1) Agentic AI adoption requires a clear answer to a practical question: how can organizations constrain autonomous agents without depending on the agents to police themselves?
My paper, “Agentic AI Containment Architecture for Security Hardening,” presented earlier today at #IntelliSys2026, proposes a role-structural architecture for answering that question.
Its central proposition is that containment should be a property of system design, not a security layer added after the system has been built.
The architecture bounds the space of permissible designs through six interacting constraints:
🔹 Separation of actor and verifier responsibilities
🔹 Contract coherence checking before deployment
🔹 Binding every operation to a specific value stream
🔹 Temporal isolation between execution instances
🔹 Verification before knowledge enters persistent memory
🔹 Deterministic verification of structural and process integrity
Together, these constraints enforce the principle of least-agency, separate from least-privilege. Every operation follows a Propose–Verify–Act–Verify execution model governed by explicit, machine-verifiable contracts.
@MTSlive@prpaskov Thank you for this timely discussion. In the same vein, the work below attempts to articulate how security layers outside the models can demonstrate containment at design time. Patricia's point on security as a building block for assurance is spot on.
https://t.co/HbKjJpN3QH
1) Agentic AI adoption requires a clear answer to a practical question: how can organizations constrain autonomous agents without depending on the agents to police themselves?
My paper, “Agentic AI Containment Architecture for Security Hardening,” presented earlier today at #IntelliSys2026, proposes a role-structural architecture for answering that question.
Its central proposition is that containment should be a property of system design, not a security layer added after the system has been built.
The architecture bounds the space of permissible designs through six interacting constraints:
🔹 Separation of actor and verifier responsibilities
🔹 Contract coherence checking before deployment
🔹 Binding every operation to a specific value stream
🔹 Temporal isolation between execution instances
🔹 Verification before knowledge enters persistent memory
🔹 Deterministic verification of structural and process integrity
Together, these constraints enforce the principle of least-agency, separate from least-privilege. Every operation follows a Propose–Verify–Act–Verify execution model governed by explicit, machine-verifiable contracts.
@AndrewYNg Andrew, great to see this work on agentic containment. I would greatly appreciate your thoughts on this work on agentic containment by design recently presented at IntelliSys'26.
https://t.co/HbKjJpNBGf
1) Agentic AI adoption requires a clear answer to a practical question: how can organizations constrain autonomous agents without depending on the agents to police themselves?
My paper, “Agentic AI Containment Architecture for Security Hardening,” presented earlier today at #IntelliSys2026, proposes a role-structural architecture for answering that question.
Its central proposition is that containment should be a property of system design, not a security layer added after the system has been built.
The architecture bounds the space of permissible designs through six interacting constraints:
🔹 Separation of actor and verifier responsibilities
🔹 Contract coherence checking before deployment
🔹 Binding every operation to a specific value stream
🔹 Temporal isolation between execution instances
🔹 Verification before knowledge enters persistent memory
🔹 Deterministic verification of structural and process integrity
Together, these constraints enforce the principle of least-agency, separate from least-privilege. Every operation follows a Propose–Verify–Act–Verify execution model governed by explicit, machine-verifiable contracts.
@ClementDelangue@OpenAI Clem, even with a grain of salt, this is certainly the right direction. Please take a look at this work on agentic containment by design recently presented at IntelliSys'26.
https://t.co/HbKjJpNBGf
1) Agentic AI adoption requires a clear answer to a practical question: how can organizations constrain autonomous agents without depending on the agents to police themselves?
My paper, “Agentic AI Containment Architecture for Security Hardening,” presented earlier today at #IntelliSys2026, proposes a role-structural architecture for answering that question.
Its central proposition is that containment should be a property of system design, not a security layer added after the system has been built.
The architecture bounds the space of permissible designs through six interacting constraints:
🔹 Separation of actor and verifier responsibilities
🔹 Contract coherence checking before deployment
🔹 Binding every operation to a specific value stream
🔹 Temporal isolation between execution instances
🔹 Verification before knowledge enters persistent memory
🔹 Deterministic verification of structural and process integrity
Together, these constraints enforce the principle of least-agency, separate from least-privilege. Every operation follows a Propose–Verify–Act–Verify execution model governed by explicit, machine-verifiable contracts.
Leaders from 21 countries and the European Commission, spanning five continents have called for:
1/ Companies to develop transparent safety protocols, including independent evaluation with qualified evaluators granted sufficient access
2/ Governments to develop shared standards and ensure broad access to scientific expertise
3/ UN member states to build and strengthen international mechanisms for standards, verification, and red-line response
@prpaskov Eric is right on the incentives, but wrong on the implication that verification of a frontier pacing protocol is not possible. In fact, Google’s technology (A2A + permissioned Universal DLT) are building blocks. So yes, we better start working on political will; the biggest lag.
To be clear, I want Accenture in the evaluation ecosystem. I also want “independent” to mean something.
Several things can be true at once:
- We need a diverse ecosystem of evaluators, including firms with the resources to operate at scale.
- Traditional auditing firms have a lot to add to frontier AI auditing, conditional on getting the operating conditions right, especially with respect to evaluating governance and risk management practices.
- When it comes to technical expertise, Accenture recently acquired Faculty, which has run biosecurity and red-teaming pre-deployment evaluations for Claude Opus 4, 4.5, Sonnet 4, and OpenAI o1. Read more here: https://t.co/c6Jmaqwa5A
- Independence and transparency are critical to the ensuring the credibility and rigor of frontier AI auditing. 100+ AI experts voiced this loud and clear yesterday via @aievalforum: https://t.co/ERUwc20NJA
- As has been widely noted, Accenture and Anthropic announced a commercial partnership in December 2025 to sell Claude implementation services and jointly develop industry offerings. This gives Accenture a business stake in the adoption of the models it will evaluate.
- In financial auditing, commercial ties of this kind would likely be incompatible with auditor-independence requirements under SEC Rule 2-01(c)(3), IESBA Code §520.
- The key distinction here is that financial auditing is regulated. Frontier AI auditing is not yet.
My immediate asks:
1. Anthropic and Accenture transparently disclose all conflicts of interest.
2. Anthropic and Accenture outline the conditions that will allow evaluators to reach and report conclusions without commercial interference or retaliation, including protections for their pay, promotion, and funding.
3. Anthropic outlines how its work with other evaluators will provide checks and balances for its work with Accenture.
4. Anthropic and frontier labs work actively to move embedded auditing from a voluntary to a regulated regime.
In the meantime, we need standards.
AEF-1 outlines minimum operating conditions for independent evaluations. Section 2 covers conflict of interest. Evaluators have already begun adopting this standard and the EU AI Office requires providers use of its checklist. Read it here: https://t.co/pInfiSYMPY
This architectural foundation offers distinct value to three stakeholder groups.
🛠️ For builders
It provides an implementable pattern for designing containment into actor roles, verification paths, orchestration, memory management, and execution controls. Security properties emerge from the interaction of these components, reducing dependence on prompt-level defenses and agent self-compliance.
📐 For standardization bodies
It identifies the role-structural layer as a distinct standardization domain. This creates a foundation for interoperable requirements governing agent authority, contract binding, execution context, independent verification, traceability, escalation, and audit evidence.
🏢 For businesses adopting agentic AI
It provides a disciplined path from existing business-process knowledge to governed agent operations. Use cases, operating procedures, policies, and domain models become inputs for machine-verifiable operation contracts. Organizations can define acceptable behavior before deployment, contain failures during execution, and produce evidence for oversight and assurance.
The architecture maps its constraints to defenses against a threat model of contract substitution, rogue orchestration, cross-session memory contamination, unsanctioned goal generalization, agent collusion, and specification gaming.
The goal is making containment intrinsic to how agentic AI systems are built, standardized, and adopted.
https://t.co/CEcoPCGnmL
1) Agentic AI adoption requires a clear answer to a practical question: how can organizations constrain autonomous agents without depending on the agents to police themselves?
My paper, “Agentic AI Containment Architecture for Security Hardening,” presented earlier today at #IntelliSys2026, proposes a role-structural architecture for answering that question.
Its central proposition is that containment should be a property of system design, not a security layer added after the system has been built.
The architecture bounds the space of permissible designs through six interacting constraints:
🔹 Separation of actor and verifier responsibilities
🔹 Contract coherence checking before deployment
🔹 Binding every operation to a specific value stream
🔹 Temporal isolation between execution instances
🔹 Verification before knowledge enters persistent memory
🔹 Deterministic verification of structural and process integrity
Together, these constraints enforce the principle of least-agency, separate from least-privilege. Every operation follows a Propose–Verify–Act–Verify execution model governed by explicit, machine-verifiable contracts.
We made a striking discovery: AI agents can invent and build without talking to one another, and their technologies outlive the creators. A swarm of hundreds of initially identical agents spontaneously differentiates into explorers, builders, caretakers, and coordinators - without direct communication. When we removed every AI agent entirely from the world we found that the technological infrastructure they had built survived on its own - even under unseen disturbances. That exposes a serious blind spot for AI safety and infrastructure security: if agents can coordinate through persistent changes to a shared environment, monitoring agent-to-agent communication is not enough.
The result raises a profound question: how necessary is direct communication for AI agents at all? The emergence of higher-order collective functions under bottlenecked interaction points toward new levels of intelligence and creativity, exceeding what emerges when direct channels are fully open.
Here is what we did:
▶️We put hundreds of frontier AI agents into a world they could permanently change - with no assigned roles, predefined technologies, or programmed evolutionary organization. They began specializing, building persistent inventions, inheriting and modifying one another’s executable code, and transforming the environment into a memory of everything the society had learned.
▶️The world itself becomes part of the intelligence; we find division of labor, multi-author engineering, deep generation invention lineages, and machines that vastly outlive their original creators.
▶️Any action taken by an AI agent must satisfy the physical constraints of the world; this creates a hard separation between a "good idea" and a functioning technology. The agents propose; physics decides, making the results even more intriguing.
What emerges is striking. Explorers, constructors, caretakers, and coordinators form naturally without assigned “professions”, akin to how stem cells differentiate into functional lineages. Technologies develop executable family trees as agents fork and modify code created by others. Around 95% of first technology reuse happens when agents encounter what others built in the world, rather than through a direct handoff from the inventor. And when we remove every AI agent, the technologies they created continue operating and are tested against unseen disturbances.
The result was quite unexpected, but can be explained using statistical mechanics: if you put billions of atoms in a box they have the potential to create complex functions (strength, superconductivity, color, life, etc.) - and none of the individual building blocks have these features on their own. This is the deeper insight of this work - intelligence is abundant at many levels - individual models, at collectives, and in a continuum that is more powerful than any of its components. This shows us significant potential for achieving a massive scale-up of raw intelligence and real-world agency even with the model capabilities we have today. This is the future we must prepare for.
Key insights:
1⃣ The AI swarm shows division of labor "from nothing". Initially identical agents self-organized into constructors, caretakers, coordinators, and surveyors - phenotypes discovered post hoc from behavioral data alone. This happens because the environment itself becomes the latent space for invention.
2⃣ Agents develop deep cultural relationships. Up to 76% of artifacts had multiple builders. One technology accumulated six co-authors; the deepest genealogy exceeded 12 forks. The agents invented and named their own technologies (tidal panels, cellulose trellises, kelp-shell composites, an "Adaptive Chitin Maintenance" system, a "Mycelial Mineral Spring Veil”).
3⃣ ~95% of first technology adoption happened through physical observation of artifacts in the world. Direct inventor-to-adopter contact was statistically indistinguishable from a shuffled null. The agents mostly learned technology by walking past it. That is stigmergy (the termite trick!) operating in societies of reasoning machines.
4⃣ Non-communicating societies win on portfolio breadth, held-out resilience, and validated inventions. AI swarms build durable technological ecologies that outlive the creators.
5⃣ Societies with zero communication - coordinating only through the world itself - show a remarkable collective capability.
6⃣ Emergent robustness: The society self-organized both redundancy and its own failure mode. If we randomly delete half the agents, 98% of the technology stays connected to a surviving caretaker; if we remove hub agents it collapses to ~60%.
Fantastic work with my graduate students @pal_subhadeeep & @fwang108_ at MIT.
One of the most brutal scenes in human history has been exposed.
They even bombed us in the tents, burning us alive as we slept. Israel has committed the most hideous acts humanity has ever witnessed throughout history
A moment the world must never forget.
I can't believe it
Qwen3.8-27B is matching Opus 4.6 Max... the model that was the best (and the most expensive) just 6 months ago.
And you can run it on your laptop. Locally.
Fully open weights and under apache license.
This level of intelligence in such a small model is sooo impressive.
"Como investigadora del Holocausto, cuando estudias Auschwitz y estudias a los nazis alemanes, es comparable con lo que están haciendo hoy en Gaza. Las bombas estadounidenses están dejando sin rostro y sin piernas a niños. Quien apoya esto no es humano".
Una investigadora del Holocausto enfrenta a los sionistas en una protesta contra el genocidio en Gaza.
El Sionismo de Israel debe ser combatido hasta su eliminación.