A compromised enterprise AI agent does not look compromised. Agent Compromise Surface ACS = {I, T, M, O} formally decomposes the four distinct attack vectors. Agent Dwell Window formalizes the temporal gap and establishes why it is structurally longer for agents than for human intruders. Semantic Blast Radius is monotonically non-decreasing with dwell time and reducible only through permission minimization, not detection. Composite Adversarial Exposure aggregates all three into a board-level risk metric. Four-tier Agent Security Maturity Model with concrete organizational criteria. Demonstrates that NIST AI RMF, OWASP LLM Top 10, MITRE ATLAS, and ISO 42001 leave the temporal and spatial dimensions of agent compromise formally undefined.
Enterprise AI increasingly routes prompts across specialist models and aggregates their outputs, yet no governance standard defines what an auditable ensemble is. Model Ensemble Specification MES = (M, R, A, G) closes this gap. Routing Policy Gap names the structural condition where routing decisions are implicit and unlogged. Arbitration Collapse establishes that ensemble outputs are not attributable to any single model, requiring a six-component Ensemble Genealogy G_ens(o) that extends the Output Genealogy from AOGF-2026-004.
Regulatory frameworks mandate AI audit trails but none defines what information an audit trail must contain. Output Genealogy G(o) = (M, P, C, D_r, Theta) closes this gap: a 5-tuple capturing every condition necessary to audit an AI output. Provenance Opacity — the structural condition where a deployment cannot reconstruct G(o) — is the default state for most enterprise AI pilots. Retroactive Unverifiability proves reconstruction is architecturally impossible once time-varying components are lost.
Binary AI disclosure requirements are structurally insufficient for accountability: any binary function applied to a continuous authorship signal discards the information that governance requires. This paper introduces the Contribution Ratio (CR), a continuous [0,1] metric decomposed across three non-overlapping phases, and proves the Provenance Collapse Property showing why watermark compliance and authorship accountability require separate instruments.
Enterprise multi-agent deployments introduce a structural governance gap not addressed by any existing standard: the trust topology itself. This paper formalizes the Agent Trust Topology (ATT) as a directed acyclic graph, proves the Acyclicity Requirement as a necessary condition for governable delegation, and introduces Action Blast Radius (ABR) and Delegation Depth Limit (DDL) as the two instruments that bound operational risk in orchestrator-worker architectures.
Enterprise AI deployments have crossed a material accountability threshold: organizations are making consequential decisions through AI systems for which no identified principal bears legally or operationally defined accountability. This paper formalizes the AI Fiduciary Gap AIFG(D) as the set of deployments with no valid fiduciary principal, the Accountability Vacuum Index AVI = |AIFG(D)| / |D| as its computable measure, and Outcome Attribution Failure OAF(d, tau) as the mechanism perpetuating the gap. The Attribution Horizon result proves that attribution above a chain-length threshold is structurally intractable without pre-deployment instrumentation. The five-component AIFA architecture and four maturity tiers give organizations a path from unchecked fiduciary exposure to board-level accountability reporting.
Global enterprise AI spend exceeds $2.59 trillion yet fewer than one in three executives can name a specific financial outcome attributable to a specific deployment. This paper formalizes Token-Value Displacement TVD(t) = C(t) − V(t) as the signed divergence between AI consumption and registered value, introduces Value Opacity as the governance failure state where TVD is undefined, and defines Consumption Decoupling as the property binding spend to outcome at authorization time. The four-component AVAL architecture and four-tier maturity model give any organization a computable, auditable path from spend visibility to attestable financial accountability.
Autonomous AI agents execute tasks across enterprise systems using provisioned credentials that persist far beyond any single task scope, creating a novel attack surface no existing identity standard addresses. This paper formalizes the Agent Identity Envelope AIE(a) = (P, Δ, S, T, α) as a five-tuple binding principal, delegation lineage, scope, temporal bound, and attestation; introduces Authority Bleed AB(a,τ) = S(a) \ S_min(a,τ) as the quantifiable excess between provisioned and minimum required permissions; and proves the Delegation Chain Collapse result: any multi-hop delegation chain without per-hop scope re-specification is authorization-equivalent to a direct root-to-terminal grant.
Persistent AI memory without governance creates a silent failure mode: memory diverges from ground truth while appearing to function correctly, and retrieval systems compound rather than correct the divergence above a critical threshold. This paper formalizes Memory Drift D(M,t), Recall Boundary B: A×P×C×T → 2M, and Memory Provenance Chain Π(m), and introduces the Enterprise Memory Governance Framework across five components and four maturity tiers. Observation 1: the Stale Memory Amplification Property.
Multi-agent systems violate least-privilege by default: permissions increase through delegation without explicit scope bounds, creating Privilege Cascade. This paper introduces Trust Inheritance I(D,A,σ) = PD ∩ σ, Privilege Cascade as union-permission amplification, and Agent Trust Chain as a directed acyclic graph with scoped edges. Five MATGF components, four governance tiers, Observation 1: Trust Monotonicity Violation.
As autonomous AI agents execute multi-step actions across enterprise systems, governance frameworks designed for single-turn LLM calls are structurally insufficient. This paper introduces Action Blast Radius R(A), Agent Delegation Boundary B: P×C×X → 2Actions, and Reversibility Budget ρ(S). Five EAGF components, four maturity tiers, Observation 1: Agent Reasoning Trace Irreversibility Property.
Enterprise AI deployments lack the control plane that every prior infrastructure technology required before responsible large-scale operation became possible. This paper introduces the EACP: five components covering model routing, cost governance, audit and observability, access and policy enforcement, and failure and fallback orchestration. Four maturity tiers. Evaluated against NIST AI RMF 1.0 and EU AI Act.