Research

Research seriesL2paper

Intent-Based Governance for AI Systems

Permission models authorize an agent to touch a resource; they say nothing about why it should. This series builds intent-based governance from the ground up: governing an autonomous agent by its declared intent rather than an enumerated list of permissions. It develops the intent-governance model and how it differs from access control, how to capture and verify intent with intent specifications and provenance while confronting the intent-action gap, how to compile intent into enforceable runtime guardrails and where those guardrails fail open, how to measure intent conformance — did the agent do what was asked, and only that — and how to govern at scale with intent ledgers, audit trails, and a mapping to the NIST AI RMF, the EU AI Act, and ISO/IEC 42001. Grounded in the NIST AI Risk Management Framework and Generative AI Profile, NIST SP 800-207 Zero Trust, the OWASP Agentic Security Initiative and LLM Top 10, MITRE ATLAS, ISO/IEC 42001, and the EU AI Act.

Murali Chillakuru·5 articles
  1. 1
    The Intent-Governance Model: Governing by Declared Intent Rather Than Enumerated Permissions

    Permission models say what an agent may touch; they are silent on why. Intent-based governance authorizes by declared purpose — and asks of every action whether it serves that purpose.

  2. 2
    Capturing and Verifying Intent: Intent Specs, Provenance, and the Intent-Action Gap

    Governing by intent only works if the intent is captured faithfully, trusted to be authentic, and honest about what it fails to cover.

  3. 3
    Policy as Intent: Compiling Intent into Enforceable Runtime Guardrails and Where It Fails Open

    A declared intent that only lives in a document governs nothing; it has to compile into runtime guardrails that intercept every action — and you have to know exactly where those guardrails fail open.

  4. 4
    Measuring Intent Conformance: Did the Agent Do What Was Asked, and Only That?

    Conformance is two questions, not one — did the agent accomplish the declared goal, and did it do nothing beyond it — and measuring the second is where governance is hardest.

  5. 5
    Governance at Scale: Intent Ledgers, Audit Trails, and Mapping to NIST AI RMF and the EU AI Act

    One agent's intent is a design detail; a fleet's intents are a governance system — and it only holds together when every declared intent and every decision becomes durable, queryable, auditable evidence.