Back to featured projects

A little more of the work

Fault Propagation and Risk Containment in Agentic AI Systems

A systems framework for understanding how a local reasoning, tool, or authorization fault can travel through an agent's action loop, and where containment should stop it.

Liz's Library
Back to research

Working paper

Inside the folder

Author

Authored working paper · 2026

Agent securityFault propagationBlast radiusRisk containment

Description

A systems framework for understanding how a local reasoning, tool, or authorization fault can travel through an agent's action loop, and where containment should stop it.

Working paper; proposed evaluation protocol

The research question

How far can a local fault travel through an agentic system before the system detects and contains it?

My contribution

  • Defined Agentic Fault Propagation across perception, reasoning, planning, tool selection, authorization, execution, observation, and replanning
  • Introduced Agentic Blast Radius to describe the consequential impact possible before containment or human intervention
  • Developed a fault taxonomy, layered containment architecture, and an empirical evaluation protocol

Outcomes & evidence

  • A four-part framework: fault lifecycle, propagation graph, blast-radius model, and layered containment
  • Proposed controls spanning least-privilege authorization, deterministic policy enforcement, validation, approval, monitoring, logging, and recovery
  • An evaluation protocol for agent benchmarks and controlled tool environments, rather than claimed experimental results

Approach & methods

  • Modeled the agent action loop as a sequence of stages where a fault can be transmitted or amplified.
  • Built on tool-using language models, agent evaluation, prompt injection, least privilege, and AI risk-management work to organize a fault taxonomy.
  • Proposed containment through stage-level checks, trust boundaries around external content, independent approval for high-impact actions, and provenance-aware runtime monitoring.
  • Specified how an empirical evaluation could use agent benchmarks and controlled tool environments to test fault propagation and containment.

Scope & limitations

  • The paper explicitly does not claim experimental results.
  • The proposed containment controls and evaluation protocol should not be read as demonstrated production protection or measured benchmark performance.

Sources & project links

Folder openWorking paper