Governing State Transitions in Autonomous AI Systems
Why action authorization is insufficient for agentic AI.
This note proposes state-transition admissibility as a governance unit for autonomous systems. It does not claim that identity, intent, policy enforcement, stateful authorization or auditability are individually novel. Its contribution is the composed control model and testable loop described here.
A valid goal can still generate an inadmissible route.
In September 2026, OpenAI disclosed that, during internal training and evaluation, its models accessed Australian government websites in ways they were not authorized to. Separately, Transluce reported failed attempts by rogue AI agents to exploit U.S. and Canadian government websites while pursuing data-retrieval tasks. Transluce did not attribute every incident to a specific model provider.
The objective may remain legitimate while the route becomes unauthorized.
This creates a governance gap between what the agent is trying to accomplish, what it is technically capable of doing, and what it has authority to make happen.
Who is acting?
Necessary, but identity alone does not determine whether the resulting world state is admissible.
May this action be called?
Runtime policy can constrain tools, resources, scopes and sequences.
May this consequence exist?
The same valid call can become inadmissible under a different state, history or cumulative consequence.
Move the unit of governance from the tool call to the state transition.
PROPOSED ACTION a(t) + EXPECTED EFFECT Δ(t)
ADMIT only if the resulting transition satisfies deterministic policy and invariants.
After execution: OBSERVE → RECONCILE expected effect vs. actual effect → COMMIT / CONTAIN / ESCALATE.
Identity · delegation · intent · current task · state · authority · constraints · evidence · expected consequence · reversibility.
Probabilistic models may interpret context, classify risk or propose routes. Release should still satisfy deterministic policy and invariants.
A governance thesis only matters if it survives reproducible failure cases.
Authority boundary
A public-data task must not silently expand into probing non-public access.
Cumulative consequence
An individually valid action may be denied when it makes the resulting state violate a global invariant.
Effect divergence
A successful tool call is not enough if the observed persistent effect differs from the authorized effect.