Is this real, or another AI governance metaphor?
Fair question. Most of the answer should be: try to break it. The rest of this page is what you'd want before deciding whether the framework deserves your time.
§01the concession
KTP should not be read as a theory of all AI risk. It does not solve alignment, prevent every misuse, or eliminate the social, economic, legal, and epistemic risks created by AI. Its claim is narrower: when an AI system, agent, workflow, or delegated process attempts to act, that action can be evaluated as motion. At that point, risk becomes more than a category. It becomes an enforceable event.
That paragraph is the load-bearing one. If you don't accept it, the rest of the page won't help. If you do, keep reading.
§02nine objections you're probably forming right now
These are fair. Listed in roughly the order they tend to surface. The honest answer is one or two sentences. If we dodge, that's on us.
“Isn't this just Zero Trust with a new coat of paint?”
No. Zero Trust verifies who you are and whether you can access something. KTP verifies what you are about to do, on what object, at what speed, with what blast radius. Zero Trust controls access. KTP controls consequence. KTP sits on top of Zero Trust, not next to it.
“Isn't this ABAC / PBAC / IAM / SOAR / DLP with new vocabulary?”
Those control identities, attributes, policies, response workflows, and data movement. KTP composes them around a unit they were not built for: an attempted action by an autonomous agent under context. The plumbing is familiar. The unit of governance is new.
“Not all AI risk is action-based. What about bias, labor displacement, training data?”
Correct. Most of those risks are not motion risks. The MIT scoring puts roughly half the risk universe outside KTP's direct scope. KTP governs the action layer. Other layers need other instruments. We say so on every page.
“Verbs alone are too simplistic. Read by itself isn't a control.”
Also correct. The unit of evaluation is not the verb. It is the tuple: agent, verb, object, channel, context, consequence, constraint. Verbs expose the control surface. Context determines the constraint. The verb library is the index, not the policy.
“How does this work outside a controlled enterprise environment?”
It mostly doesn't, yet. KTP assumes a runtime where actions can be intercepted at a tool gateway, API, identity layer, or egress point. On the open internet, against unmanaged agents, the enforcement surface shrinks to whatever your edge controls. Honest answer: enterprise first, federation later.
“What does 'governable' actually mean? That word is doing a lot of work.”
It is. We define it as a ladder: not visible, observable, attributable, constrainable, interruptible, reversible, pre-authorized. KTP doesn't promise that every risk becomes preventable. It claims to move risks up that ladder. The governability ladder lives at methods; see §03 here for the term sheet.
“Is KTP a protocol, a model, a policy framework, or a product?”
It is a control methodology with a reference architecture and a small vocabulary. Not a product. Not a model. Not a single protocol. The artifacts are: a decision function, an action tuple, a verb library, a set of enforcement surfaces, a governability ladder. Anyone can implement it. Nobody owns it.
“Where is the empirical evidence?”
Thin, on purpose. The v0.2 MIT Scorecard is a deterministic first-pass review expansion, not human adjudication or empirical validation. The 337 generated test cases have not been run against a prototype. We say this on /enterprise/methods. v0.3 is where evidence starts. Today is positioning and architecture.
“The should gate is just un-instrumented telemetry. Wire up an HR feed and 'there was a layoff' becomes a signal like any other.”
Half right. Instrumentation gives you the fact, layoff = true. It never gives you the mapping, therefore the cheerful newsletter is cruel. Stability signals are the constraint directly; the layoff signal is not, and turning a fact into fittingness needs a model that holds norms. Fully instrumented, you still need that model. That residual is exactly why the normative layer is a separate thing, not a SIEM feature. And yes, the should gate is earlier-stage than the can gate. We say so.
§03tight definitions (skeptic-safe)
If any of these terms doesn't survive a definition you can defend in front of a hostile architect, the framework hasn't earned them.
The veto definition is essential. KTP is not saying “ask the model to behave.” It is saying: do not let the model's cooperation be the control boundary.
§04what KTP is not (the disclaimer block)
- KTP solves AI risk.
- KTP is the answer.
- KTP governs the universe of AI risk.
- KTP makes AI safe.
- KTP is mind-blowing.
- a control methodology
- a bounded contribution
- the action layer of AI risk
- technically governable subset
- enforcement surface
- translation layer between taxonomy and control
The idea may be mind-blowing. The artifact should not say so.
§05the relationship to existing controls
The skeptic is already thinking it. We already have IAM, ABAC, SOAR, DLP, eBPF, ISE, Umbrella, EDR, CASB, DSPM, identity providers, network segmentation, approval workflows, and a decade of telemetry. None of those are wrong. None of those are going away. The honest question is not whether KTP replaces them. It is whether they are enough on their own when the actor is an autonomous agent acting at machine speed against systems they were never identity-bound to.
The answer is no, but barely. The existing stack does most of the work. What's missing is the layer that composes it around the unit that matters in agentic AI: an attempted action, evaluated under context, against an object, with a known blast radius and a real right of veto.
KTP is not a replacement for existing controls. It is a way to compose them around the unit that matters most in agentic AI: attempted action under context.
§06the seven-step skeptic walkthrough
If you read in this order, the framework reads like a serious proposal. Read in any other order and it reads like a pitch. The sequence matters more than the slogans.
- 01ConcessionStart by admitting KTP doesn't solve all AI risk. Skip this and the rest sounds like a manifesto.
- 02DefinitionDefine KTP narrowly: a methodology that governs attempted motion, not thought, output, or intent.
- 03TranslationConvert noun-shaped risks (privacy, fraud, autonomy) into verb-shaped controls (read, transact, delegate).
- 04ArchitectureMap the verbs to enforcement points you already operate: tool gateway, API gateway, identity, egress, transaction.
- 05MethodologyFor each risk: name the action, the context, the blast radius, and where the veto lives.
- 06EvidenceUse the MIT taxonomy as an external stress test. Score honestly. Tag the risks KTP cannot reach.
- 07Claim disciplineSort risks into directly governable, partially governable, observable, or out of scope. Refuse to overclaim.
§07the line you can use against us
KTP does not claim that all AI risk is motion. It claims that when AI risk becomes motion, governance finally has something to hold onto.
Quote it back at us if we ever drift. That is the bound.
§08if you still think it's nonsense
Reasonable. Here are the productive routes.
- What would refute the framework. Written before the critique arrives.
- The v0.2 limitations, stated in the project's own words.
- Email the authorDirect line. The address is on /about. Hostile readings welcome.
- Write a hostile critiquePublish it. Send the link. The framework's last several iterations came out of pressure-tests we did not invite.
The framework's posture is “critique becomes fuel rather than threat.” Test it.