Skip to content
#explainable ai Open access

Shift Intent Left: Intent Contracts, Agency Budgets, and Drift Verification for Securing the Agentic Software Development Lifecycle

Sep 2026 · Zenodo (CERN European Organization for Nuclear Research)

Abstract

“Shift left” moved security activities toward the earliest artifact of the software development lifecycle (SDLC): source code. Autonomous coding agents invalidate the premise that code is that earliest artifact. An agent equipped with a shell, a package manager, credentials, and tool connectors performs security-relevant actions — installing dependencies, reading secrets, calling external services — before any diff exists for a scanner or reviewer to inspect. Its behaviour is also steered by natural-language context (task descriptions, rules files, tool descriptions, issue text) that conventional pipelines neither version nor verify. We argue that in an agentic SDLC the earliest securable artifact is intent: the declared goal, scope, context, and authority under which an agent operates. We introduce Shift Intent Left (SIL), a lifecycle discipline that makes intent explicit, bounded, and verifiable before execution and checks execution against it afterwards. Shift Intent Left is the successor to shift left for agentic development: where shift left asks “what is in the code?” as early as possible, Shift Intent Left asks “what was the agent authorised to do?” before it acts. We contribute: the Shift Intent Left principle and its definition; a formal model comprising Intent Contracts, Agency Budgets, an admissibility predicate over agent actions, and a severity-weighted Intent Drift metric; a five-stage lifecycle (Declare, Budget, Sanitise, Verify, Learn) with a reference architecture; a threat model mapping four adversary classes to SIL controls, including the under-specified principal; a mapping of SIL onto NIST SSDF, OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications (ASI01–ASI10), NIST AI RMF, Zero Trust, and software supply-chain attestation (in-toto, SLSA); four falsifiable hypotheses, each with a full experimental design and explicit refutation criteria. SIL complements, rather than replaces, shift-left, shift-right, and runtime agent-security mechanisms: it supplies the reference specification those mechanisms currently lack. The appendices assume no background in formal methods. They provide a notation primer explaining every symbol used, a step-by-step expansion of the bounded-delegation proof, a fully worked example computing Intent Drift by hand for both an attacked and a benign run, and answers to recurring questions. Status. This is a conceptual and architectural contribution. It reports no empirical results; it specifies the experiments that would confirm or refute its claims. An empirical evaluation of Hypothesis H2 (Intent Drift as a detection signal under indirect prompt injection) is planned and will be published as a new version of this record. Supplementary material. The Intent Contract JSON Schema, a validator enforcing the invariants that JSON Schema cannot express, and example contracts are available at https://github.com/AnimeshShaw/Shift-Intent-Left.

View source

Similar papers

#artificial intelligence Conference Open access Apr 2020

ECCOLA - a Method for Implementing Ethically Aligned AI Systems

The method, ECCOLA, is presented, which aims at making the high-level AI ethics principles more practical, making it possible for developers to more easily implement them in practice.

Ville Vakkuri, Kai-Kristian Kemell, P. Abrahamsson · 64 citations · ⚡6
#computer vision Review Apr 2024

AI-powered Code Review with LLMs: Early Results

The goal is to not only refine the accuracy of the LLM-based tool but also to underscore its potential in streamlining the software development lifecycle through proactive code improvement and education.

Z. Rasheed, Malik Abdul Sami, Muhammad Waseem et al. · 62 citations · ⚡3
#computer vision Open access Mar 2024

LLM-based agents for automating the enhancement of user story quality: An early report

The use of large language models to automatically improve the user story quality in Austrian Post Group IT agile teams is explored, with a reference model for an Autonomous LLM-based Agent System developed and implemented at the company.

Zheying Zhang, M. Rayhan, Tomas Herda et al. · 48 citations · ⚡4
#computer vision Review Mar 2024

System for systematic literature review using multiple AI agents: Concept and an empirical evaluation

This paper introduces a novel multi-AI-agent system designed to fully automate SLRs, and demonstrates how it substantially reduces the time and effort traditionally required for SLRs while maintaining comprehensiveness and precision.

Abdul Malik Sami, Z. Rasheed, Kai-Kristian Kemell et al. · 44 citations · ⚡2
#computer vision Feb 2024

Can Large Language Models Serve as Data Analysts? A Multi-Agent Assisted Approach for Qualitative Data Analysis

The proposed LLM-based multi-agent system automates qualitative data analysis process, creating opportunities for researchers and practitioners, and future improvements focus on enhancing multilingual performance and integrating continuous expert feedback.

Z. Rasheed, Muhammad Waseem, Aakash Ahmad et al. · 41 citations
#artificial intelligence Conference Open access Jun 2018

The Key Concepts of Ethics of Artificial Intelligence

It is suggested that the focus on finding keywords is the first step in guiding and providing direction for future research in the AI ethics field.

Ville Vakkuri, P. Abrahamsson · 39 citations · ⚡2

Related blog posts

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.