AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

When the Agent Becomes the Kernel: A Systematization of Security on the Path to AI-Native Operating Systems

arXiv · AI, language, vision and robotics · article · Sep 20, 2026 · UTC

Large language model agents are now privileged principals that take consequential actions: editing code repositories, operating inboxes, completing purchases. Their authority is kernel-grade, but it comes without what classical systems security requires: a trusted mediator interposed on every access. Operating-system vendors are now rebuilding the platform around this de-facto agent kernel, inheriting complete mediation as a design problem. We systematize the security of such systems around a single distinction: a crossing mediated over provenance admits a deterministic check, while one over c

Read original source ↗ Open in workspace

recordType
paper
region
Global

Evidence & attribution

First collected: 2026-09-23T09:51:33.063Z. This is not the publication date.