Skip to content

Fault Propagation and Risk Containment in Agentic AI Systems

Oct 2026 · Zenodo (CERN European Organization for Nuclear Research)
Adversarial Robustness in Machine Learning

Abstract

Agentic artificial intelligence systems differ from conventional language model applications because they can reasonover a task, select tools, invoke external systems, observe resulting state, and continue acting toward a goal. Thisaction loop creates a security and reliability problem that cannot be adequately described by model accuracy orprompt-level safety alone. A local reasoning error, malicious instruction, misleading tool output, or authorizationmistake can propagate across subsequent actions and produce a system-level failure with consequences larger thanthe initial fault. This paper proposes a systems framework for analyzing that problem. It introduces Agentic FaultPropagation as the transmission or amplification of a local fault across an agent's perception, reasoning, planning, toolselection, authorization, execution, observation, and replanning cycle. It also introduces Agentic Blast Radius as ameasure of the maximum consequential impact that can result from an undetected fault before containment or humanintervention. Building on established work on tool-using language models, agent evaluation, prompt injection, leastprivilege, and AI risk management, the paper develops a fault taxonomy and a containment architecture. Theframework has four components: a fault lifecycle model, a propagation graph, a blast-radius model, and a layeredcontainment strategy. Proposed controls include least-privilege tool authorization, deterministic policy enforcement,stage-level validation, trust boundaries around external content, independent approval for high-impact actions, runtimemonitoring, provenance-aware logging, and recovery mechanisms. The paper does not claim experimental results.Instead, it specifies an empirical evaluation protocol that can be implemented using agent benchmarks and controlledtool environments. The central research claim is that secure agentic AI should be evaluated not only by whether anagent can complete a task, but also by how far an error can travel before the system stops it.

View source

Similar papers

#artificial intelligence Open access May 2023

Evaluating the Performance of Large Language Models on GAOKAO Benchmark

GAOKAO-Bench is introduced, an intuitive benchmark that employs questions from the Chinese GAOKAO examination as test samples, including both subjective and objective questions that contribute a robust evaluation benchmark for future large language models and offers valuable insights into the advantages and limitations...

Xiaotian Zhang, Chun-yan Li, Yi Zong et al. · 216 citations · ⚡17
#computer vision Open access Jun 2016

Software Development in Startup Companies: The Greenfield Startup Model

The results are packaged in the Greenfield Startup Model (GSM), which explains the priority of startups to release the product as quickly as possible, and the need to shorten time-to-market, by speeding up the development through low-precision engineering activities.

Carmine Giardino, Nicolò Paternoster, M. Unterkalmsteiner et al. · 178 citations · ⚡14
#computer vision Open access Oct 2016

Software Startups - A Research Agenda

Software startup companies develop innovative, software-intensive products within limited timeframes and with few resources, searching for sustainable and scalable business models.

M. Unterkalmsteiner, P. Abrahamsson, Xiaofeng Wang et al. · 157 citations · ⚡17
#artificial intelligence Open access Jul 2024

Gender, Race, and Intersectional Bias in Resume Screening via Language Model Retrieval

This work investigates the possibilities of using LLMs in a resume screening setting via a document retrieval framework that simulates job candidate selection and finds that the MTEs are biased, significantly favoring White-associated names in 85% of cases and female-associated names in only 11.1% of cases.

Kyra Wilson, Aylin Caliskan · 131 citations · ⚡8
#machine learning Review Open access Oct 2016

“Failures” to be celebrated: an analysis of major pivots of software startups

This study conducts a case survey study based on the secondary data of the major pivots happened in 49 software startups, and demonstrates that customer need pivot is the most common among all pivot types.

Sohaib Shahid Bajwa, Xiaofeng Wang, Anh Nguyen-Duc et al. · 127 citations · ⚡15
#artificial intelligence Review Nov 2024

How to Build a Quantum Supercomputer: Scaling from Hundreds to Millions of Qubits

This work shows that orders of magnitude enhancement in performance could be obtained by a combination of hardware improvements and tight quantum-HPC integration and introduces high-performance architectures for quantum-probabilistic computing with custom-designed accelerators to tackle today's industry-scale classical...

Masoud Mohseni, Artur Scherer, K. Johnson et al. · 121 citations · ⚡9

Related blog posts

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.