJ and RA.

Original link

e002

Decision Evidence Maturity Model for Agentic AI: A Property-Level Method Specification

Permalink
Source
arXiv 2605.04093
Source type
research
Primary or secondary status
Primary
Domain
Evidence
Published
2026-05
Claims
GE
Conditions
EV
Stance
complicates
Relation
differentiates
Strength
supporting
Overlap flag
prior_art

Five-level evidence sufficiency rubric plus the named 'container fallacy' — equating evidence-container presence with audit sufficiency. Directly parallels the E0-E4 scale and the Section 4.4 warning about describing an E0 control as fully audited.

Original link

e003

DEMM-Bench: A Cross-Regime Benchmark for Agent-Runtime Governance-Evidence Sufficiency

Permalink
Source
arXiv 2606.20634
Source type
research
Primary or secondary status
Primary
Domain
Evidence
Published
2026-06
Claims
GE
Conditions
EV
Stance
complicates
Relation
complements
Strength
emerging
Overlap flag
naming_collision

Benchmark accompanying the Decision Evidence Maturity Model. Uses 'agent-runtime governance-evidence' as a compound term. Provides executable categories for classifying evidence sufficiency, making the property measurable rather than asserted. Bears on GE and on the metrics discussion in Section 6.6.

Original link

e005

Intent-Governed Tool Authorization for AI Agents

Permalink
Source
arXiv 2606.22916
Source type
research
Primary or secondary status
Primary
Domain
Policy
Published
2026-06
Claims
EL
Conditions
3.4
Stance
complicates
Relation
differentiates
Strength
supporting
Overlap flag
absorption

Argues a tool call can be authorized by static credentials and still be unjustified by the user's current request — export authority should not be exposed when a bounded summary was asked for. This is Intent Conformance being attacked directly. Contradicts the Appendix A claim that intent conformance remains outside the stated scope of current proposals.

Original link

e006

Verifiable Agent Protocol (VAP): Intent-Bound Admission Control and Audit for Agent Tool Invocation

Permalink
Source
IETF draft-samal-vap-00
Source type
standard
Primary or secondary status
Primary
Domain
Policy
Published
2026
Claims
EL, GE
Conditions
3.4, EV
Stance
complicates
Relation
differentiates
Strength
emerging
Overlap flag
absorption

Individual Internet-Draft binding declared intent to admission control and audit at the point of tool invocation. Not a working group document as of cataloging. Addresses the same evaluation moment as Runtime Admissibility. Bears on condition 3.4 and on GE.

Original link

e012

OpenID Connect Agent Identity Claims for Autonomous AI Agents

Permalink
Source
IETF draft-sharif-openid-agent-identity-00
Source type
standard
Primary or secondary status
Primary
Domain
Identity
Published
2026-03-26
Claims
AC
Conditions
3.1, 3.2
Stance
complicates
Relation
complements
Strength
emerging
Overlap flag
absorption

Profile of OIDC Core enabling IdPs to issue identity tokens for autonomous agents. Strengthens coverage of conditions 3.1 and 3.2, narrowing the thesis to 3.3-3.5 as intended by Section 3.7.

Original link

e018

Agent Control Protocol (ACP): Admission Control for Agent Actions

Permalink
Source
arXiv 2603.18829
Source type
research
Primary or secondary status
Primary
Domain
Runtime
Published
2026-03
Claims
RA, OBJ
Conditions
OBJ, 3.4
Stance
complicates
Relation
differentiates
Strength
supporting
Overlap flag
prior_art

Technical specification and reference implementation for admission control at the agent action boundary. Same inline-enforcement pattern as Section 5.1, with a concrete protocol. Relevant to the Section 5.5 concession that the discipline may be implemented inside existing machinery.

Original link

e019

Proof of Execution: Runtime Verification for Governed AI Agent Actions

Permalink
Source
arXiv 2607.05397 (Rhodes & Kang)
Source type
research
Primary or secondary status
Primary
Domain
Verification
Published
2026-04-26
Claims
GE, RA, OBJ, PE
Conditions
EV, OBJ, 3.2
Stance
complicates
Relation
differentiates
Strength
supporting
Overlap flag
prior_art

Formalizes execution as a triple (contract C, Execution Causal Event Stream T, replay context R) with five validator-checkable invariants and five semantic guarantees: authorization, path compliance, null effect on deny, history integrity, replayability. Includes soundness and replay theorems with witness constructions. Overlaps AOI on execution as evaluation object, deterministic inline enforcement, null effect after denial, integrity and replayability, and independently checkable execution history. Does not evaluate contextual validity, intent conformance, or causal origin; establishes that execution followed a valid contract and path rather than whether the execution was institutionally legitimate.

Original link

e020

Governing Actions, Not Agents: Institutional Attestation as a Governance Model for Autonomous AI Systems

Permalink
Source
arXiv 2606.26298 (Salfeld-Nebgen)
Source type
research
Primary or secondary status
Primary
Domain
Evidence
Published
2026-06-24
Claims
OBJ, GE, EL
Conditions
OBJ, EV, 3.4
Stance
complicates
Relation
differentiates
Strength
supporting
Overlap flag
prior_art

Observes that human institutions have governed autonomous actors by requiring independently attested evidence at the point of consequential action rather than by monitoring reasoning. Agent retains planning and reasoning autonomy but holds no execution authority over designated high-risk actions. Execution is conditional on preconditions each independently attested by a separate authoritative source, cryptographically bound to a declared intent, evaluated by deterministic policy, and recorded in a tamper-evident log amenable to independent re-verification. Examples from software deployment and clinical prescribing; proof-of-concept on GitHub. Bears on OBJ, GE, and condition 3.4.

Original link

e028

Toward cryptographically verifiable authorization for autonomous AI agents

Permalink
Source
arXiv 2607.21325
Source type
research
Primary or secondary status
Primary
Domain
Identity
Published
2026-07
Claims
AC, GE
Conditions
3.2, EV
Stance
complicates
Relation
differentiates
Strength
emerging
Overlap flag
absorption

Security hypothesis, preliminary formal model, and proof-of-concept implementation for cryptographically verifiable authorization of autonomous agents. Early-stage single-source work. Bears on condition 3.2 and on GE.

Original link

e031

AgentBound: Verifiable Behavioral Governance for Autonomous AI Agents

Permalink
Source
arXiv 2606.30970
Source type
research
Primary or secondary status
Primary
Domain
Evidence
Published
2026-06
Claims
GE, AC, RA
Conditions
EV, 3.1, 3.2
Stance
complicates
Relation
differentiates
Strength
supporting
Overlap flag
prior_art

Introduces cryptographically verifiable governance receipts binding each executed action to its exact governing policy artifacts, enabling non-repudiable independent replay verification. Composes three independent authorities in parallel: delegated authorization, owner-signed behavioral constitutions, and site action contracts. Introduces a standing delegation model, per-execution policy refreshing, and deterministic obligation enforcement, accommodating both interactive and long-running periodic agents. Bears on GE, AC, and RA.

Original link

e032

Reconstructive Authority Model: Runtime Execution Validity Under Partial Observability

Permalink
Source
arXiv 2604.22898
Source type
research
Primary or secondary status
Primary
Domain
Verification
Published
2026-04
Claims
AC, RA, EL
Conditions
3.1, 3.2, 3.3
Stance
complicates
Relation
differentiates
Strength
supporting
Overlap flag
prior_art

Treats authority as reconstructed at execution rather than carried forward from grant, addressing runtime execution validity under partial observability. Companion to e033. Bears on AC, RA, and conditions 3.1 through 3.3.

Original link

e033

Operationalizing Reconstructive Authority: Runtime Construction, Dependency Resolution, and Execution Gating in Autonomous Agent Systems

Permalink
Source
arXiv 2605.23935
Source type
research
Primary or secondary status
Primary
Domain
Runtime
Published
2026-05
Claims
RA, AC
Conditions
3.1, 3.2
Stance
complicates
Relation
differentiates
Strength
supporting
Overlap flag
prior_art

Operationalizes the reconstructive authority model through runtime construction, dependency resolution, and execution gating in autonomous agent systems. Execution gating addresses the same decision point as Runtime Admissibility, with a dependency-resolution mechanism. Companion to e032.

Original link

e035

Harnessing Embodied Agents: Runtime Governance for Policy-Constrained Execution

Permalink
Source
arXiv 2604.07833
Source type
research
Primary or secondary status
Primary
Domain
Robotics
Published
2026-04
Claims
RA, OBJ
Conditions
OBJ
Stance
complicates
Relation
differentiates
Strength
supporting
Overlap flag
naming_collision

Robotics application of the term runtime governance. Separates agent cognition from execution oversight by externalizing governance into a dedicated runtime layer performing policy checking, capability admission, execution monitoring, rollback handling, and human override. Capability admission and rollback handling bear on CD and on the reversibility material in Section 5.3.

Original link

e038

Are You Still the Agent I Authorized? Earned Authority under a Fixed Ceiling for Evolving Agents

Permalink
Source
arXiv 2607.23586
Source type
research
Primary or secondary status
Primary
Domain
Verification
Published
2026-07
Claims
CD, AC, RA
Conditions
3.1, 3.2, 3.3
Stance
complicates
Relation
differentiates
Strength
supporting
Overlap flag
prior_art

Formulates what it calls authorization continuity: whether an existing grant remains valid as a long-lived agent evolves after deployment by retaining experience, acquiring skills and tools, revising workflows, delegating work, and moving across task phases. States that evolution can change both the effects reachable under an old grant and the authority a task requires, and that the required authority may rise, fall, or become incomparable; existing tool policies constrain actions but do not determine when a grant survives this change. Proposes a state-bound model that fixes a transition envelope and an immutable effect ceiling at grant time, distinguishes requested from realized effects, and proves that under complete mediation, sound effect abstraction, attenuating delegation, and monitor integrity, mutation cannot amplify protected effects beyond the user-issued ceiling; agent-produced evidence may allocate authority below the ceiling but cannot raise it, which places the derivation of any additional authority under an evidence condition and bears on condition 3.2. The source's authorization continuity is scoped to grant survival under agent mutation. Vocabulary in use that overlaps AOI's: authorization continuity, authorization drift, admission, effect ceiling. Bears on CD, AC, and conditions 3.1 through 3.3.

Original link

e039

ChainCaps: Composition-Safe Tool-Using Agents via Monotonic Capability Attenuation

Permalink
Source
arXiv 2605.26542 (Jiang et al.; AIWILD workshop, ICML 2026)
Source type
research
Primary or secondary status
Primary
Domain
Runtime
Published
2026-05
Claims
AC, RA
Conditions
3.3, 3.5
Stance
complicates
Relation
complements
Strength
supporting
Overlap flag
prior_art

Names permission laundering: an agent can satisfy every per-tool permission check and still produce an unsafe end-to-end effect, because a restricted value is transformed, mixed, or rewritten before reaching a sink it should not reach. Enforces a runtime invariant in which every value carries a sink-specific authority budget and tool composition propagates budgets by intersection, so a value may lose but never gain authority through composition; states and proves a non-amplification theorem to that effect. Implemented as a transparent MCP proxy requiring no change to agent or tool servers; reports attack success falling from 25-68 percent to 0-4.8 percent across five frontier models on an 82-task suite, with manifest authoring quality, not runtime overhead, identified as the binding deployment constraint. The mechanism governs authority attenuation across a composed tool chain within a session rather than change in an agent's effective ability to produce consequences over time. The paper positions itself as complementary to execution-boundary mechanisms, which it says constrain execution while ChainCaps constrains the authority of derived values. Vocabulary in use that overlaps AOI's: monotonic capability attenuation, authority propagation, declassification. Bears on AC, RA, condition 3.5, and the compositional material in Appendix C.4.

Original link

e040

Governed Capability Evolution: Lifecycle-Time Compatibility Checking and Rollback for AI-Component-Based Systems, with Embodied Agents as Case Study

Permalink
Source
arXiv 2604.08059
Source type
research
Primary or secondary status
Primary
Domain
Robotics
Published
2026-04
Claims
CD, RA
Conditions
3.1
Stance
complicates
Relation
complements
Strength
supporting
Overlap flag
naming_collision

Formulates governed capability evolution as a software-lifecycle problem: when a capability module evolves into a new version, the hosting system must decide whether the new version may be activated, under what deployment conditions it runs, how it is monitored, and when it is rolled back. Introduces four upgrade compatibility checks (interface, policy, behavioral, recovery) staged into a pipeline of candidate validation, sandbox evaluation, shadow deployment, gated activation, online monitoring, and rollback. Reports that naive upgrade reaches 72.9 percent task success but drives unsafe activation to 60 percent by the final round, while governed upgrade retains 67.4 percent success with zero unsafe activations, and that shadow deployment reveals 40 percent of upgrade regressions invisible to sandbox evaluation alone. States its contribution as extending runtime governance from action execution to capability evolution; the checks are lifecycle-time and pre-activation rather than per-execution. The source's terms are governed capability evolution and runtime governance; it does not use the term Capability Drift. Bears on CD and on the reversibility material in Section 5.3.

Original link

e041

Sovereign Assurance Boundary: Certificate-Bound Admission for Agentic Infrastructure

Permalink
Source
arXiv 2606.11632
Source type
research
Primary or secondary status
Primary
Domain
Runtime
Published
2026-06
Claims
RA, GE, OBJ, EL
Conditions
3.1, 3.2, 3.4, 3.5
Stance
complicates
Relation
differentiates
Strength
supporting
Overlap flag
prior_art

States a control-plane authorization problem: non-deterministic reasoning systems may propose high-stakes mutations to production resources, while IAM, policy engines, consensus protocols, and audit logs either enforce static permissions or record actions only after execution. Introduces a certificate-bound runtime admission boundary that intercepts agent proposals at an assurance airlock, compiles them into typed execution contracts, binds those contracts to cryptographic evidence digests and policy versions, and routes them through consequence-aware certification paths; successful admission emits a signed certificate valid only for a scoped execution identity, revocation epoch, and validity window. The contract-to-certificate-to-execution chain constrains which execution path may follow from a given admitted proposal, which bears on condition 3.5. Formalizes admission and revocation invariants and reports feasibility measurements from a Go prototype over 2,500 admission attempts. Vocabulary in use that overlaps AOI's: runtime admission boundary, execution contract, evidence-bound, consequence-aware certification, replayable. Companion to e042. Bears on RA, GE, OBJ, and conditions 3.1, 3.2, 3.4, and 3.5.

Original link

e042

Sovereign Execution Broker: Enforcing Certificate-Bound Authority in Agentic Control Planes

Permalink
Source
arXiv 2606.20520
Source type
research
Primary or secondary status
Primary
Domain
Runtime
Published
2026-06-19
Claims
RA, AC, GE
Conditions
3.1, 3.3
Stance
complicates
Relation
differentiates
Strength
supporting
Overlap flag
prior_art

Execution-side companion to e041. Defines a runtime enforcement boundary that consumes certificates issued by the assurance boundary, verifies that the requested mutation matches the certified execution contract, checks validity windows, policy epochs, revocation epochs, and live-state drift, mints a scoped execution identity, invokes infrastructure APIs, and records signed decision and outcome records. States that production mutation authority should not reside inside non-deterministic reasoning processes, and separates proposal, admission, and execution so that certified authority becomes a short-lived, revocable, auditable runtime capability. Prototype evaluated on AWS and Kubernetes clusters. The live-state drift check compares infrastructure state at execution against the certified contract; it is not a comparison of retained authority against current organizational circumstances, and the entry is therefore not tagged AD. Vocabulary in use that overlaps AOI's: certificate-bound authority, execution broker, live-state drift, signed decision records, revocation epoch. Bears on RA, AC, GE, and the grant-to-effect interval.

Original link

Methodology

How to read this map.

AO Integrity maintains the corpus and performs the classifications. Classification is interpretive. Total, primary, and externally contributed counts are corpus facts. Other metrics depend on the current taxonomy. Records can be corrected or withdrawn. Stable evidence IDs are never renumbered or reused. Withdrawn records remain addressable.

Contribution

What are we missing?

The corpus is intended to include work that supports, overlaps with, complicates, or challenges the Runtime Governance thesis. Sources that make the thesis less comfortable are especially useful.

Please include the source title, original URL, author, organization, or venue as published, publication date, and why it may be relevant. Submission does not imply guaranteed inclusion.

Submit a source