Securing an Agent Is Two Questions, Not One.
Can it act here. And should it, right now.
Traditional identity and security controls help establish who may act and whether an action is allowed. KTP proposes an additional check: whether the action fits current environmental conditions. This overview explains the proposed gates, their limits, and implementation evidence.
§01the two gates
Securing an agent is not one question. It is two.
Can it act here?
Capacity and safety. Is the action authorized, is the environment stable enough to carry it.
Silent veto. When the action is riskier than the environment can hold, it becomes impossible. Record the reason and provide an appeal or repair path for the governing decision. Review does not make an unsafe action executable.
Should it act, right now?
Appropriateness. The action is authorized and safe, but is it the right thing for this moment.
De-automation, or a propriety veto. The wrong-for-the-moment action is held for a reason, a witness, or a co-sign. The hard cases are refused outright.
The first gate asks if the action is safe. The second asks if it is right.
§02the three-bucket frame
AI risk is not one problem. It is three different problems.
- Risk type
- Model risk
- Example
- hallucination, bias, unsafe output
- Best control
- evaluation, training, red teaming
- Risk type
- Governance risk
- Example
- accountability, policy, labor, compliance
- Best control
- oversight, law, process
- Risk type
- Motion risk
- Example
- agents acting, accessing, executing, exfiltrating
- Best control
- KTP
KTP is the control plane for motion risk.
§03the deeper master frame
KTP is not an AI risk taxonomy. It is a governability test. Most AI risk frameworks describe what can go wrong. KTP asks: can this failure be constrained at the moment of action?
- Risk physics
- Semantic risk
- What breaks
- The model says something wrong, biased, manipulative, misleading.
- KTP relevance
- Partial
- Risk physics
- Motion risk
- What breaks
- The system acts, accesses, executes, transfers, delegates, crosses boundaries.
- KTP relevance
- Very high
- Risk physics
- Institutional risk
- What breaks
- Governance, accountability, regulation, incentives, ownership.
- KTP relevance
- Low to medium
- Risk physics
- Social / ecological risk
- What breaks
- Labor, culture, inequality, environment, public trust.
- KTP relevance
- Low
- Risk physics
- Infrastructure risk
- What breaks
- Cyber, APIs, identity, data movement, cloud, tools.
- KTP relevance
- Very high
For boards, use 3 buckets. For architects, the 5-bucket version is sharper.
§04eleven mind-blowers
The model is not the main control point.
The dangerous moment is not when the AI thinks. It is when the AI acts. The control surface is not prompt to model to output. It is agent to tool to data to API to transaction to consequence. That reframes the entire investment thesis.
The dangerous moment is not when the AI thinks. The dangerous moment is when the AI acts.
AI risk collapses into motion risk.
The 1,612 risks look overwhelming until you ask one question. Does this risk require the AI system to move, act, access, delegate, transact, or cross a boundary? If yes, KTP has leverage. If no, it may be governance, society, economics, law, culture, or model-quality risk, but not primarily KTP risk. Clean enough to put in front of a board.
Does this risk require the AI system to move, act, access, delegate, transact, or cross a boundary?
KTP scores best on the risks security actually owns.
KTP does not score well on every AI risk. It scores well on the ones that become incidents: data exfiltration, credential abuse, tool misuse, unauthorized API calls, autonomous transactions, agentic cyberattacks, runaway workflows, multi-agent propagation, fraud automation, cross-boundary data movement.
KTP does not cover all AI risks. It covers the risks that turn into security events.
Zero Trust is incomplete for agents.
Zero Trust says never trust, always verify. In most architectures that still means verifying identity and access. KTP extends it twice: never trust an action just because the actor is trusted, and never run an authorized action just because it is allowed. Three questions, in order. Who is it. What is it about to do. And should it do that, right now.
Zero Trust verified who you are. KTP verifies what you are about to do, and whether you should.
The future firewall is the Tool Gateway.
The most important new choke point is not the perimeter. It is the Tool Gateway, the layer through which agents reach databases, browsers, APIs, shells, code execution, file systems, ticketing, payment, cloud consoles, MCP servers. This is the most concrete architectural breakthrough.
Every agent action goes through a policy-enforced tool gateway.
Governance becomes executable.
Most AI governance is paper: policies, principles, committees, risk assessments, checklists. KTP turns governance into runtime decisions: ALLOW / CONSTRAIN / VETO / ESCALATE / REVOKE.
KTP turns AI governance from a PDF into a control plane.
The silent veto is the killer concept.
People are used to humans approving or denying things. Machine-speed risk needs machine-speed denial. The silent veto says the environment blocks the action even if the agent tries to proceed. The agent does not need to be persuaded. The environment refuses to move. That is the heart of KTP.
Machine-speed risk requires machine-speed refusal.
The most dangerous AI risks are verbs, not nouns.
People classify AI risk by nouns: misinformation, privacy, bias, autonomy, cyber, fraud. KTP classifies by verbs: read, write, send, delete, execute, delegate, purchase, transfer, impersonate, escalate, exfiltrate. Security controls verbs.
AI risk becomes governable when you stop categorizing nouns and start controlling verbs.
The 1,612 risks reduce to about 10 enforcement patterns.
The MIT repository looks enormous. But for KTP-relevant risks, they collapse into repeatable patterns: data access, data export, tool execution, API invocation, credential use, delegation, transaction, external communication, multi-agent propagation, emergency stop or containment.
1,612 risks look impossible. The actionable subset collapses into a small number of enforcement patterns.
KTP gives CISOs permission to say not my risk.
Security teams are getting handed all AI risk. KTP creates a principled boundary. Security should own AI risks involving action, access, systems, tools, data movement, execution, and containment. Security should influence, but not fully own, labor displacement, cultural change, macroeconomic concentration, institutional governance, broad social harms.
KTP does not expand the CISO's job infinitely. It clarifies which AI risks security can actually control.
Authorized is not appropriate.
A comms agent is cleared to send the quarterly newsletter. The company announced layoffs an hour ago. Every permission is valid, the environment is calm, nothing is unsafe. Sending it is still the wrong thing to do. The first gate measures safety, and it is blind to whether the action fits the moment. Judging the fit is the job of the second gate, and almost no stack has one.
A security model that only measures safety cannot tell an allowed action from a right one.
§05noun to verb
AI risk becomes governable when it becomes grammatical. Subject, verb, object, context, consequence.
- Noun framing
- Privacy risk
- KTP framing
- Who is allowed to read, retrieve, summarize, export, or share this data?
- Noun framing
- Cyber risk
- KTP framing
- Who is allowed to scan, execute, escalate, or move laterally?
- Noun framing
- Fraud risk
- KTP framing
- Who is allowed to transact, transfer, approve, or impersonate?
- Noun framing
- Autonomy risk
- KTP framing
- Who is allowed to delegate, chain actions, or continue without review?
- Noun framing
- Misinformation risk
- KTP framing
- Who is allowed to publish, amplify, target, or automate distribution?
§06the sharpest lines
Same insight, four registers. The poetry stays in the title, the rigor lives in the architecture, and each line is pitched to the room it has to land in.
AI risk becomes operationally governable at the boundary between cognition and consequence. KTP lives at that boundary. It does not try to control every model output, belief, or latent intention. It controls the moment an autonomous system attempts to turn computation into motion: accessing data, invoking tools, crossing boundaries, delegating authority, executing workflows, or producing external effects. That is where trust must become physics.
We do not need to govern every thought an AI system has. We need to govern every consequential action it can take, and whether it should take that action right now.
KTP is a two-gate action plane for autonomous systems: a capacity gate that asks can it, and an appropriateness gate that asks should it.
KTP tells us which AI risks security can actually control, where to enforce those controls, and how to reduce blast radius at machine speed.
§07next doors
MIT maps a broad universe of AI risk. KTP identifies the subset of those risks that become technically governable at the moment of action. Its contribution is not that it solves every AI risk. Its contribution is that it translates abstract harms into enforceable motion: who or what is acting, what verb is being attempted, through which channel, against which object, under what context, with what blast radius, and with what right of veto. AI risk becomes governable when it becomes motion.