Research

Watch · narrated whiteboard episodesL2

Intent-Based Governance for AI Systems

Permission models authorize an agent to touch a resource; they say nothing about why it should. This series builds intent-based governance from the ground up: governing an autonomous agent by its declared intent rather than an enumerated list of permissions. It develops the intent-governance model and how it differs from access control, how to capture and verify intent with intent specifications and provenance while confronting the intent-action gap, how to compile intent into enforceable runtime guardrails and where those guardrails fail open, how to measure intent conformance — did the agent do what was asked, and only that — and how to govern at scale with intent ledgers, audit trails, and a mapping to the NIST AI RMF, the EU AI Act, and ISO/IEC 42001. Grounded in the NIST AI Risk Management Framework and Generative AI Profile, NIST SP 800-207 Zero Trust, the OWASP Agentic Security Initiative and LLM Top 10, MITRE ATLAS, ISO/IEC 42001, and the EU AI Act.

Murali Chillakuru·5 episodes
  1. 12 min Episode 1The Intent-Governance Model: Governing by Declared Intent Rather Than Enumerated PermissionsA moderator and a staff engineer work through why permission lists can't catch an on-permission abuse, and how governing by declared intent supplies the missing 'why'.
  2. 11 min Episode 2Capturing and Verifying Intent: Intent Specs, Provenance, and the Intent-Action GapA moderator and a staff engineer work through how a fuzzy human purpose becomes a machine-checkable intent that is faithful, authentic, and honest about what it can't cover.
  3. 11 min Episode 3Policy as Intent: Compiling Intent into Enforceable Runtime Guardrails and Where It Fails OpenA moderator and a staff engineer work through how a declared intent becomes runtime guardrails at an enforcement point, and the three surfaces where those guardrails fail open.
  4. 11 min Episode 4Measuring Intent Conformance: Did the Agent Do What Was Asked, and Only That?A moderator and a staff engineer work through why conformance is two questions, why 'only that' is the hard one, and how to measure it without drowning in false alarms or being gamed.
  5. 12 min Episode 5Governance at Scale: Intent Ledgers, Audit Trails, and Mapping to NIST AI RMF and the EU AI ActA moderator and a staff engineer work through how a fleet's intents become a durable, queryable, auditable system of record — the evidence that turns governance from assertion into demonstration.