KYE Governed Research Rail™ · Deep Dive · Edition 2026-Q3
Adaptive AI Governance Needs a Runtime Authority Layer — Q3 2026 Edition
Ed25519-sealed · fingerprint 02051b076ddf2f6e · verify it yourself ↓
KYE Protocol™ governs actions and authorities, not outcomes, diagnoses, or results. This report synthesises public sources under the evidence / no-hallucination gate — every claim below is pinned to a cited source.
Executive tear-sheet
AI governance is converging on a single structural conclusion: written policy and pre-deployment assessment are necessary but not sufficient. As AI systems take actions — calling tools, moving money, releasing documents, deciding access — the governance question shifts from "is this model approved?" to "is this action authorised, right now, by whom, and with what evidence?" That question can only be answered at runtime. The major frameworks now in force each point at the same missing piece: a runtime authority layer that admits or refuses each action against current policy and emits tamper-evident evidence. This deep dive maps that convergence across NIST, the EU, OWASP, and ISO, and argues the layer is a distinct architectural primitive, not a feature of any one model.
Key findings
- The leading AI risk frameworks treat governance as a continuous function, not a one-time gate.
- Both the EU AI Act and ISO/IEC 42001 require runtime oversight, logging, and monitoring — obligations that bind while the system is in use, not only at design time.
- Agentic-AI security guidance independently arrives at runtime authority controls — least privilege per tool, explicit approval for destructive actions, just-in-time verification.
- The pattern already has a mature analogue: the zero-trust PDP/PEP split, applied to AI actions rather than network requests.
In the full report
- Governance is a continuous function, not a one-time gate
- The EU AI Act binds oversight and logging at runtime
- ISO/IEC 42001 demands operational control, continuously
- Agentic AI forces the question
- The mature analogue: zero-trust PDP/PEP, applied to actions
- Conclusion
Paid edition
Get the full report
This is the preview. 6 further sections of cited analysis remain in the full edition. The full edition is a paid KYE Governed Research Rail™ deliverable — every claim cited, the whole edition Ed25519-sealed and replay-verifiable.
Pinned sources
Every claim in the full edition is pinned to a cited public source (evidence gate); the 7 pinned sources are listed below. The full claim-by-claim map ships with the paid edition, sealed into evidence pack kye:evidence-pack:research:adaptive-ai-governance-runtime-authority:2026-q3.
- https://www.nist.gov/itl/ai-risk-management-framework — National Institute of Standards and Technology (retrieved 2026-06-03T12:30:00Z)
- https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence — National Institute of Standards and Technology (retrieved 2026-06-03T12:30:00Z)
- https://artificialintelligenceact.eu/article/14/ — EU Artificial Intelligence Act (artificialintelligenceact.eu) (retrieved 2026-06-03T12:30:00Z)
- https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng — Official Journal of the European Union (EUR-Lex) (retrieved 2026-06-03T12:30:00Z)
- https://genai.owasp.org/2025/12/09/owasp-top-10-for-agentic-applications-the-benchmark-for-agentic-security-in-the-age-of-autonomous-ai/ — OWASP GenAI Security Project (retrieved 2026-06-03T12:30:00Z)
- https://www.nist.gov/publications/zero-trust-architecture — National Institute of Standards and Technology (retrieved 2026-06-03T12:30:00Z)
- https://www.iso.org/standard/42001 — International Organization for Standardization (retrieved 2026-06-03T12:30:00Z)
Replay-verifiable
This edition is sealed and Ed25519-signed over the published keys. Any reader can confirm the seal offline — no KYE™ service required.
- Signature algorithm
EdDSA- Key id
kye:key:self-audit-fixture-2026-06- Seal fingerprint
02051b076ddf2f6e(sha256 of the signature, first 16 hex)- Published keys (JWKS)
/trust/self-audit-jwks.json- Report envelope
kye:research-report:adaptive-ai-governance-runtime-authority-2026-q3· schemakye.research_report.v1
Verify it yourself: fetch the published JWKS, recompute the Ed25519 signature over this edition's canonicalised envelope (minus seal) bound to the body hash, and confirm it matches the key id above — from public keys alone, no KYE™ service in the loop.