KTP/
github ↗
created 24 August 2026 · last modified 6 September 2026
the enterprise ecosystem

Securing an Agent Is Two Questions, Not One.

Can it act here. And should it, right now.

Traditional identity and security controls help establish who may act and whether an action is allowed. KTP proposes an additional check: whether the action fits current environmental conditions. This overview explains the proposed gates, their limits, and implementation evidence.

§01the two gates

Securing an agent is not one question. It is two.

the can gate

Can it act here?

A ≤ E

Capacity and safety. Is the action authorized, is the environment stable enough to carry it.

Silent veto. When the action is riskier than the environment can hold, it becomes impossible. Record the reason and provide an appeal or repair path for the governing decision. Review does not make an unsafe action executable.

Existing identity, authorization, and security controls address parts of this question. Coverage depends on the product, configuration, and deployment.
the should gate

Should it act, right now?

W ≤ J

Appropriateness. The action is authorized and safe, but is it the right thing for this moment.

De-automation, or a propriety veto. The wrong-for-the-moment action is held for a reason, a witness, or a co-sign. The hard cases are refused outright.

KTP proposes a context-aware authorization layer. A dated comparison is needed to establish which existing controls cover parts of this role.

The first gate asks if the action is safe. The second asks if it is right.

§02the three-bucket frame

AI risk is not one problem. It is three different problems.

Risk type
Model risk
Example
hallucination, bias, unsafe output
Best control
evaluation, training, red teaming
Risk type
Governance risk
Example
accountability, policy, labor, compliance
Best control
oversight, law, process
Risk type
Motion risk
Example
agents acting, accessing, executing, exfiltrating
Best control
KTP

KTP is the control plane for motion risk.

§03the deeper master frame

KTP is not an AI risk taxonomy. It is a governability test. Most AI risk frameworks describe what can go wrong. KTP asks: can this failure be constrained at the moment of action?

Risk physics
Semantic risk
What breaks
The model says something wrong, biased, manipulative, misleading.
KTP relevance
Partial
Risk physics
Motion risk
What breaks
The system acts, accesses, executes, transfers, delegates, crosses boundaries.
KTP relevance
Very high
Risk physics
Institutional risk
What breaks
Governance, accountability, regulation, incentives, ownership.
KTP relevance
Low to medium
Risk physics
Social / ecological risk
What breaks
Labor, culture, inequality, environment, public trust.
KTP relevance
Low
Risk physics
Infrastructure risk
What breaks
Cyber, APIs, identity, data movement, cloud, tools.
KTP relevance
Very high

For boards, use 3 buckets. For architects, the 5-bucket version is sharper.

§04eleven mind-blowers

01

The model is not the main control point.

The dangerous moment is not when the AI thinks. It is when the AI acts. The control surface is not prompt to model to output. It is agent to tool to data to API to transaction to consequence. That reframes the entire investment thesis.

The dangerous moment is not when the AI thinks. The dangerous moment is when the AI acts.
02

AI risk collapses into motion risk.

The 1,612 risks look overwhelming until you ask one question. Does this risk require the AI system to move, act, access, delegate, transact, or cross a boundary? If yes, KTP has leverage. If no, it may be governance, society, economics, law, culture, or model-quality risk, but not primarily KTP risk. Clean enough to put in front of a board.

Does this risk require the AI system to move, act, access, delegate, transact, or cross a boundary?
03

KTP scores best on the risks security actually owns.

KTP does not score well on every AI risk. It scores well on the ones that become incidents: data exfiltration, credential abuse, tool misuse, unauthorized API calls, autonomous transactions, agentic cyberattacks, runaway workflows, multi-agent propagation, fraud automation, cross-boundary data movement.

KTP does not cover all AI risks. It covers the risks that turn into security events.
04

Zero Trust is incomplete for agents.

Zero Trust says never trust, always verify. In most architectures that still means verifying identity and access. KTP extends it twice: never trust an action just because the actor is trusted, and never run an authorized action just because it is allowed. Three questions, in order. Who is it. What is it about to do. And should it do that, right now.

Zero Trust verified who you are. KTP verifies what you are about to do, and whether you should.
05

The future firewall is the Tool Gateway.

The most important new choke point is not the perimeter. It is the Tool Gateway, the layer through which agents reach databases, browsers, APIs, shells, code execution, file systems, ticketing, payment, cloud consoles, MCP servers. This is the most concrete architectural breakthrough.

Every agent action goes through a policy-enforced tool gateway.
06

Governance becomes executable.

Most AI governance is paper: policies, principles, committees, risk assessments, checklists. KTP turns governance into runtime decisions: ALLOW / CONSTRAIN / VETO / ESCALATE / REVOKE.

KTP turns AI governance from a PDF into a control plane.
07

The silent veto is the killer concept.

People are used to humans approving or denying things. Machine-speed risk needs machine-speed denial. The silent veto says the environment blocks the action even if the agent tries to proceed. The agent does not need to be persuaded. The environment refuses to move. That is the heart of KTP.

Machine-speed risk requires machine-speed refusal.
08

The most dangerous AI risks are verbs, not nouns.

People classify AI risk by nouns: misinformation, privacy, bias, autonomy, cyber, fraud. KTP classifies by verbs: read, write, send, delete, execute, delegate, purchase, transfer, impersonate, escalate, exfiltrate. Security controls verbs.

AI risk becomes governable when you stop categorizing nouns and start controlling verbs.
09

The 1,612 risks reduce to about 10 enforcement patterns.

The MIT repository looks enormous. But for KTP-relevant risks, they collapse into repeatable patterns: data access, data export, tool execution, API invocation, credential use, delegation, transaction, external communication, multi-agent propagation, emergency stop or containment.

1,612 risks look impossible. The actionable subset collapses into a small number of enforcement patterns.
10

KTP gives CISOs permission to say not my risk.

Security teams are getting handed all AI risk. KTP creates a principled boundary. Security should own AI risks involving action, access, systems, tools, data movement, execution, and containment. Security should influence, but not fully own, labor displacement, cultural change, macroeconomic concentration, institutional governance, broad social harms.

KTP does not expand the CISO's job infinitely. It clarifies which AI risks security can actually control.
11

Authorized is not appropriate.

A comms agent is cleared to send the quarterly newsletter. The company announced layoffs an hour ago. Every permission is valid, the environment is calm, nothing is unsafe. Sending it is still the wrong thing to do. The first gate measures safety, and it is blind to whether the action fits the moment. Judging the fit is the job of the second gate, and almost no stack has one.

A security model that only measures safety cannot tell an allowed action from a right one.

§05noun to verb

AI risk becomes governable when it becomes grammatical. Subject, verb, object, context, consequence.

Noun framing
Privacy risk
KTP framing
Who is allowed to read, retrieve, summarize, export, or share this data?
Noun framing
Cyber risk
KTP framing
Who is allowed to scan, execute, escalate, or move laterally?
Noun framing
Fraud risk
KTP framing
Who is allowed to transact, transfer, approve, or impersonate?
Noun framing
Autonomy risk
KTP framing
Who is allowed to delegate, chain actions, or continue without review?
Noun framing
Misinformation risk
KTP framing
Who is allowed to publish, amplify, target, or automate distribution?

§06the sharpest lines

Same insight, four registers. The poetry stays in the title, the rigor lives in the architecture, and each line is pitched to the room it has to land in.

essay-grade

AI risk becomes operationally governable at the boundary between cognition and consequence. KTP lives at that boundary. It does not try to control every model output, belief, or latent intention. It controls the moment an autonomous system attempts to turn computation into motion: accessing data, invoking tools, crossing boundaries, delegating authority, executing workflows, or producing external effects. That is where trust must become physics.

board-grade

We do not need to govern every thought an AI system has. We need to govern every consequential action it can take, and whether it should take that action right now.

architect-grade

KTP is a two-gate action plane for autonomous systems: a capacity gate that asks can it, and an appropriateness gate that asks should it.

ciso-grade

KTP tells us which AI risks security can actually control, where to enforce those controls, and how to reduce blast radius at machine speed.

§07next doors

the data

Risks

1,612 MIT AI risks scored against KTP. Heat map, sortable matrix, distributions, scenario cards.

the technical

Architecture

Ten control sets. PDP/PEP reference. The seven enforcement surfaces. The verb library and the action tuple.

the rollout

Roadmap

Five phases: Visibility, Soft controls, Guardrails, Full enforcement, Appropriateness governance. The Tool Gateway as the headline.

the translation

CISO

Eleven reasons in CISO terms. The not-my-risk boundary. The board-ready narrative.

the credibility close

Methods

Provenance, limitations, failure modes. The governability ladder. The bounded public claim.

for the reader who does not want to be sold to

Skeptical

Concession first. Then the bounded claim. Nine objections, answered.

the field map

Defense Map

KTP located on the field's own coordinate system. Seven canonical frameworks, six primitives, the contradictions left in.

the blind spot

Home Grown

Governing the agents that never went through the front door. Composite intent, embedded vendor agents, and the Declare/Emit/Accept conformance seam.

the canonical closer

MIT maps a broad universe of AI risk. KTP identifies the subset of those risks that become technically governable at the moment of action. Its contribution is not that it solves every AI risk. Its contribution is that it translates abstract harms into enforceable motion: who or what is acting, what verb is being attempted, through which channel, against which object, under what context, with what blast radius, and with what right of veto. AI risk becomes governable when it becomes motion.

How to cite
APA 7th ed.

Perkins, C. (2026, May 6). Enterprise. Kinetic Trust Protocol. https://kinetic-trust-protocol.net/enterprise
Plain text

Chris Perkins, "Enterprise," Kinetic Trust Protocol, https://kinetic-trust-protocol.net/enterprise (accessed May 6, 2026).

Phase B build, May 2026. Sub-pages above. Source: MIT AI Risk Repository v0.2 + KTP-RPT v0.2 (1,612 risks scored).

Theoretical foundation — the proof · how it is built.