Papers1 provider · 3 records
July 5, 2026· Zenodo (CERN European Organization for Nuclear Research)
report
Open access

Cross-Agent Governance Alignment (CAGA): Formalizing Cross-Organizational AI Governance as a Zero-Knowledge Coordination Problem

Abstract

Cross-Agent Governance Alignment (CAGA): Verifiable Coordination Across Private AI Governance Domains formalizes the CAGA problem: establishing a declared compatibility relation between AI governance domains across organizational boundaries without disclosing the proprietary policy content on which each domain relies. Cross-organizational agent interaction creates two distinct governance questions: whether each local effect-bearing action is authorized within its own domain, and whether the participating domains can establish the declared relation. This paper formalizes the second problem. CAGA does not itself authorize execution. It produces a privacy-preserving compatibility result and associated evidence that each domain's runtime authorization boundary may materially consume before emitting its own action-bound verdict and authorization artifact. The formal model defines a governance domain as agents, a declared effect-bearing action vocabulary, versioned policy and authority state, governance-relevant state, a material evidence set, and a runtime authorization boundary over the triadic verdict space (ALLOW, DENY, ABSTAIN), where unresolved ABSTAIN remains ABSTAIN and authorized resolution produces a separate resulting action-bound verdict through the boundary. Every CAGA claim is scoped to a declared profile identifying the participating domains and authority roots, action vocabulary, compatibility relation and version, commitments, temporal boundary, leakage profile, scheme and verification parameters, declared replay mode, failure treatment, and expected local-boundary consumption. The Boolean compatibility relation is separated from protocol status: the protocol output comprises a result that may be positive, negative, or unresolved, together with the proof or verifier record and a CAGA evidence artifact. An unresolved result is not a verdict, and neither a negative nor an unresolved result may be treated as affirmative CAGA support for ALLOW. An illustrative prior-authorization compatibility relation between a hospital domain and an insurer domain, together with a worked local-boundary consumption sequence, shows the level at which a CAGA proposition may be stated without disclosing a protocol construction; no execution path originates from CAGA. The paper: Separates local pre-execution authorization from cross-domain compatibility evidence, and reserves the term authorization artifact for the action-bound record emitted by a runtime authorization boundary; a CAGA result may participate in composed authorization only where the Composition Test is satisfied; the CAGA evidence artifact does not thereby become an authorization artifact Formalizes the declared compatibility relation and protocol output under a declared CAGA profile, with cross-domain interactions whose local actions need not be identical, and supplies a terminology and instrument-ownership map locating each evidentiary term in its owning instrument States the threat model with honest-but-curious as the base analytic assumption rather than a prediction about regulated parties, classifies an expanded threat inventory as covered, partially covered, or excluded, and treats Byzantine deviation, arbitrary collusion, and malicious-verifier behavior as outside the base claim, requiring separately specified protocol defenses Identifies the required properties of a declared CAGA protocol: relation completeness and soundness, declared-leakage privacy, deterministic relation result with permitted cryptographic randomness, evidence and reconstruction sufficiency under the declared replay mode, commitment and domain binding, repeated-interaction privacy, optional post-compromise transcript confidentiality, non-authorizing failure, evidence traceability and presentation scope, declared-regime scope, and Input Integrity support, where provenance establishes origin, not truth Restructures the prior-art analysis as a component-and-gap assessment across communication protocols including the current Model Context Protocol specification (2026-07-28), policy composition and distributed authorization, secure multi-party computation and zero-knowledge systems, selective-disclosure credentials, multi-agent and agent-action governance architectures, and ledger approaches, identifying CAGA as the residual problem after those contributions are accounted for Zero-knowledge proof systems, secure multi-party computation, private set intersection, trusted execution, commitment schemes, and selective disclosure are candidate implementation substrates rather than authorization substitutes; no component establishes CAGA or authorization by label alone. The analysis is aligned with the Authorization Artifact Test v1.2, the Authorization Boundary Integrity Model v1.1, the Five Tests Standard v1.2.0, the ABIM Evidence Requirements v3.5, the Closed-World Bargain v1.1, and the Override Asymmetry v2.0. The paper does not assert that any jurisdiction requires CAGA, zero-knowledge proof, or pre-execution authorization, and it deliberately stops at problem formalization: it does not disclose protocol constructions, circuits, trusted-setup designs, or implementation mechanisms. The paper does not present an ideal functionality, security reduction, theorem establishing a protocol construction, or deployable implementation. By defining the problem space and evaluation criteria within a declared closed world, it provides a structured problem specification against which candidate cross-domain coordination protocols and their composition with local runtime authorization boundaries can be assessed. Version 2.0 (August 2026) separates cross-domain compatibility evidence from local pre-execution authorization; replaces the governance-domain enforcement function with a runtime authorization-boundary model; distinguishes the Boolean compatibility relation from unresolved protocol status; defines a declared CAGA profile; separates CAGA evidence artifacts from local authorization artifacts; conditions determinism on declared decision state while permitting cryptographic randomness; replaces default-denial protocol failure with non-authorizing unresolved status; adds an explicit interface to local Input Integrity assessment, authenticated bound materials, replay-mode, closed-world, Composition Test, and authorized-resolution semantics; narrows legal and regulatory claims; updates MCP and multi-agent prior-art references; and restructures the prior-art analysis as a component-and-gap assessment. Version 2.0 also adds an illustrative prior-authorization compatibility relation and a worked local-boundary consumption sequence; clarifies that the paper specifies a formal problem rather than presenting an ideal functionality, security reduction, or protocol proof; adds a terminology and instrument-ownership map; expands the component-and-gap analysis to address policy composition, distributed authorization, selective-disclosure credentials, and recent agent-action governance work; and clarifies the relationship between the paper's CC BY 4.0 copyright license and unlicensed patent rights. It supersedes Version 1.1 (July 2026), which aligned terminology with 5TS v1.2.0 and the FERZ authorization-artifact vocabulary, and Version 1.0 (February 2026), the original problem formalization. Keywords: cross-agent governance alignment, cross-organizational AI governance, private governance domains, privacy-preserving coordination, runtime authorization boundary, pre-execution authorization, authorization artifacts, zero-knowledge proofs, secure multi-party computation, Input Integrity, independent reconstruction

Community

0 comments
Use Connect Wallet in the navigation

No discussion yet

Be the first to share a question or observation.