Intrusion Prevention for Agentic Processes:
Evidence-Governed Runtime Response and Enforcement

Arslan Brömme

Abstract

Agentic systems can execute tools, retain state, delegate authority, propagate information, and act across organizational boundaries. A security-relevant finding may therefore require intervention, while direct detector-to-block coupling can turn uncertain evidence into harmful enforcement.

This paper proposes an Agentic-Process Intrusion Prevention System (A-IPS), a conceptual, evidence-governed intervention model for agentic processes. A-IPS composes bounded findings with a versioned response policy while keeping evidence support, policy-relative evidence sufficiency, admissibility, authorization, execution, scoped effect, and recovery validity distinct. Existing enforcement mechanisms can serve as policy-controlled intervention points rather than being replaced.

Agentic-process-specific response targets and dependencies include process branches, delegated authority, information and persistent state, propagation paths, cross-domain relationships, resource budgets, and recovery artifacts. The same governance interface can optionally represent proactive resilience hardening as preventive posture control, but such control remains risk reduction rather than an incident finding or proof of trust. The prevention plane is itself treated as an attack surface.

A-IPS is a conceptual architecture and does not claim a new incident-response lifecycle, runtime-enforcement primitive, universally correct policy, empirically validated prevention mechanism, or proof that successful response establishes an uncompromised agent state.

Key concepts

  • Bounded security findings
  • Policy-relative evidence sufficiency
  • Admissibility separated from authorization
  • Authorization separated from execution
  • Scoped effect verification
  • Recovery validity
  • Agentic-process-specific containment and intervention targets
  • Prevention plane as an attack surface

Keywords

Agentic AI · AI Agents · Agentic Processes · Intrusion Prevention · Cybersecurity · AI Security · Runtime Security · Security Governance · Multi-Agent Systems · Incident Response · Evidence-Governed Security

Citation

Brömme, Arslan (2026). Intrusion Prevention for Agentic Processes: Evidence-Governed Runtime Response and Enforcement. Version v0.9.1.4. Zenodo. DOI: 10.5281/zenodo.22765147.

BibTeX

@misc{broemme2026aips,
  author       = {Arslan Brömme},
  title        = {Intrusion Prevention for Agentic Processes:
                  Evidence-Governed Runtime Response and Enforcement},
  year         = {2026},
  month        = sep,
  version      = {v0.9.1.4},
  publisher    = {Zenodo},
  doi          = {10.5281/zenodo.22765147},
  url          = {https://doi.org/10.5281/zenodo.22765147}
}