{"slug": "agent-safety-should-be-a-runtime-contract", "title": "Agent Safety Should Be a Runtime Contract", "summary": "A new arXiv preprint argues that AI agent safety should be enforced as a runtime contract by the harness, not instilled during training, citing a survey of 52 documented AI-agent and LLM safety incidents and a false-completion audit with 31 non-contested core cases. The paper, submitted on 11 Aug 2026, also reports a trajectory-schema audit of 12 public agent systems and a title-level audit of 28,560 papers at NeurIPS, ICML, and ICLR 2023-2025 showing an 8-12x imbalance between training-time and deployment-time publications.", "body_md": "# Computer Science > Cryptography and Security\n\n[Submitted on 11 Aug 2026]\n\n# Title:Agent Safety Should Be a Runtime Contract\n\n[View PDF](/pdf/2608.11274)\n\n[HTML (experimental)](https://arxiv.org/html/2608.11274v1)\n\nAbstract:The dominant paradigm treats AI safety as a property to be instilled during model training via RLHF, DPO, or Constitutional AI. We argue this is structurally insufficient for autonomous agents that execute code, mutate files, send messages, and modify databases. Agent safety should be a runtime contract enforced by the harness, and the contract has two complementary faces. The preventive face blocks dangerous actions before they happen via sandboxes, permission gates, output filters, and trajectory monitors. The evidential face requires verifiable proof that good actions actually happened, gating task submission on hard evidence such as test runs, log captures, file diffs, and citation grounding. We ground the position in four lines of public evidence, with row-level protocols and data released in the supplementary JSON files: a survey of 52 documented AI-agent and LLM safety incidents, a false-completion audit with 31 non-contested core cases plus one disputed illustrative case, a trajectory-schema audit of 12 public agent systems and harnesses, and a title-level audit of all 28,560 papers accepted at NeurIPS, ICML, and ICLR 2023-2025 showing a pooled 8-12x imbalance between training-time and deployment-time publication. Two prior communities that needed to enforce safety, computer security and the experimental sciences, converged on runtime contracts with both preventive and evidential elements; agentic AI is now under the same pressure. We formalize an Agent Trajectory Schema and Evidence Chain, state a compositional gating proposition based on standard monitor composition, and outline a research agenda. The right unit of safety in agentic AI is the trajectory-with-checkable-evidence, not the model.\n\n### References & Citations\n\nLoading...\n\n# Bibliographic and Citation Tools\n\nBibliographic Explorer\n\n*(*[What is the Explorer?](https://info.arxiv.org/labs/showcase.html#arxiv-bibliographic-explorer))\nConnected Papers\n\n*(*[What is Connected Papers?](https://www.connectedpapers.com/about))\nLitmaps\n\n*(*[What is Litmaps?](https://www.litmaps.co/))\nscite Smart Citations\n\n*(*[What are Smart Citations?](https://www.scite.ai/))# Code, Data and Media Associated with this Article\n\nalphaXiv\n\n*(*[What is alphaXiv?](https://alphaxiv.org/))\nCatalyzeX Code Finder for Papers\n\n*(*[What is CatalyzeX?](https://www.catalyzex.com))\nDagsHub\n\n*(*[What is DagsHub?](https://dagshub.com/))\nGotit.pub\n\n*(*[What is GotitPub?](http://gotit.pub/faq))\nHugging Face\n\n*(*[What is Huggingface?](https://huggingface.co/huggingface))\nScienceCast\n\n*(*[What is ScienceCast?](https://sciencecast.org/welcome))# Demos\n\n# Recommenders and Search Tools\n\nInfluence Flower\n\n*(*[What are Influence Flowers?](https://influencemap.cmlab.dev/))\nCORE Recommender\n\n*(*[What is CORE?](https://core.ac.uk/services/recommender))# arXivLabs: experimental projects with community collaborators\n\narXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.\n\nBoth individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.\n\nHave an idea for a project that will add value for arXiv's community? [ Learn more about arXivLabs](https://info.arxiv.org/labs/index.html).", "url": "https://wpnews.pro/news/agent-safety-should-be-a-runtime-contract", "canonical_source": "https://arxiv.org/abs/2608.11274", "published_at": "2026-08-14 06:07:20+00:00", "updated_at": "2026-08-14 06:40:44.249697+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-research"], "entities": ["arXiv", "NeurIPS", "ICML", "ICLR"], "alternates": {"html": "https://wpnews.pro/news/agent-safety-should-be-a-runtime-contract", "markdown": "https://wpnews.pro/news/agent-safety-should-be-a-runtime-contract.md", "text": "https://wpnews.pro/news/agent-safety-should-be-a-runtime-contract.txt", "jsonld": "https://wpnews.pro/news/agent-safety-should-be-a-runtime-contract.jsonld"}}