Skip to content
#edge computing Open access

Enterprise AI as a Reconstruction Layer: Governing Derived Knowledge and Execution-Time Consequences

Sep 2026 · Zenodo (CERN European Organization for Nuclear Research)
Scientific Computing and Data Management

Abstract

Abstract Modern enterprise AI systems increasingly operate across multiple authorized data sources, memories, applications, and tools. This creates a security problem that is not adequately described as conventional data theft. An AI workload may be individually authorized to read support records, engineering information, source-control activity, supplier data, budgets, hiring information, and calendars. No individual source may contain a sensitive strategic conclusion. However, the AI system may combine those independently authorized fragments and reconstruct a new high-value object: an unreleased product direction, likely launch window, supplier dependency, market strategy, organizational weakness, or other forward-looking enterprise knowledge. The security boundary therefore changes. The relevant questions are no longer only: Who may read data A? or: Who may read data B? They also become: Who may establish the relationship A-to-B? Who may retain or disclose the resulting inference? Who may cause an external action because of that reconstructed meaning? This paper describes a threat model in which the AI assistant becomes a computational graph across previously separate enterprise systems. The resulting risk may exist even when each underlying retrieval complies with its ordinary source-level permissions. The sensitive object is not necessarily a stolen database record; it may be a new semantic object created through authorized association. The architecture therefore separates two security transitions: Authorized Data | v Authorized Reconstruction | v Computed Meaning | v Authorized Effectuation | v External Consequence The first transition concerns association authority: permission to read independently authorized fragments does not automatically imply permission to join those fragments into a new semantic relationship. The second concerns execution-time finality: permission to compute, generate, or prepare an output does not automatically imply permission for that output to become externally consequential. The proposed architectural model therefore introduces controls around independently governed relationship mapping, session-bound reconstruction, minimum-necessary temporary views, provenance-aware release, and a mandatory effectuation boundary. Candidate outputs or actions remain non-effective until the consequence-controlling component verifies the applicable authority, provenance, destination, policy state, disclosure conditions, and other protected execution state immediately before release or effectuation. In compact form: Access != Association Association != Authority to Disclose Computation != Authority to Cause Consequence The execution-time consequence boundary may be implemented through existing mechanisms such as policy-enforcement points, reference monitors, authorization servers, secure execution environments, transaction coordinators, capability systems, protected dispatchers, database commit controls, network command gates, or equivalent mechanisms. The important property is functional rather than terminological: A computed result or proposed action remains non-effective until the component with mandatory control over the actual consequence verifies that the exact pending effect is permitted under current protected authority and state. This architecture is intended to complement conventional identity, access control, encryption, zero-trust, data-loss prevention, confidential-computing, logging, and authorization systems rather than replace them. Those mechanisms continue to protect identities, stores, channels, and individual permissions. The additional problem addressed here is governance of the relationship created between authorized fragments and governance of the transition from computed meaning to actual consequence. The paper presents this as a forward-looking threat model rather than an allegation concerning any specific enterprise or AI product. The objective is to identify an architectural risk before multi-source, tool-enabled enterprise agents make cross-domain reconstruction and autonomous effectuation routine. Core Security Principle Access is not association. Computation is not consequence. A system may legitimately authorize an AI workload to retrieve multiple pieces of information without granting unrestricted authority to construct every possible relationship between them. Likewise, a system may permit an AI workload to reason, generate, prepare, or propose an action without granting that workload unconditional authority to make the action externally effective. The security architecture should therefore protect not only the nodes—files, databases, identities, applications, and APIs—but also the edges created between them and the consequence that may follow from those edges. Architectural Model A simplified model is: Source A ----\ \ Source B ------> Controlled Reconstruction / | Source C ----/ v Derived Semantic Object | v NON-EFFECTIVE | v Execution-Time Finality | +------+------+ | | DENY RELEASE | v CONSEQUENCE The architecture therefore introduces two independently enforceable questions. Reconstruction Question May this workload establish this relationship between these independently authorized inputs? Effectuation Question May this exact derived result produce this exact external consequence under the current protected state? Both must be answered affirmatively where the deployment treats the resulting relationship or consequence as protected. Why Conventional Source Permissions Are Insufficient Traditional access-control systems commonly evaluate permissions against individual resources: Identity X may read Resource A. Identity X may read Resource B. That does not necessarily define whether: Identity X may establish A <-> B. Nor does it necessarily define whether the resulting inference may be: stored remembered exported sent used as tool input written to another system or converted into an external action In an agentic environment, the semantic relationship itself may become the sensitive asset. The architecture therefore treats association authority as distinct from ordinary read authority. Execution-Time Finality After an authorized reconstruction has produced a candidate result, that result is not automatically permitted to cause consequence. The system keeps the candidate output or candidate action non-effective until a mandatory effectuation boundary verifies, as applicable: exact pending effect + current authority + protected policy state + provenance + destination + session binding + revocation / generation state + freshness / replay state + applicable disclosure or usage limits Only after successful execution-time verification may the consequence be committed. This produces the broader invariant: AUTHORIZED INPUT != AUTHORIZED RELATIONSHIP AUTHORIZED RELATIONSHIP != AUTHORIZED CONSEQUENCE Relationship to Existing Security Controls The architecture does not argue that identity management, encryption, source permissions, zero trust, DLP, confidential computing, or conventional authorization are unnecessary. They solve important problems. Instead, this work identifies two additional control surfaces that become increasingly important for multi-source agentic systems: the semantic edge created between separately accessible information; and the execution boundary where computed meaning becomes an external consequence. Existing mechanisms may be used to implement these controls. The contribution is the separation of these authorities and the requirement that they be enforceable at the relevant reconstruction and effectuation boundaries. Broader Principle The central problem can be summarized as: Protect the nodes. Protect the edges. Protect the transition from edge to consequence. As AI systems become increasingly capable of retrieving, combining, remembering, and acting across enterprise systems, protecting individual data stores is no longer sufficient by itself. The system must also determine which relationships may be constructed and which consequences those relationships may authorize. Disclaimer This paper presents a hypothetical architectural threat model. It does not claim that any named enterprise, AI provider, or deployed product has reconstructed, disclosed, sold, or acted upon an enterprise strategy in the manner described. The purpose is preventive: to describe what becomes technically possible when a multi-connected AI workload is permitted to combine independently authorized information and when computed results can become consequential without separately governed association and execution-time authority. Related Internet-Drafts The architectural controls discussed here are further developed in the following individual Internet-Drafts: The Missing Piece for High-Value Confidential Enterprise AI: Non-Joinable Vaults and Output-Release Finality for Banking, Defence, and Public-Sector Deployments https://datatracker.ietf.org/doc/draft-das-enterprise-ai-output-finality/ Enterprise AI Protocol Architecture https://datatracker.ietf.org/doc/draft-das-protocols-enterprise-ai/ Technical Non-Joinability and Execution Finality for Enterprise AI: 79 Enforcement Profiles https://datatracker.ietf.org/doc/draft-das-enterprise-ai-enforcement-profiles/ These are individual Internet-Drafts submitted for discussion and review. Their presence on the IETF Datatrack

View source

Similar papers

#computer vision Review Sep 2017

Agile Software Development Methods: Review and Analysis

This publication proposes a definition and a classification of agile software development approaches and analyses ten software development methods that can be characterized as being "agile" against the defined criterion.

P. Abrahamsson, O. Salo, Jussi Ronkainen et al. · 727 citations · ⚡54
#computer vision Jun 2008

The impact of agile practices on communication in software development

The study shows that agile practices improve both informal and formal communication, but indicates that, in larger development situations involving multiple external stakeholders, a mismatch of adequate communication mechanisms can sometimes even hinder the communication.

M. Pikkarainen, Jukka Haikara, O. Salo et al. · 401 citations · ⚡48
#machine learning Review Open access Oct 2014

Software development in startup companies: A systematic mapping study

The results indicate that software engineering work practices are chosen opportunistically, adapted and configured to provide value under the constrains imposed by the startup context.

Nicolò Paternoster, Carmine Giardino, M. Unterkalmsteiner et al. · 394 citations · ⚡54

Related blog posts

Microsoft Research Blog Sep 29, 2026

Introducing Quine: An AI research system designed for the complexity of biology

Biology doesn't operate in silos, and neither should the AI representation of it. Quine is an early-stage research effort to create a multimodal world model of biology. By connecting insights across biological scales and modalities, Quine helps scientists computationally search a space far larger than intuition allows and prioritize hypotheses before they reach the lab. Experimental results provide important feedback, helping researchers sharpen future research directions. The post Introducing Q…

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.