Research

Watch · narrated whiteboard episodesL3

The Layers That Secure Agents That Act

Securing an AI agent one component at a time is no longer enough: every component can pass review while the agent's overall behavior reaches an outcome nobody approved. This series defines Layered Outcome Assurance, an architecture of six layers for agents that act. Each layer makes one guarantee true, depends on the layer below it, and supplies something the layer above cannot work without: design for continuous pressure, bound every agent's reach as an actor, keep untrusted content away from privileged actions, govern whole sequences of behavior, record evidence that explains every consequential action, and enforce decisions with controls the model cannot argue with. Each article defines a layer's guarantee, its contract with its neighbours, what fails when it is skipped, and how to test that it holds, closing with conformance tests and a build order. Vendor-neutral and grounded in primary security and AI-security literature.

Murali Chillakuru·8 episodes
  1. 23 min Episode 1Layered Outcome Assurance: An Architecture for Securing Agents That ActWhy an agent whose every permission was approved can still reach an outcome nobody approved, and the six-layer architecture that bounds and explains what it can do.
  2. 23 min Episode 2Layer 1, Continuous Pressure: Designing for Attackers Who Never TireWhy a defence that blocks almost every attempt can still lose a campaign, and how to design agent controls whose protection does not decay as attempts pile up.
  3. 23 min Episode 3Layer 2, Agents as Actors: Knowing an Agent's True ReachWhy a list of approved permissions never shows what an agent could cause, and how to compute, reduce, and verify an agent's true reach before an incident reveals it.
  4. 23 min Episode 4Layer 3, The Action Chain: Keeping Untrusted Content Away from Privileged ActionsWhy spotting malicious instructions can never be the guarantee, and how provenance, plan separation, argument contracts, and narrow endorsement keep untrusted content from choosing what an agent does.
  5. 22 min Episode 5Layer 4, Whole Behavior: When Allowed Steps Compose into HarmWhy per-call authorization cannot see what a sequence of allowed steps adds up to, and how toxic-combination analysis, history-based rules, and outcome approval judge the whole before it becomes permanent.
  6. 21 min Episode 6Layer 5, Explanatory Evidence: The Record Every Consequential Action OwesWhy logs that show success cannot explain an agent incident, and how a tamper-evident record that answers six questions becomes an input to every decision: no record, no action.
  7. 22 min Episode 7Layer 6, Deterministic Enforcement: Guardrails the Model Cannot Argue WithWhy neither the agent's model, a reviewer model, nor a context-free approval button can be the final safeguard, and how attribute-based, analysable policy outside the model makes a guardrail no sentence can move.
  8. 23 min Episode 8Adopting Layered Outcome Assurance: Conformance, Maturity, and Build OrderHow to actually adopt the six layers: a conformance suite as the source of truth, evidence-based states instead of maturity scores, a build order read from the contract, and thin slices that protect the worst outcome first.