{
  "schema": "https://aisharedresponsibility.com/data/srf-vnext-extensions.schema",
  "title": "Proposed CoSAI SRF next-version agentic extensions",
  "source": "https://aisharedresponsibility.com/papers/srf-vnext-agentic-extensions/",
  "updated": "2026-09-09",
  "status": "Independently proposed companion extension of the CoSAI Shared Responsibility Framework; not part of CoSAI SRF v1.0; not endorsed by CoSAI or OASIS.",
  "description": "Nine asks for a future CoSAI SRF revision. Each record names the v1.0 hook it extends, the site surfaces that already use it, and what the next paper should add. These are companion ideas on this site, not a competing framework.",
  "srf_version_hook": "1.0",
  "refused": [
    {
      "label": "A0-A6 autonomy ladder",
      "reason": "Collides with published L0-L5 (Appendix A.1.3.3)."
    },
    {
      "label": "AI SAFE² ACT-1 to ACT-4",
      "reason": "Same collision. At most a crosswalk footnote, never a live scale."
    },
    {
      "label": "AISM Chaos-to-Sovereignty",
      "reason": "Competing maturity architecture; not an SRF noun."
    },
    {
      "label": "HEAR doctrine",
      "reason": "Keep fail-closed named halt authority; do not add a ninth persona or a branded named-key ritual."
    },
    {
      "label": "Control Envelope as an SRF object",
      "reason": "Control already means an accountability assignment with ID, layer, persona, operating models, and threshold."
    }
  ],
  "items": [
    {
      "id": "accountability-continuity",
      "title": "Accountability continuity",
      "glossary_anchor": "accountability-continuity",
      "v1_0_hook": "Section 3, exactly one accountable party per activity; CoSAI IAM non-expanding delegation",
      "site_surfaces": [
        "/glossary/#accountability-continuity",
        "/agentic-ai-security/#delegation-chains"
      ],
      "cosai_vnext_ask": "State that delegated authority must not silently expand, and that a child agent's authority stays inside the parent assignment. Keep the one-party rule; add continuity across delegation hops.",
      "status": "proposed-companion",
      "inspired_by": ["CoSAI IAM", "handoff"]
    },
    {
      "id": "agent-replication",
      "title": "Spawn and replication as a named activity",
      "glossary_anchor": "agent-replication",
      "v1_0_hook": "L3 / Agent-PaaS matrices; agent definitions on a provider runtime",
      "site_surfaces": [
        "/glossary/#agent-replication",
        "/tools/vendor-risk/",
        "/operating-models/"
      ],
      "cosai_vnext_ask": "Add spawn authority, descendant capability narrowing, live descendant inventory, and revocation of the full descendant tree as a named Agent-PaaS / L3 activity.",
      "status": "proposed-companion",
      "inspired_by": ["AI SAFE² CP.9"]
    },
    {
      "id": "fail-closed-override",
      "title": "Fail-closed halt when the authorizer is unreachable",
      "glossary_anchor": "fail-closed-override",
      "v1_0_hook": "Appendix A.1.3.2, Human Override Tiers T1-T5",
      "site_surfaces": [
        "/glossary/#fail-closed-override",
        "/tools/vendor-risk/",
        "thresholds/ai-srf-threshold-control.schema.json"
      ],
      "cosai_vnext_ask": "For irreversible, financially material, security-control-modifying, physical, or cross-organization actions, block if the assigned override authority cannot be reached. Do not import a named-individual brand.",
      "status": "proposed-companion",
      "inspired_by": ["AI SAFE² CP.10 minus brand", "SRF T1-T5"]
    },
    {
      "id": "persistence-scope",
      "title": "Persistence scope on L2",
      "glossary_anchor": "persistence-scope",
      "v1_0_hook": "L2 AI Information, retention and access prose",
      "site_surfaces": [
        "/glossary/#persistence-scope",
        "/tools/vendor-risk/",
        "thresholds/ai-srf-threshold-control.schema.json"
      ],
      "cosai_vnext_ask": "Classify information effects as request, handle_scoped, or durable, and name the accountable persona for durable state.",
      "status": "proposed-companion",
      "inspired_by": ["AI SAFE² CP.1"]
    },
    {
      "id": "enforcement-plane",
      "title": "Enforcement-plane declaration",
      "glossary_anchor": "enforcement-plane",
      "v1_0_hook": "Operating-model matrices; Appendix A.1.3 agentic attributes",
      "site_surfaces": [
        "/glossary/#enforcement-plane",
        "/operating-models/",
        "/tools/vendor-risk/",
        "thresholds/ai-srf-threshold-control.schema.json"
      ],
      "cosai_vnext_ask": "Treat north-south, east-west, and agent-to-tool as an attribute on agentic deployments, like autonomy_scope. Not a sixth architecture layer. Name which persona owns each plane under each operating model.",
      "status": "proposed-companion",
      "inspired_by": ["AI SAFE² CP.5"]
    },
    {
      "id": "protocol-independent-evidence",
      "title": "Protocol-independent evidence",
      "glossary_anchor": "protocol-independent-evidence",
      "v1_0_hook": "Appendix A.7 evidence",
      "site_surfaces": [
        "/glossary/#protocol-independent-evidence",
        "/papers/what-new-telemetry-agents-need.md"
      ],
      "cosai_vnext_ask": "Bind evidence to principals, capability grants, delegation chains, policy versions, and state handles, not to a session identifier owned by a protocol.",
      "status": "proposed-companion",
      "inspired_by": ["AI SAFE² v3.1 CP.5"]
    },
    {
      "id": "halt-authority-coverage",
      "title": "Owner coverage vs halt-authority coverage",
      "glossary_anchor": null,
      "v1_0_hook": "Section 3 personas; Appendix A.1.3.2 override tiers",
      "site_surfaces": [
        "/tools/vendor-risk/"
      ],
      "cosai_vnext_ask": "Require that halt authority is assigned and measurable, and that persona assignment and halt-authority coverage can be audited separately. Do not add a ninth persona.",
      "status": "proposed-companion",
      "inspired_by": ["AI SAFE² owner_of_record vs halt authority", "SRF T1-T5"]
    },
    {
      "id": "spend-ceiling-halt",
      "title": "Spend ceiling as a halt, not only an alert",
      "glossary_anchor": null,
      "v1_0_hook": "L3 application safety; L4 platform; Agent-PaaS",
      "site_surfaces": [
        "/tools/vendor-risk/"
      ],
      "cosai_vnext_ask": "Name spend or economic ceiling as an Agent-PaaS / L3-L4 control with halt vs alert semantics and one accountable persona.",
      "status": "proposed-companion",
      "inspired_by": ["OWASP-STATE budget limits", "vendor-risk blast-radius"]
    },
    {
      "id": "control-plane-location",
      "title": "Control-plane location per operating model",
      "glossary_anchor": null,
      "v1_0_hook": "Operating-model chapter, four deployment archetypes",
      "site_surfaces": [
        "/operating-models/"
      ],
      "cosai_vnext_ask": "Each matrix should state where authorization is enforced (customer app, Agent-PaaS runtime, model-provider gateway), distinct from where the agent executes.",
      "status": "proposed-companion",
      "inspired_by": ["handoff", "AI SAFE² enforcement planes"]
    }
  ]
}
