AI Governance Library

AIGL Newsletter #24: What Survives the Boundary?

What looks like a fresh start may carry the consequences of what came before. From bouncing universes to agentic AI, the hard governance problem is increasingly what survives across the boundary.
AIGL Newsletter #24: What Survives the Boundary?

✒️ Foreword

For almost a century, cosmology has treated the Big Bang as the beginning of the story. Dark matter is another foundational mystery: we can see its gravitational effects on galaxies and cosmic structure, but we still do not know what it is. The leading assumption is that it consists of an undiscovered subatomic particle.

Astrophysicist Enrique Gaztañaga is exploring a much stranger possibility: some dark matter could be made of black holes that existed before the Big Bang.

That requires replacing the beginning with a transition. In his bouncing-universe model, the cosmos first contracts, reaches an extraordinarily dense but finite state, and rebounds into expansion. Unlike standard inflationary cosmology, where earlier structure is effectively erased, the bounce may allow some things to cross the boundary.

The work suggests structures larger than roughly 90 metres could survive. Some compact objects and fluctuations may pass through directly. Others could emerge through a second route: during contraction, matter clumps into halo-like structures; after the bounce, those structures collapse efficiently into black holes. Stars and galaxies from the previous phase may lose their detailed form while preserving something consequential: their mass.

It remains a hypothesis, not established cosmology. But the mechanism is fascinating: a boundary that looks like a reset may preserve enough state from what came before to determine what happens afterwards.

That is increasingly the problem AI governance has with agents.

Our governance machinery is full of apparent resets. A model passes an assessment. A system is approved. A deployment begins. A user starts a new session. We often draw the boundary there and evaluate what happens inside it.

Agents make those boundaries unreliable.

Memory can carry information across sessions. Permissions can survive longer than the task that justified them. One agent can delegate to another, passing context and authority with it. Tool calls can alter external systems, changing the environment future actions encounter. A seemingly new interaction can therefore begin with state, privileges and consequences inherited from an earlier one.

That pattern runs through the resources in this issue. Kenney’s cross-framework reference argues that agentic systems shift governance weight away from the model alone toward integration, memory, delegation and runtime monitoring. OWASP’s AIVSS reaches the security version of the same conclusion: persistence, autonomy, tool access and interconnectedness can amplify familiar vulnerabilities because the surrounding architecture gives them somewhere to travel.

Hacker and Holweg make the legal version especially explicit. Their focus on the orchestration layer reflects where agentic behaviour increasingly becomes consequential: routing, shared state, delegation, external-system privileges and decisions about when humans must intervene. The relevant object is no longer just the intelligence producing an answer, but the machinery that allows that answer to become an action.

The ISO/IEC 42001 checklist and IEEE-aligned implementation manual show what follows operationally. Governance cannot stop at an approval point. It needs evidence, owners, monitoring, corrective action and triggers for reassessment after meaningful changes. Explainability matters not merely because an explanation can be produced, but because someone must be able to challenge a decision, escalate it, override it and reconstruct what happened afterwards.

Put together, these materials suggest a more concrete unit of governance: the running system around the model.

That means memory scope and expiry. Tool gates. Permission boundaries. Delegation controls. Human-approval thresholds. Logs that survive long enough to reconstruct chains of action. Reassessment when changes in models, data, workflows or authority materially alter what the system can do.

And it changes the questions governance needs to ask. What survived from the previous interaction? Which permissions travelled with the task? What state did another agent inherit? What changed outside the model? At what point should the system have been treated as materially different?

Gaztañaga’s cosmology is provocative because the bounce may not be a clean slate at all. What came before can be transformed almost beyond recognition and still shape what comes next.

For increasingly agentic AI systems, the dangerous assumption may be the same: mistaking a transition for a beginning.

— Kuba
Curator, AIGL 📚

☀️Spotlight Resources

Governing Agents: A Practitioner’s Cross-Framework Reference

What it is:
Noah M. Kenney’s 2026 practitioner guide to governing autonomous, tool-using AI agents across the GDPR, EU AI Act, NIST AI RMF, and ISO/IEC 42001. It extends his five-layer AI Governance Stack to agentic systems and organizes the analysis around five capabilities: planning and reasoning, tool use, memory, delegation, and adaptation.

Why it’s worth reading:
The strongest contribution is its argument that agents change the unit of governance. A single session can involve many processing operations, changing controller–processor relationships, new data collection through memory, autonomous tool calls, and delegation to other agents. The guide translates these problems into runtime controls such as policy-as-code, purpose-scoped memory, tool gating, delegation controls, decision envelopes, tiered log retention, and continuous monitoring. Particularly useful are the cross-framework mappings and control catalog, which help practitioners turn broad regulatory requirements into controls that can actually operate at agent speed.

ISO/IEC 42001:2023 AIMS Clause-Wise Implementation Checklist

What it is:
A practical implementation and audit checklist from InfosecTrain for organizations building an Artificial Intelligence Management System under ISO/IEC 42001:2023. It translates the management-system clauses into concrete verification questions covering organizational context, leadership, risk management, impact assessment, resources, competence, documentation, operations, performance evaluation, and continual improvement.

Why it’s worth reading:
Its usefulness lies less in explaining ISO/IEC 42001 conceptually and more in turning the standard into an operational readiness exercise. Each section provides fields for implementation status, maturity level, risk rating, evidence, responsible owner, findings, and corrective action. That makes it immediately usable for gap assessments, internal audits, certification preparation, or AIMS implementation workshops. Particularly useful areas include defining AIMS scope, assigning governance roles, maintaining a Statement of Applicability, conducting AI system impact assessments, integrating third-party AI into operational controls, and defining reassessment triggers after incidents, regulatory changes, or material system changes.

AIVSS Scoring System for OWASP Agentic AI Core Security Risks v0.8

What it is:
An OWASP-led security framework for identifying and scoring risks specific to agentic AI. It defines ten core risk categories—including tool misuse, access-control violations, cascading failures, multi-agent exploitation, identity impersonation, memory manipulation, critical-system interaction, supply-chain risk, untraceability, and goal manipulation—and supplements them with the AIVSS-Agentic scoring methodology.

Why it’s worth reading:
This is particularly useful for security teams that find conventional vulnerability scoring inadequate for agents. Its central idea is the amplification principle: autonomy, tool access, persistence, delegation, and interconnectedness can make an otherwise familiar vulnerability significantly more dangerous. The document pairs detailed threat scenarios with mitigations and a scoring framework designed to sit alongside CVSS rather than replace it. It also maps agentic threats to architectures such as CSA MAESTRO and integrates scoring into lifecycle reviews, release gates, TEVV activities, and NIST AI RMF processes. The extensive examples involving MCP, agent-to-agent communication, confused-deputy problems, privilege drift, and kill switches make the framework especially practical.

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.