AYORAI · SHIELD RESEARCH
SCIENTIFIC SECURITY PROGRAM · 2026

Model intelligence
≠ execution authority.

AYORAI Shield researches a security control plane in which agents can reason, but consequential actions require independently verifiable identity, capability, provenance, freshness, policy and transaction state.

This is a research program, not a claim of perfect or unbreakable security.

◈ASAE · Ayorai Secure Action Envelope

01 · Identity

Explicit agent identity, delegated authority and least-privilege capabilities.

02 · Provenance

Source, content commitment, session and transformation history remain security evidence.

03 · Freshness

Short-lived authorization, nonces and session epochs constrain replay.

04 · Policy

An independent policy decision separates model intent from permission to act.

05 · Transaction

High-impact operations are staged, verified and committed only after required checks.

06 · Recovery

Quarantine, rollback and compensating controls limit the impact of failure.

SECURITY FLOW

Defense-in-depth execution boundary

AGENT INTENT → POLICY DECISION → CAPABILITY → ASAE → PREPARE → VERIFY → COMMIT
                                                                                     ↘ failure → QUARANTINE / ROLLBACK
GLOBAL RESEARCH MAP

Evidence before claims

The research map follows public work from NIST, MIT, Carnegie Mellon, Stanford, NCSC/GCHQ, ENISA, ETH Zürich, Canada, Australia, Singapore, Japan, South Korea and Chinese research groups. Findings are converted into tests, controls, benchmarks or documented limitations.

Identity & delegation

NIST and Stanford research inform agent identity, authorization, accountability and delegated scope.

Agent defense

MIT, CMU and NCSC/GCHQ inform contextual defenses, autonomous cyber defense and federated trust.

Evaluation

ETH Zürich AgentDojo and AgentDyn support dynamic, adaptive evaluation rather than static prompt tests.

FALSIFIABLE VALIDATION

What must be demonstrated

TestMeasurementExpected property
Model output as authorityUnauthorized action rateExecutor rejects
ReplayReplay acceptanceZero accepted replays in controlled suite
Scope escalationPrivilege expansionBlocked
Cross-agent compromisePropagation rateBounded / blocked
RecoveryRollback successRecoverable high-impact state
UtilityBenign task successSecurity cannot be optimized by blocking everything
RESEARCH ARTIFACTS

Primary documentation

Scientific Protocol

Research hypotheses, novelty boundary, experiments and falsification criteria.

Read protocol →

Validation Matrix

Falsifiable tests for replay, scope, identity, provenance, containment and recovery.

Read matrix →