Preprint

Governance Is the Moat: An Agentic Authority Architecture for Enterprise AI in the Era of Autonomous Offensive Capability

April 2026
DOI: 10.13140/AGI.P2.2026

Authors:

Dr. Binod Kumar
Preprints and early-stage research may not have been peer reviewed yet.

Abstract

In April 2026, two frontier AI laboratories independently disclosed models capable of autonomous end-to-end compromise of simulated enterprise networks, autonomous discovery of zero-day vulnerabilities across every major operating system and browser, and working exploit generation at a cost of approximately fifty United States dollars per run. These disclosures, corroborated by independent evaluation from the United Kingdom AI Safety Institute, mark a qualitative inflection in the asymmetry between enterprise defenders and AI-enabled adversaries. This working paper argues that the resulting risk environment is inadequately addressed by existing enterprise security and AI governance frameworks taken in isolation, and that a composite architecture is required. We propose the Agentic Authority Architecture (AAA) Framework: a four-layer governance model spanning Identity, Authorization, Attestation, and Accountability, applied across three actor classes human principals, autonomous agents, and delegated capabilities. The framework is designed to extend the National Institute of Standards and Technology AI Risk Management Framework (NIST AI RMF 1.0 and the AI 600-1 Generative AI Profile), operationalize the CISA, NSA, and FBI joint guidance on secure AI integration, and provide enterprise boards with a measurable governance substrate for the autonomous agent era.

PDF

To read the file of this research, you can view or download it directly from our repository.