Agents & Automation

The Irreversibility Budget: Fleet-Level Risk Accounting and Admission Control for Agent Operating Systems

The engineering layer supplies the mechanisms. The Irreversibility Budget (2609.00275) shows why local gates fail at fleet scale: per-effect checks let a fleet of individually-authorized agents overdraw its principal's risk under a shared trigger - in the controlled study, up to 48× the tenant's risk limit.

AI Agency

What the source reports

The engineering layer supplies the mechanisms. The Irreversibility Budget (2609.00275) shows why local gates fail at fleet scale: per-effect checks let a fleet of individually-authorized agents overdraw its principal's risk under a shared trigger - in the controlled study, up to 48× the tenant's risk limit. The fix is to treat irreversibility as a first-class metered resource: a trusted runtime charges each effect its residual value-at-risk and denies the marginal effect once the aggregate would overdraw. Spawn Freely, Act Sparingly (2609.01035) extends the same logic to recursive agent trees: distinguish sandbox spawning (external controls prevent the harm) from capability activation (the branch crosses an irreversible-action boundary), and hold a trajectory-level risk budget in escrow, debiting it as branches activate. The paper proves an anytime harm bound and derives an "authority reproduction number" R_A where trajectory harm changes character as it crosses one. Design rule: search broadly in the sandbox; grant recursive authority sparingly, with an explicit risk charge.

Original source

Title
The Irreversibility Budget: Fleet-Level Risk Accounting and Admission Control for Agent Operating Systems
Publication
arXiv