AI News selected for Professionals and Decision Makers
Primary Research Stream

From Agent Failure Paths to Quantified Residual Risk: A Compositional Framework for Resilient Agentic AI

06:00 · July 22, 2026 · arXiv cs.AI RSS

From Agent Failure Paths to Quantified Residual Risk: A Compositional Framework for Resilient Agentic AI

Agentic AI is crossing trust boundaries faster than current risk models can represent. Existing approaches provide one of two partial views. They either describe failure mechanisms without producing a transferable residual-risk estimate, or they produce a risk estimate while treating the internal failure path as a black box. We couple those two views by proposing CPSAINT, a seven-layer integrity decomposition over Physical state, Sensors, Data, Compute, Actuators, Environment, and Time, paired with FRIESA-K, a residual-risk functional that maps each failure path to a quantified risk instance. FRIESA-K grounds the resistance term K in a controlled absorbing Markov model so that control effectiveness is derived from state dynamics rather than assigned as an informal score. The result is a concise mechanism-to magnitude pipeline for resilient agentic and embodied AI. We report governance observability through a separate additive penalty instead of inserting governance as a new variable in the resistance functional. We formalize structural composability linking valid failure paths to well-defined risk instances and show the framework on two contrasting scenarios a hard real-time warehouse robot and a governance-instrumented financial-services agent. Across both cases, the same layer grammar, variable semantics, and dynamic-resistance construction remain intact. Thus, we obtain a compact kernel that supports cross-domain reasoning, explicit assumptions, and quantitatively grounded formalism of composable trust.

Summary

The paper presents CPSAINT and FRIESA-K as a paired framework that links explicit structural descriptions of integrity failures in agentic and embodied systems to transferable residual-risk estimates. CPSAINT decomposes any such system into the same seven ordered layers—Physical state, Sensors, Data, Compute, Actuators, Environment, and Time—while defining a fixed propagation relation and a compact failure-mode alphabet. Valid attack or fault paths are expressed as sequences that cross these layers according to the architecture’s concrete interfaces, without altering the layer grammar itself when the domain changes.

FRIESA-K supplies the complementary quantitative layer. It maps each CPSAINT path to a risk instance by deriving a dynamic resistance term from a controlled absorbing Markov model. The model tracks the probability of reaching a designated catastrophe state within a finite, domain-specific horizon; control effectiveness therefore appears as a measurable reduction in absorption probability rather than an externally assigned score. Governance observability is handled outside the core functional as an additive penalty term, preserving a clean separation between operational risk and audit or oversight degradation.

A composition result shows that any valid CPSAINT path induces a well-defined FRIESA-K instance while leaving the functional form unchanged. The authors illustrate the pipeline on two materially different cases: a hard real-time warehouse robot whose horizon is measured in milliseconds and a governance-instrumented financial-services agent whose operational window is sub-second yet embedded in longer audit cycles. In both settings the same layer symbols, path semantics, and resistance construction apply directly, demonstrating that the framework supports cross-domain reasoning about path-dependent integrity loss without requiring domain-specific reformulation of the risk model.

Why it matters

Provides a novel, reproducible mechanism-to-magnitude framework for AI risk and resilience that aligns with EU emphasis on ethical, transparent, and quantifiable AI governance; directly applicable to Dutch research and advanced deployments in robotics and regulated sectors.

More in this beat
agent-safetyai-agentsCPSAINTcyber-physical-systemsembodied-agentsFRIESA-Kthreat-modeling
RIFT-Bench: Dynamic Red-teaming For Agentic AI Systems

06:00 · June 24, 2026

RIFT-Bench: Dynamic Red-teaming For Agentic AI Systems

This research is highly relevant for Dutch AI practitioners and researchers focusing on AI safety and compliance with the EU AI Act. RIFT-Bench provides a scalable, unified framework for red-teaming autonomous LLM agents, which is critical for deploying secure and trustworthy AI systems in enterprise environments.

Relevance 85 · Audience 95

Phishing 3.0: The Fight Moves to Agent Versus Agent

13:30 · August 19, 2026

Phishing 3.0: The Fight Moves to Agent Versus Agent

This article is highly relevant for security professionals as it highlights the emerging threat of AI-driven phishing agents. Dutch enterprises must adapt their cybersecurity strategies to counter AI-generated attacks, making this crucial for maintaining robust organizational security.

Relevance 85 · Audience 95

Agentao: A Governed Local-First Runtime for Tool-Using LLM Agents

06:00 · August 17, 2026

Agentao: A Governed Local-First Runtime for Tool-Using LLM Agents

Agentao's focus on runtime governance, auditability, and permission-mediated execution aligns strongly with the transparency and human-oversight requirements of the EU AI Act. Dutch AI researchers and engineers can leverage this open-source architecture to build compliant, secure, and inspectable local-first AI agents.

Relevance 85 · Audience 90

The Agent Access Model

15:00 · August 5, 2026

The Agent Access Model

Highly actionable reference architecture for Dutch security teams deploying AI agents under GDPR, EU AI Act, and national ethical-AI guidelines; addresses real enterprise risks with concrete controls that can be implemented on existing OAuth/DPoP/MCP standards.

Relevance 88 · Audience 95

SeerGuard: A Safety Framework for Mobile GUI Agents via World Model Prediction

06:00 · July 20, 2026

SeerGuard: A Safety Framework for Mobile GUI Agents via World Model Prediction

This research is highly relevant for Dutch AI researchers and developers focusing on agentic AI and AI safety. It aligns with the EU's stringent regulatory emphasis on safe, transparent, and risk-aware AI systems by offering a proactive mechanism to prevent harmful autonomous actions before they occur.

Relevance 85 · Audience 95

SPINE: Bridging the Cyber-Physical Gap with Agentic AI

06:00 · July 16, 2026

SPINE: Bridging the Cyber-Physical Gap with Agentic AI

This research is highly relevant for Dutch AI and robotics researchers, offering an open-source, agentic solution to accelerate Embodied AI deployment. Given the Netherlands' strong high-tech manufacturing and logistics sectors, reducing the friction of cyber-physical integration directly benefits local enterprise and academic labs.

Relevance 85 · Audience 95