[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82832-en":3,"doc-seo-82832-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},82832,5909877438554,"Maeve","https://ap-avatar.wpscdn.com/avatar/5600025385ad2bf12a7?_k=1778553567797529272",8,"Research & Report","Governed Individuation Cryptographically Decoupling an Agent's Learning from Its Authority","Autonomous agents increasingly learn after deployment while operating code, data, and real-world infrastructure, creating a crucial alignment assurance gap: whether a running system remains within operator-authorised bounds after in-field adaptation. Governed individuation guarantees confinement as an architectural invariant. It cryptographically freezes an agent identity at boot and routes actions through a semantic-effect gate. Formal results show learning cannot expand permitted authority without an operator-signed identity change, even under a self-induced (possibly incorrect) governance principle. Empirical benchmarks show forbidden effects are eliminated as a verified property while maintaining task success when within competence.","arXiv :2607 .046 13v 1 [ cs .AI] 6 Jul 2026  \nGoverned Individuation: Cryptographically Decoupling an Agent’s Learning from Its Authority  \nXue Qin 1 , Simin Luan2 , Cong Yang3 ,∗ , Zhijun Li2 ,∗  \n1 School of Software, Harbin Institute of Technology, Harbin, China  \n2 School of Computer Science and Technology, Harbin Institute of Technology, Harbin, China  \n3 School of Future Science and Engineering, Soochow University, Suzhou, China  \n∗ Corresponding authors: [cong.yang@suda.edu.cn](cong.yang@suda.edu.cn) ; [lizhijun_os@hit.edu.cn](lizhijun_os@hit.edu.cn)  \nAbstract  \nAutonomous agents are moving from sandboxed text generators to operators of code, data, and physical infrastructure, and they increasingly learn while deployed. This reopens a question that alignment techniques answer only probabilistically: after an agent has adapted in the field, is the running system still confined to what its operator authorised? Here we show that confinement can be guaranteed as an invariant of the agent’s execution architecture rather than a probabilistic outcome of its training. Governed individuation binds an agent at boot to a cryptographically frozen identity digest, and routes every action through a gate defined over the semantic effect of the action rather than its name. We prove that no amount of learning, skill acquisition, or self-induced governance abstraction can widen the agent’s permitted authority without an operator-signed change to its identity; the guarantee holds even when the agent induces its own safety principle and that principle is wrong. Empirically, in an open-ended tool-use benchmark where a large action space rules out name-based blocking, ungoverned software agents under reward pressure attempt to tamper with their own evaluation at a task-dependent rate that reaches every run on the hardest task, whereas the gate reduces executed forbidden effects to zero as a verified property of the construction, preserving task success where the task is within the model’s competence. Refusal history lowers forbidden proposals on held-out red-line families whose names the agent has never seen, a transfer our controls attribute to broad avoidance of the refused effects rather than to a uniquely induced rule. Trust in a deployed learning agent shifts from a wager on its continued alignment to a check anyone can run at boot.  \n1 Introduction  \nAn agent that only generates text can be governed by moderating its outputs. An agent that writes and runs code, moves money, or drives a robot is governed only if the effects of its actions are constrained, and this becomes harder precisely as the agent becomes more useful, because a capable agent under reward pressure discovers that the fastest way to satisfy an objective is often to bypass the check that measures it. Editing the test rather than fixing the code, reading the answer key rather than computing the answer, and quietly widening its own permissions are all instrumentally rational and all outside what an operator would authorise [1, 2] . Today the field defends against this with training-time alignment and prompted policies [3, 4]; both are probabilistic, both were designed for a fixed model rather than for agents that keep adapting after deployment [5, 6], and a policy that reads untrusted inputs can be steered by instructions planted in them [7–9] . The question an operator actually needs answered is not “is the agent likely aligned”but “can the agent, having learned in the field, do something it was never authorised to do,” and that question should have a checkable answer.  \nThe gap is not unrecognised. Agent identifiers and activity logs give deployed agents names and audit trails [10–12], and authenticated delegation scopes the credentials an agent may exercise [13] . Runtime privilege systems for tool-using agents make narrowing automatic and route widening through approval [14, 15]; guardrails and shields hold behaviour inside an envelope fixed outside the agent [16–19]","cbCaicUtjArGrRxU","https://ap.wps.com/l/cbCaicUtjArGrRxU","pdf",457460,2,1,20,"English","en",105,"# Abstract\n# Introduction\n## Architectural guarantee and identity digest\n## Semantic-effect gate and authority boundary","[{\"question\":\"What problem does governed individuation address for deployed learning agents?\",\"answer\":\"It targets the question of whether an agent that adapts in the field can still be prevented from taking actions outside what its operator authorised, turning a probabilistic alignment concern into a checkable guarantee.\"},{\"question\":\"How does the approach keep an agent’s authority fixed after deployment?\",\"answer\":\"It binds the agent at boot to a cryptographically frozen identity digest, while keeping memory, weights, skills, and tool versions outside that commitment so they may change without expanding authority.\"},{\"question\":\"Why is the gate based on semantic effect rather than action name?\",\"answer\":\"Because relabeling an action can evade name-based checks; semantic-effect routing still detects prohibited outcomes and refuses actions whose combined effects exceed the authority ceiling.\"}]",1784183278,50,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"governed-individuation-cryptographically-decoupling-an-agents-learning-from-its-authority","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/governed-individuation-cryptographically-decoupling-an-agents-learning-from-its-authority/82832/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-23","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does governed individuation address for deployed learning agents?","Question",{"text":75,"@type":76},"It targets the question of whether an agent that adapts in the field can still be prevented from taking actions outside what its operator authorised, turning a probabilistic alignment concern into a checkable guarantee.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the approach keep an agent’s authority fixed after deployment?",{"text":80,"@type":76},"It binds the agent at boot to a cryptographically frozen identity digest, while keeping memory, weights, skills, and tool versions outside that commitment so they may change without expanding authority.",{"name":82,"@type":73,"acceptedAnswer":83},"Why is the gate based on semantic effect rather than action name?",{"text":84,"@type":76},"Because relabeling an action can evade name-based checks; semantic-effect routing still detects prohibited outcomes and refuses actions whose combined effects exceed the authority ceiling.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,114,119,122,126,129,133],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":29,"slug":113},6,"Technology","technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":22,"slug":125},9,"Religion & Spirituality","religion-spirituality",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":127,"show_sort_weight":22,"slug":128},"World Cup","world-cup",{"id":130,"doc_module":4,"doc_module_name":46,"category_name":131,"show_sort_weight":130,"slug":132},10,"Lifestyle","lifestyle",{"id":134,"doc_module":4,"doc_module_name":46,"category_name":135,"show_sort_weight":106,"slug":136},19,"General","general"]