AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

AgentKernel: The Trust-Native Agentic Operating System

arXiv · AI, language, vision and robotics · article · Aug 29, 2026 · UTC

Modern AI agents routinely cross trust boundaries: they ingest untrusted content, combine it with privileged instructions, persist intermediate beliefs in long-term memory, and invoke privileged tools. This creates an attack surface in which malicious payloads can enter through model inputs and cause harmful tool actions. Yet current governance stacks remain application-level middleware that share a process trust boundary with the agents they monitor. We argue that agents need an operating-system substrate providing mandatory, non-bypassable services for identity, input mediation, memory gover

Read original source ↗ Open in workspace

recordType
paper
region
Global

Evidence & attribution

First collected: 2026-09-26T21:41:48.575Z. This is not the publication date.