Research Index

AOI Runtime Governance Evidence Map

A continuously maintained index of primary research, technical architectures, standards, market developments, and adjacent work contributing to the emerging discipline of Runtime Governance.

The map catalogs supporting, overlapping, adjacent, and challenging work. Inclusion does not imply endorsement.

The Evidence Map describes the state of the literature, not the state of AO Integrity.

Schema v744 sources9 claims

Corpus facts

Derived from stored corpus records.

44

Total sources

35

Primary sources

0 external contributions recorded.

Classification metrics

Counts depend on AOI's current taxonomy.

25

Overlap flagged

23

Challenge or complicate

Claim Map

Stored claims and source relationships.

Coverage statements are rendered exactly as stored in the Schema v7 corpus.

ClaimLabelTypeCoverageSources
EL

Execution Legitimacy

Whether a specific execution remains a legitimate exercise of conferred authority at the moment it occurs. The five conditions operationalize this determination.

determinationFourteen sources. Three added 2026-08-03, all as support or complement rather than competition: aviation dispatch release as a two-party determination made against current conditions, financial settlement finality as an ex ante determinate irrevocability point, and certificate-bound admission as a conditional-execution model. Support remains strongest from outside AI. Competing treatments continue to address individual conditions rather than the integrated five.
RA

Runtime Admissibility

The determination of whether execution should proceed right now. Not whether memory, data, context, or a consequence is admissible — those may be inputs or subordinate questions, but RA governs execution.

gateTwenty-one sources. Six added 2026-08-03. The certificate-bound admission and execution pair (arXiv 2606.11632, 2606.20520) is the corpus's first two-paper treatment separating proposal, admission, and execution with a signed artifact carried between them, with prototype measurements on AWS and Kubernetes. Foundational support continues to come from runtime verification and monitorability literature, now joined by financial settlement-finality standards on the ex ante determinacy of the irrevocability point. No enterprise-scale operational case study found.
AC

Authority Continuity

The preservation of valid, correctly scoped, and traceable authority across identity, delegation, context, and execution as conditions change over time. Broader than delegation-chain correctness: includes whether authority remains legitimate through the interval between grant and effect.

continuityTwenty sources. Four added 2026-08-03. arXiv 2607.23586 addresses grant survival under agent mutation under the name authorization continuity, with a fixed transition envelope and effect ceiling; arXiv 2606.20520 revalidates against live state at execution rather than at grant. Aviation dispatch regulation (14 CFR 121.533 and 121.663) supplies a long-standing regulatory analogue in which release authority is joint, continuously revisited between release and completion, and non-delegable at the dispatch level. Catalogued treatments continue to address subsets of the claim: agent mutation, infrastructure state, or delegation structure, rather than authority across identity, delegation, organizational context, and execution together. Delegation chains remain structurally representable without non-widening enforced by construction in any deployed standard.
AD

Authority Drift

The divergence, over time, between authority a system retains and the authority current organizational circumstances would justify. Not privilege accumulation — a technically correct entitlement may still be illegitimate in current context.

failureThree sources, unchanged this week. No competing treatments found, and none of the seven sources added 2026-08-03 competes with the canonical definition. arXiv 2606.20520 checks live-state drift at execution against a certified contract, but that comparison is infrastructure state against a contract rather than retained authority against current organizational circumstances, and it was not tagged AD. No standardized business-state event vocabulary exists. No unit of measure, continuous formulation, or threshold located in any source. AD remains the thinnest claim in the corpus by competing coverage and an open search lane.
CD

Capability Drift

Change in an autonomous system's effective ability to produce consequences without a corresponding reevaluation of the authority governing those capabilities. Arises through learned skills, tool composition, memory, model updates, reusable behaviors, delegation, or environmental change.

failureThree sources, up from one. Two added 2026-08-03 substantively address capability evolution rather than state persistence: a state-bound authorization model that fixes an immutable effect ceiling at grant time and proves that mutation cannot amplify protected effects beyond it, where the mutations enumerated include acquiring skills and tools, revising workflows, and delegating work (arXiv 2607.23586); and a lifecycle-time upgrade governance pipeline with interface, policy, behavioral, and recovery compatibility checks, gated activation, shadow deployment, online monitoring, and rollback, measured on an embodied-agent testbed (arXiv 2604.08059). Both report formal or quantitative results; neither uses the term Capability Drift. A third source added this week, arXiv 2605.26542, is catalogued under AC and RA rather than CD: it governs authority attenuation across a composed tool chain within a session, which is adjacent compositional attenuation rather than change over time in effective ability to produce consequences. Still absent from the record: any enterprise deployment case study, any continuous measure or threshold for capability change, and any treatment tying capability change to organizational rather than technical authority.
GE

Governance Evidence

Independently reviewable evidence showing what legitimacy determination was made, which authority and contextual signals informed it, and why the execution was permitted, denied, escalated, or attested. Logs may contribute evidence; event records alone do not establish governance reasoning.

evidenceThirteen sources. Three added 2026-08-03. Signed decision and outcome records bound to a certified execution contract (arXiv 2606.20520) and evidence-digest binding at admission (arXiv 2606.11632) extend the catalogued set of cryptographically bound evidence models. The signed dispatch release under 14 CFR 121.663 is the corpus's first regulatory instance of a governance artifact that two named parties must both sign before an operation may begin. Regulatory demand remains documented with no finalized technical standard.
OBJ

Evaluation Object

The composite execution event: principal, delegation chain, agent, action, target, context, intent, and provenance relevant to a specific execution. Treated as an adopted and refined architecture choice, not a novelty claim.

designNine sources. One added 2026-08-03: arXiv 2606.11632 compiles agent proposals into typed execution contracts bound to evidence digests and policy versions, adding a fifth independent 2026 work locating governance at an execution, admission, or bind boundary.
PE

Policy vs Enforcement

The distinction between governance that is declared and governance that is operationally established in the execution path. A supporting claim, not AOI-originated.

supportingWell covered externally. Primary source is Cavallo's described-versus-established framing; supported by practitioner and distributed-systems material.
MKT

Market Conditions

External technical, regulatory, operational, and commercial developments that increase the need for Runtime Governance but do not themselves establish its architecture.

contextAmple. NHI ratios, over-permissioning rates, IAM capability gaps, and regulatory timelines all documented from multiple sources.

Showing 19 of 44 sources.

Clear filters

e008

Prompt injection still drives most agentic AI security failures in production

Permalink
Source
Help Net Security / OWASP
Source type
press
Primary or secondary status
Secondary
Domain
Runtime
Published
2026-06-11
Claims
EL
Conditions
3.5
Stance
supports
Relation
supports
Strength
supporting
Overlap flag
none

OWASP-sourced. Prompt injection lands on roughly one in three deployed agents; 88 percent of enterprises deploying agents reported at least one agent-linked security incident. Direct empirical support for Causal Integrity as a live failure mode rather than a hypothetical.

Original link

e009

awesome-ai-agent-attacks — sourced timeline of real AI agent security incidents 2024-2026

Permalink
Source
Community timeline
Source type
incident
Primary or secondary status
Primary
Domain
Runtime
Published
2026
Claims
EL, AC
Conditions
3.5, 3.2
Stance
supports
Relation
supports
Strength
supporting
Overlap flag
none

Dated and sourced incident corpus. Includes the Copilot email-summarization case (hidden instructions ingested during summarization, exfiltration from OneDrive/SharePoint/Teams via a trusted Microsoft domain), CVE-2025-6514 MCP RCE, CVE-2025-59536 hooks injection, postmark-mcp supply chain, and GTG-1002. The Copilot case is a close real-world analogue of Appendix C.1.

Original link

e010

Authorization Propagation in Multi-Agent AI Systems: Identity Governance as Infrastructure

Permalink
Source
arXiv 2605.05440 (Tallam)
Source type
research
Primary or secondary status
Primary
Domain
Identity
Published
2026-05
Claims
AC
Conditions
3.2
Stance
supports
Relation
supports
Strength
supporting
Overlap flag
none

Examines how authorization propagates across multi-agent systems and frames identity governance as infrastructure rather than policy. Consistent with the delegation-propagation reading in Appendix A. Cited in the thesis reference list. Bears on AC and condition 3.2.

Original link

e011

AI Identity: Standards, Gaps, and Directions

Permalink
Source
arXiv 2604.23280
Source type
research
Primary or secondary status
Primary
Domain
Identity
Published
2026-04-28
Claims
AC
Conditions
3.2
Stance
supports
Relation
supports
Strength
supporting
Overlap flag
none

Finds OAuth 2.0 handles one-hop delegation well but lacks multi-hop chaining, cross-domain asynchronous flows, and any mapping between OAuth scopes and agent capabilities; cross-organizational log correlation unsolved. Independent corroboration of the Appendix A reading of RFC 8693 and RFC 9396.

Original link

e013

EU AI Act Article 12 logging obligations reach full enforcement August 2, 2026

Permalink
Source
Salt Security / EU AI Act
Source type
regulatory
Primary or secondary status
Secondary
Domain
Regulatory
Published
2026
Claims
GE, MKT
Conditions
EV, MKT
Stance
supports
Relation
supports
Strength
supporting
Overlap flag
none

Article 12 mandates automatic logging of events relevant to traceability; logs must be tamper-evident, retained six months minimum. No finalized technical standard yet — prEN 18229-1 and ISO/IEC DIS 24970 still in draft. Demand-side support for the decision receipt and for stating an assurance level explicitly.

Original link

e014

Okta transmits only two outbound CAEP event types as of early 2026

Permalink
Source
Andrew Doering
Source type
practitioner
Primary or secondary status
Secondary
Domain
Identity
Published
2026
Claims
AD
Conditions
3.3
Stance
supports
Relation
supports
Strength
emerging
Overlap flag
none

Okta does not emit risk-level-change, device-compliance-change, or assurance-level-change outbound. Sharpens the Appendix A argument that expressibility is not standardization — the deployed vocabulary is narrower than the specified one, well before reaching matter closure or contract expiry.

Original link

e015

Compositional agent harm — individually authorized sub-actions yielding harmful sequences

Permalink
Source
arXiv 2604.23338
Source type
research
Primary or secondary status
Primary
Domain
Runtime
Published
2026-04
Claims
EL, AC
Conditions
3.4, 3.2
Stance
supports
Relation
supports
Strength
supporting
Overlap flag
none

Systematic survey establishing that multi-step chains compose individually benign invocations into harmful sequences, and that the security property of a composition cannot be derived from its steps. Stateless per-request engines cannot enforce properties depending on execution history. Direct support for Appendix C.4.

Original link

e016

GitGuardian / Veza — non-human identity sprawl and over-permissioning at scale

Permalink
Source
Security Boulevard / GitGuardian / Veza
Source type
analyst
Primary or secondary status
Secondary
Domain
Market
Published
2026-07
Claims
MKT, AC
Conditions
MKT, 3.1
Stance
supports
Relation
supports
Strength
emerging
Overlap flag
none

Reports non-human identity to human ratios between 45:1 and 144:1 depending on environment, 73 percent of NHI-held secrets carrying excessive permissions, over 5.5 percent of AWS machine identities holding full administrative privilege, and 92 percent of organizations stating current IAM tooling cannot manage AI agent identities. Aggregated vendor and analyst reporting rather than peer-reviewed measurement. Bears on MKT and, indirectly, condition 3.1.

Original link

e017

The Non-Human Identity Governance Vacuum

Permalink
Source
Cloud Security Alliance
Source type
industry_standard
Primary or secondary status
Primary
Domain
Identity
Published
2026
Claims
MKT, AC
Conditions
MKT, 3.1
Stance
supports
Relation
supports
Strength
supporting
Overlap flag
none

CSA whitepaper framing NHI and agentic AI governance as a vacuum. Institutional corroboration that the gap is recognized, from a body that predates the thesis.

Original link

e021

Described vs. Established Governance in Agentic AI: Closing the Gap Between Policy and Enforcement

Permalink
Source
SSRN (Cavallo)
Source type
research
Primary or secondary status
Primary
Domain
Policy
Published
2026
Claims
PE, GE
Conditions
EV
Stance
supports
Relation
supports
Strength
supporting
Overlap flag
none

Frames the gap between governance as described in policy and governance as operationally established in the execution path. Bears on Section 3.8's distinction between security correctness and governance legitimacy, and on the Section 4.4 observation that controls are often described as audited at assurance levels they do not meet.

Original link

e022

State-Aware Runtime for Long-Horizon LLM Agents: A Conceptual Framework and Research Agenda

Permalink
Source
Cambridge Open Engage
Source type
research
Primary or secondary status
Primary
Domain
Memory/State
Published
2026
Claims
AD, CD, RA
Conditions
3.3
Stance
supports
Relation
complements
Strength
emerging
Overlap flag
none

Conceptual framework and research agenda for state-aware runtime across long-horizon agent operation. Bears on AD and on the Section 6.1 assumption that business systems can be consulted at execution latency. CD tag is provisional: the source addresses state persistence, and qualifies for CD only where it substantively treats capability evolution.

Original link

e023

Agency doctrine: actual authority, apparent authority, and ratification

Permalink
Source
Oxford Business Law Blog
Source type
legal_doctrine
Primary or secondary status
Primary
Domain
Legal
Published
2025-04
Claims
EL, AC
Conditions
3.2, 3.4
Stance
supports
Relation
complements
Strength
foundational
Overlap flag
none

Governance analogue and legal foundation rather than a doctrinal conclusion about software agents. Actual authority, apparent authority, and ratification establish that possession of apparent permission does not prove actual authority; that third parties may act on authority that is operationally credible but institutionally defective; and that later acceptance of an act differs from prior legitimacy. Apparent authority resembles the structure of Appendix C.1, though prompt injection and delegated software action are not doctrinally identical to it absent jurisdiction-specific authority. Ratification is the closest legal analogue to Section 5.2 post-hoc attestation, including its all-or-nothing character.

Original link

e024

Mission command doctrine: commander's intent and disciplined initiative

Permalink
Source
US Air Force AFDP 1-1
Source type
doctrine
Primary or secondary status
Primary
Domain
Ops Doctrine
Published
2023-08-14
Claims
EL, AC
Conditions
3.4
Stance
supports
Relation
supports
Strength
foundational
Overlap flag
none

Mission command combines centralized intent with decentralized execution. Commander's intent is doctrinally defined as a concise expression of purpose, method, and end state, including constraints, limitations, assumptions and resources, and is stated as a necessary condition without which mission command cannot be exercised. Subordinates exercise disciplined initiative within it. Establishes an institutional precedent for delegated autonomy bounded by represented intent; does not address machine-readable intent binding. Bears on condition 3.4 and Section 6.2.

Original link

e025

Runtime verification and monitorability of safety properties

Permalink
Source
Springer / RV literature
Source type
research
Primary or secondary status
Primary
Domain
Verification
Published
2023
Claims
RA, GE
Conditions
EV, OBJ
Stance
supports
Relation
supports
Strength
foundational
Overlap flag
none

Monitorability is defined as the ability to return a positive or negative verdict after a finite execution prefix, with the field concentrating on safety properties because violations are always detectable in finite time. This supplies formal grounding for Section 2.2's claim that the evaluable tuple is only complete at execution, and a rigorous way to state which legitimacy conditions are monitorable at all. Also gives Section 4.3's determinism requirement an existing literature to stand on.

Original link

e026

Verified runtime validation for partially observable hybrid systems

Permalink
Source
arXiv 1811.06502
Source type
research
Primary or secondary status
Primary
Domain
Verification
Published
2018
Claims
RA, AD
Conditions
3.3, EV
Stance
supports
Relation
supports
Strength
foundational
Overlap flag
none

Synthesizes runtime monitors from provably safe hybrid system models, robust to partial observability arising from sensor uncertainty and partial controllability arising from actuator disturbance. Establishes what guarantee survives when a monitor cannot observe full system state. The partial-observability treatment corresponds to the Section 6.1 assumption that contextual validity may proceed on cached state, and to the signal-freshness requirement in Section 4.2.

Original link

e027

Saga pattern, compensating transactions, and durable execution

Permalink
Source
Azure Architecture Center / long-running transaction literature
Source type
architecture
Primary or secondary status
Primary
Domain
Distributed Systems
Published
ongoing
Claims
RA, PE, OBJ
Conditions
OBJ
Stance
supports
Relation
adjacent
Strength
foundational
Overlap flag
none

Long-running transactions abandon locks on non-local resources and use compensating transactions that semantically undo rather than restore prior state, typically coordinated by a durable state machine. Establishes an existing engineering distinction between operations that can be compensated and those that cannot. Bears on the reversibility-based allocation in Section 5.3.

Original link

e029

Authenticated Delegation and Authorized AI Agents

Permalink
Source
arXiv 2501.09674
Source type
research
Primary or secondary status
Primary
Domain
Identity
Published
2025-01
Claims
AC
Conditions
3.2
Stance
supports
Relation
complements
Strength
supporting
Overlap flag
none

Earlier work connecting agency-law delegation concepts to authenticated agent authorization. Useful bridge between the Legal domain entries and the identity standards track, and evidence that the legal framing is already being imported by researchers.

Original link

e043

Responsibility for operational control and dispatch release: joint authority, continuous re-release, and non-delegable dispatch

Permalink
Source
eCFR - 14 CFR 121.533, with 121.663 (US Federal Aviation Administration)
Source type
regulatory
Primary or secondary status
Primary
Domain
Aviation
Published
1964-12-31, as amended 1996-01-26
Claims
EL, AC, GE
Conditions
3.1, 3.3
Stance
supports
Relation
supports
Strength
foundational
Overlap flag
none

Governance analogue from aviation regulation, not a doctrinal claim about software agents. The certificate holder is responsible for operational control; the pilot in command and the aircraft dispatcher are jointly responsible for preflight planning, delay, and dispatch release, and under 121.663 both must sign the release and may do so only if both believe the flight can be made with safety. Authority is not settled at release: the dispatcher must monitor the progress of each flight, issue information necessary for its safety, and cancel or redispatch if either the dispatcher or the pilot in command judges that the flight cannot continue to operate safely as planned or released. 121.663 further provides that a dispatcher may delegate authority to sign a release for a particular flight but may not delegate the authority to dispatch. Establishes a long-standing regulatory precedent separating conferred authority, delegable and non-delegable components, evaluation against current conditions, continuing responsibility after release, and a signed record of the determination. Bears on EL, AC, and the grant-to-effect interval; the signed release is an evidence artifact bearing on GE.

Original link

e044

Principles for financial market infrastructures - Principle 8: Settlement finality

Permalink
Source
CPSS-IOSCO / CPMI-IOSCO, PFMI (CPMI Papers No 101)
Source type
standard
Primary or secondary status
Primary
Domain
Financial Systems
Published
2012-04-16
Claims
EL, RA
Conditions
3.5
Stance
supports
Relation
complements
Strength
foundational
Overlap flag
none

Governance analogue from financial market infrastructure standards, not a doctrinal claim about software agents. Principle 8 requires that an FMI provide clear and certain final settlement, at a minimum by the end of the value date, and intraday or in real time where necessary or preferable. The accompanying legal-basis discussion states that there should be a clear legal basis regarding when settlement finality occurs, in order to define when key financial risks are transferred, including the point at which transactions are irrevocable, and treats settlement finality as a building block for risk management rather than a bookkeeping detail. Establishes an existing international standard requiring that the moment at which an action becomes irrevocable be defined ex ante and be legally determinate, including under participant insolvency. The standard governs the determinacy of the finality boundary; it does not specify evidence of a governance determination, and the entry is therefore not tagged GE. Bears on the reversibility-based allocation in Section 5.3 and on the treatment of the consequence-formation boundary; complements the compensating-transaction material catalogued at e027.

Original link

Methodology

How to read this map.

AO Integrity maintains the corpus and performs the classifications. Classification is interpretive. Total, primary, and externally contributed counts are corpus facts. Other metrics depend on the current taxonomy. Records can be corrected or withdrawn. Stable evidence IDs are never renumbered or reused. Withdrawn records remain addressable.

Contribution

What are we missing?

The corpus is intended to include work that supports, overlaps with, complicates, or challenges the Runtime Governance thesis. Sources that make the thesis less comfortable are especially useful.

Please include the source title, original URL, author, organization, or venue as published, publication date, and why it may be relevant. Submission does not imply guaranteed inclusion.

Submit a source