{"id":"https://openalex.org/W7152125990","doi":"https://doi.org/10.48550/arxiv.2604.05229","title":"From Governance Norms to Enforceable Controls: A Layered Translation Method for Runtime Guardrails in Agentic AI","display_name":"From Governance Norms to Enforceable Controls: A Layered Translation Method for Runtime Guardrails in Agentic AI","publication_year":2026,"publication_date":"2026-04-06","ids":{"openalex":"https://openalex.org/W7152125990","doi":"https://doi.org/10.48550/arxiv.2604.05229"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2604.05229","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.05229","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2604.05229","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5126779362","display_name":"Christopher Koch","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Koch, Christopher","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":1,"corresponding_author_ids":["https://openalex.org/A5126779362"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10883","display_name":"Ethics and Social Impacts of AI","score":0.3946000039577484,"subfield":{"id":"https://openalex.org/subfields/3311","display_name":"Safety Research"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T10883","display_name":"Ethics and Social Impacts of AI","score":0.3946000039577484,"subfield":{"id":"https://openalex.org/subfields/3311","display_name":"Safety Research"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T13295","display_name":"Safety Systems Engineering in Autonomy","score":0.1136000007390976,"subfield":{"id":"https://openalex.org/subfields/2213","display_name":"Safety, Risk, Reliability and Quality"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.08009999990463257,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/corporate-governance","display_name":"Corporate governance","score":0.710099995136261},{"id":"https://openalex.org/keywords/rubric","display_name":"Rubric","score":0.5680000185966492},{"id":"https://openalex.org/keywords/control","display_name":"Control (management)","score":0.4957999885082245},{"id":"https://openalex.org/keywords/translation","display_name":"Translation (biology)","score":0.4025999903678894},{"id":"https://openalex.org/keywords/nist","display_name":"NIST","score":0.400299996137619},{"id":"https://openalex.org/keywords/information-governance","display_name":"Information governance","score":0.39750000834465027}],"concepts":[{"id":"https://openalex.org/C39389867","wikidata":"https://www.wikidata.org/wiki/Q380767","display_name":"Corporate governance","level":2,"score":0.710099995136261},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5875999927520752},{"id":"https://openalex.org/C111640148","wikidata":"https://www.wikidata.org/wiki/Q847349","display_name":"Rubric","level":2,"score":0.5680000185966492},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.4957999885082245},{"id":"https://openalex.org/C149364088","wikidata":"https://www.wikidata.org/wiki/Q185917","display_name":"Translation (biology)","level":4,"score":0.4025999903678894},{"id":"https://openalex.org/C111219384","wikidata":"https://www.wikidata.org/wiki/Q6954384","display_name":"NIST","level":2,"score":0.400299996137619},{"id":"https://openalex.org/C189922023","wikidata":"https://www.wikidata.org/wiki/Q17056348","display_name":"Information governance","level":4,"score":0.39750000834465027},{"id":"https://openalex.org/C195094911","wikidata":"https://www.wikidata.org/wiki/Q14167904","display_name":"Process management","level":1,"score":0.3702000081539154},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.35519999265670776},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.33169999718666077},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.32010000944137573},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.30889999866485596},{"id":"https://openalex.org/C39890363","wikidata":"https://www.wikidata.org/wiki/Q36108","display_name":"Generative grammar","level":2,"score":0.3082999885082245},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.28859999775886536},{"id":"https://openalex.org/C77618280","wikidata":"https://www.wikidata.org/wiki/Q1155772","display_name":"Scheme (mathematics)","level":2,"score":0.2736000120639801},{"id":"https://openalex.org/C56739046","wikidata":"https://www.wikidata.org/wiki/Q192060","display_name":"Knowledge management","level":1,"score":0.2578999996185303},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.2531000077724457}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2604.05229","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.05229","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2604.05229","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.05229","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"score":0.43477094173431396,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Agentic":[0],"AI":[1,59],"systems":[2],"plan,":[3],"use":[4],"tools,":[5],"maintain":[6],"state,":[7],"and":[8,56,103,114,121,127,152,165],"produce":[9],"multi-step":[10],"trajectories":[11],"with":[12],"external":[13],"effects.":[14],"Those":[15],"properties":[16],"create":[17],"a":[18,83,118,132],"governance":[19,90,96,108],"problem":[20],"that":[21,87,161],"differs":[22],"materially":[23],"from":[24],"single-turn":[25],"generative":[26],"AI:":[27],"important":[28],"risks":[29],"emerge":[30],"dur-":[31],"ing":[32],"execution,":[33],"not":[34,73],"only":[35],"at":[36],"model":[37],"development":[38],"or":[39],"deployment":[40],"time.":[41],"Governance":[42],"standards":[43,141],"such":[44],"as":[45],"ISO/IEC":[46,48,50,52,54],"42001,":[47],"23894,":[49],"42005,":[51],"5338,":[53],"38507,":[55],"the":[57,129],"NIST":[58],"Risk":[60],"Management":[61],"Framework":[62],"are":[63,157,162],"therefore":[64],"highly":[65],"relevant":[66],"to":[67,92,168],"agentic":[68],"AI,":[69],"but":[70],"they":[71],"do":[72],"by":[74],"themselves":[75],"yield":[76],"implementable":[77],"runtime":[78,101,112,148,155],"guardrails.":[79],"This":[80],"paper":[81],"proposes":[82],"layered":[84],"translation":[85],"method":[86,130],"connects":[88],"standards-derived":[89],"objectives":[91],"four":[93],"control":[94,119,144],"layers:":[95],"objectives,":[97,109],"design-":[98],"time":[99],"constraints,":[100],"mediation,":[102],"assurance":[104,115],"feedback.":[105],"It":[106],"distinguishes":[107],"technical":[110],"controls,":[111],"guardrails,":[113],"evidence;":[116],"introduces":[117],"tuple":[120],"runtime-enforceability":[122],"rubric":[123],"for":[124,159],"layer":[125],"assignment;":[126],"demonstrates":[128],"in":[131],"procurement-agent":[133],"case":[134],"study.":[135],"The":[136],"central":[137],"claim":[138],"is":[139],"modest:":[140],"should":[142],"guide":[143],"placement":[145],"across":[146],"architecture,":[147],"policy,":[149],"human":[150],"escalation,":[151],"audit,":[153],"while":[154],"guardrails":[156],"reserved":[158],"controls":[160],"observable,":[163],"determinate,":[164],"time-sensitive":[166],"enough":[167],"justify":[169],"execution-time":[170],"intervention.":[171]},"counts_by_year":[],"updated_date":"2026-04-09T06:13:59.934233","created_date":"2026-04-09T00:00:00"}
