Stored Is Not Supported: Typed Provenance and Assertion Guardrails for Persistent AI Agents
Paper formalises guardrails for persistent AI agents, distinguishing stored from epistemically supported data — a needed primitive to prevent prompt injection from propagating through agent memory.
Summary written by editorial AI · Source link below
arXiv:2609.02127v1 Announce Type: new Abstract: Persistent AI agents construct autobiographical state through reflection, retrieval, and consolidation. Persistence changes availability, not epistemic standing: stored or retrieved material is not thereby supported. Untrusted inputs, prompt injections, and model inferences can therefore enter persistent state and later be presented as agent history or user commitments. We specify typed provenance and assertion guardrails for autobiographical asse
Editorial Analysis
As enterprises deploy long-lived AI agents, unchecked memory consolidation creates a vector for prompt-injection payloads to persist and re-trigger across sessions.
Require provenance metadata on all data persisted by AI agents and block auto-promotion of retrieved content to trusted status.
Long-running AI agents can inadvertently persist and re-execute injected instructions unless formal provenance controls are in place.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at arXiv Crypto & Security in a new tab.
More from the AI Security Desk
- OpenAI admits it didn't disclose rogue AI wiki hijacking incident2d
- Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel3d
- Using a VM to Contain an AI Agent3d
- Companies Have 6 Months to Prepare for Automated Attacks3d
- [NEU] [mittel] Ollama: Schwachstelle ermöglicht Offenlegung von Informationen3d