用于信任保留的智能体AI执行的策略代数
A Policy Algebra for Trust-Preserving Agentic AI Execution
AI总结:
本文提出一种策略代数,用于定义智能体AI执行的可靠范围,可干预94.8%的策略违规事件,保留86.9%的任务完成率,为构建可靠智能体提供支持。
AI中文摘要:
基于大语言模型的智能体框架主要优化能力:即智能体是否能推理、检索信息、调用工具、委派工作并完成目标。企业级执行需要更强的属性:若成功结果由未授权的数据访问、扩大的委派权限、未批准的副作用、不可恢复的预算消耗或不完整证据产生,则该结果不可靠。本文将可靠能力定义为路径属性:智能体仅在通过符合身份、配置文件、工具、数据、内存、预算、工件、审批和审计约束的可允许动作事件完成任务时,才具备可靠能力。我们提出一种策略代数,定义智能体能力可被行使的可靠范围:安全配置文件和运行时义务通过连接、交集、预算收窄、审批继承和证据积累进行组合,所得组合既保留信任,又是满足所有管控输入的最宽松状态;该代数还会在多智能体调用间传播限制,并引入感知成本的工件物化,即随着预算暴露增加,将开放式执行重定向至可恢复结果。评估被解读为可靠能力与能力间的权衡而非能力基准:策略代数运行时会干预94.8%的违反策略事件,同时保留86.9%的任务完成率,消除了观测到的配置文件单调性和零工件耗尽违规,并将审计完整性提升至98.6%。该方法为研究人员和从业者提供了形式化正确性条件、可执行决策语义和追踪证据,用于构建不仅有能力且具备可靠能力的智能体。
英文摘要:
Large language model-based agentic frameworks primarily optimize capability: whether an agent can reason, retrieve information, call tools, delegate work, and complete a goal. Enterprise execution requires a stronger property. A successful result is not reliable if it was produced through unauthorized data access, widened delegated authority, unapproved side effects, unrecoverable budget consumption, or incomplete evidence. This paper defines reliable capability as a path property: an agent is reliably capable only when it completes a task through action events that remain admissible under identity, profile, tool, data, memory, budget, artifact, approval, and audit constraints. We propose a policy algebra that defines the reliability envelope within which agent capability may be exercised. Security profiles and runtime obligations compose through joins, intersections, budget narrowing, approval inheritance, and evidence accumulation; the resulting composition is both trust-preserving and the least restrictive state satisfying all governing inputs. The algebra also propagates restrictions across multi-agent calls and introduces cost-aware artifact materialization, which redirects open-ended execution toward a recoverable outcome as budget exposure grows. The evaluation is interpreted as a reliability-capability trade-off rather than a capability benchmark: the policy-algebra runtime intervenes on 94.8% of policy-violating events while retaining an 86.9% task-completion rate, eliminates the observed profile-monotonicity and zero-artifact-exhaustion violations, and increases audit completeness to 98.6%. The method provides researchers and practitioners with formal correctness conditions, executable decision semantics, and trace evidence for building agents that are not only capable, but reliably capable.