From Agent Failure Paths to Quantified Residual Risk: A Compositional Framework for Resilient Agentic AI
06:00 · July 22, 2026 · arXiv cs.AI RSS

Agentic AI is crossing trust boundaries faster than current risk models can represent. Existing approaches provide one of two partial views. They either describe failure mechanisms without producing a transferable residual-risk estimate, or they produce a risk estimate while treating the internal failure path as a black box. We couple those two views by proposing CPSAINT, a seven-layer integrity decomposition over Physical state, Sensors, Data, Compute, Actuators, Environment, and Time, paired with FRIESA-K, a residual-risk functional that maps each failure path to a quantified risk instance. FRIESA-K grounds the resistance term K in a controlled absorbing Markov model so that control effectiveness is derived from state dynamics rather than assigned as an informal score. The result is a concise mechanism-to magnitude pipeline for resilient agentic and embodied AI. We report governance observability through a separate additive penalty instead of inserting governance as a new variable in the resistance functional. We formalize structural composability linking valid failure paths to well-defined risk instances and show the framework on two contrasting scenarios a hard real-time warehouse robot and a governance-instrumented financial-services agent. Across both cases, the same layer grammar, variable semantics, and dynamic-resistance construction remain intact. Thus, we obtain a compact kernel that supports cross-domain reasoning, explicit assumptions, and quantitatively grounded formalism of composable trust.
Summary
The paper presents CPSAINT and FRIESA-K as a paired framework that links explicit structural descriptions of integrity failures in agentic and embodied systems to transferable residual-risk estimates. CPSAINT decomposes any such system into the same seven ordered layers—Physical state, Sensors, Data, Compute, Actuators, Environment, and Time—while defining a fixed propagation relation and a compact failure-mode alphabet. Valid attack or fault paths are expressed as sequences that cross these layers according to the architecture’s concrete interfaces, without altering the layer grammar itself when the domain changes.
FRIESA-K supplies the complementary quantitative layer. It maps each CPSAINT path to a risk instance by deriving a dynamic resistance term from a controlled absorbing Markov model. The model tracks the probability of reaching a designated catastrophe state within a finite, domain-specific horizon; control effectiveness therefore appears as a measurable reduction in absorption probability rather than an externally assigned score. Governance observability is handled outside the core functional as an additive penalty term, preserving a clean separation between operational risk and audit or oversight degradation.
A composition result shows that any valid CPSAINT path induces a well-defined FRIESA-K instance while leaving the functional form unchanged. The authors illustrate the pipeline on two materially different cases: a hard real-time warehouse robot whose horizon is measured in milliseconds and a governance-instrumented financial-services agent whose operational window is sub-second yet embedded in longer audit cycles. In both settings the same layer symbols, path semantics, and resistance construction apply directly, demonstrating that the framework supports cross-domain reasoning about path-dependent integrity loss without requiring domain-specific reformulation of the risk model.
Why it matters
Provides a novel, reproducible mechanism-to-magnitude framework for AI risk and resilience that aligns with EU emphasis on ethical, transparent, and quantifiable AI governance; directly applicable to Dutch research and advanced deployments in robotics and regulated sectors.








