AI News HubLIVE
Original source2 min read

Verifiable Agentic Infrastructure: Proof-Derived Authorization for Sovereign AI Systems

Modern cloud and enterprise systems rely on identity-centric authorization, but autonomous AI agents can generate syntactically valid yet semantically unsafe actions. This paper introduces a Distributed Trust Framework (DTF) that replaces standing privileges with proof-derived authority, ensuring governable, auditable, and bounded agent execution. DTF uses justification proofs, consensus models, ephemeral execution identities, and an append-only evidence chain, instantiated on an OpenKedge-based substrate for cloud-native environments.

SourcearXiv AIAuthor: Jun He, Deying Yu

[2605.15228] Verifiable Agentic Infrastructure: Proof-Derived Authorization for Sovereign AI Systems

[Submitted on 13 May 2026]

Title:Verifiable Agentic Infrastructure: Proof-Derived Authorization for Sovereign AI Systems

View a PDF of the paper titled Verifiable Agentic Infrastructure: Proof-Derived Authorization for Sovereign AI Systems, by Jun He and 1 other authors

View PDF HTML (experimental)

Abstract:Modern cloud and enterprise systems rely on identity-centric authorization, assuming that callers possessing valid credentials are safe to execute commands. The emergence of autonomous AI agents invalidates this assumption: agents can generate syntactically valid but semantically unsafe actions, making standing privileges a significant operational risk. This risk becomes especially acute in sovereign AI systems, where autonomous agents may interact with cloud infrastructure, regulated data, financial workflows, and national-scale digital services. Governed mutation substrates reduce this risk by interposing on agent actions: agents submit intents, infrastructure evaluates context and policy, and execution is mediated. However, this shifts the trust boundary: how can the decision to authorize an intent be made verifiable, distributed, and replayable?

We introduce a Distributed Trust Framework (DTF), a verification framework for governed mutation systems that computes execution authority from structured, verifiable artifacts. DTF introduces a Justification Proof to encode the admissibility basis of an action, a consensus model for independent evaluation, an ephemeral Execution Identity derived from the approved proof, and an append-only Evidence Chain that preserves the authorization lifecycle. Under stated substrate assumptions, this architecture enforces a compact authorization invariant: no high-stakes execution without a proof object, no derived authority without consensus, and no valid mutation detached from evidence.

We define the model, instantiate it over an OpenKedge-based governed mutation substrate, and show how it maps onto cloud-native environments. By shifting authorization from standing identity to proof-derived authority, DTF provides an infrastructure foundation for making agentic execution governable, auditable, and bounded in sovereign AI deployments.

Comments: 19 pager, 2 figures, 4 tables

Subjects:

Artificial Intelligence (cs.AI); Machine Learning (cs.LG)

Cite as: arXiv:2605.15228 [cs.AI]

(or arXiv:2605.15228v1 [cs.AI] for this version)

https://doi.org/10.48550/arXiv.2605.15228

arXiv-issued DOI via DataCite

Submission history

From: Jun He [view email] [v1] Wed, 13 May 2026 17:58:52 UTC (28 KB)

Full-text links:

Access Paper:

View a PDF of the paper titled Verifiable Agentic Infrastructure: Proof-Derived Authorization for Sovereign AI Systems, by Jun He and 1 other authors

View PDF

HTML (experimental)

TeX Source

view license

Current browse context:

cs.AI

new | recent | 2026-05

Change to browse by:

cs cs.LG

References & Citations

NASA ADS

Google Scholar

Semantic Scholar

Loading...

Data provided by:

Bibliographic Tools

Bibliographic and Citation Tools

Bibliographic Explorer Toggle

Bibliographic Explorer (What is the Explorer?)

Connected Papers Toggle

Connected Papers (What is Connected Papers?)

Litmaps Toggle

Litmaps (What is Litmaps?)

scite.ai Toggle

scite Smart Citations (What are Smart Citations?)

Code, Data, Media

Code, Data and Media Associated with this Article

alphaXiv Toggle

alphaXiv (What is alphaXiv?)

Links to Code Toggle

CatalyzeX Code Finder for Papers (What is CatalyzeX?)

DagsHub Toggle

DagsHub (What is DagsHub?)

GotitPub Toggle

Gotit.pub (What is GotitPub?)

Huggingface Toggle

Hugging Face (What is Huggingface?)

ScienceCast Toggle

ScienceCast (What is ScienceCast?)

Demos

Demos

Replicate Toggle

Replicate (What is Replicate?)

Spaces Toggle

Hugging Face Spaces (What is Spaces?)

Spaces Toggle

TXYZ.AI (What is TXYZ.AI?)

Related Papers

Recommenders and Search Tools

Link to Influence Flower

Influence Flower (What are Influence Flowers?)

Core recommender toggle

CORE Recommender (What is CORE?)

Author

Venue

Institution

Topic

About arXivLabs

arXivLabs: experimental projects with community collaborators

arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.

Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.

Have an idea for a project that will add value for arXiv's community? Learn more about arXivLabs.

Which authors of this paper are endorsers? | Disable MathJax (What is MathJax?)