{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T06:03:48Z","timestamp":1784700228911,"version":"3.55.0"},"publisher-location":"Cham","reference-count":21,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032331946","type":"print"},{"value":"9783032331953","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-33195-3_21","type":"book-chapter","created":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T05:24:25Z","timestamp":1784697865000},"page":"292-302","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Fundamental Limits of\u00a0Runtime Policy Enforcement in\u00a0Multi-agent AGI Systems"],"prefix":"10.1007","author":[{"given":"Shivani","family":"Shukla","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Himanshu","family":"Joshi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,23]]},"reference":[{"key":"21_CR1","unstructured":"Bhardwaj, V.: Agent Behavioural Contracts: Formal Specification and Runtime Enforcement. arXiv:2602.22302 (2026)"},{"key":"21_CR2","unstructured":"Cryptographic Runtime Governance for Autonomous AI Systems: The Aegis Architecture. arXiv:2603.16938 (2026)"},{"key":"21_CR3","unstructured":"Kaptein, M.: Runtime Governance for AI Agents: Policies on Paths. arXiv:2603.16586 (2026)"},{"key":"21_CR4","unstructured":"Microsoft: Introducing the Agent Governance Toolkit. Microsoft Open Source Blog (2026)"},{"key":"21_CR5","unstructured":"Wang, H., Poskitt, C.M., Sun, J.: AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents. In: Proceedings of ICSE. arXiv:2503.18666 (2026)"},{"key":"21_CR6","unstructured":"Wang, H., Poskitt, C.M., Sun, J., Wei, J.: Pro$$^2$$Guard: proactive runtime enforcement of LLM agent safety via probabilistic model checking. arXiv:2508.00500 (2025)"},{"key":"21_CR7","unstructured":"Costa, M., K\u00f6pf, B.: Securing AI Agents with Information-Flow Control. arXiv:2505.23643 (2025)"},{"key":"21_CR8","unstructured":"Debenedetti, E.: Defeating Prompt Injections by Design. arXiv:2503.18813 (2025)"},{"issue":"1","key":"21_CR9","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1145\/353323.353382","volume":"3","author":"FB Schneider","year":"2000","unstructured":"Schneider, F.B.: Enforceable security policies. ACM Trans. Inf. Syst. Secur. 3(1), 30\u201350 (2000)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"issue":"1\u20132","key":"21_CR10","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1007\/s10207-004-0046-8","volume":"4","author":"J Ligatti","year":"2005","unstructured":"Ligatti, J., Bauer, L., Walker, D.: Edit automata: enforcement mechanisms for run-time security policies. Int. J. Inf. Secur. 4(1\u20132), 2\u201316 (2005)","journal-title":"Int. J. Inf. Secur."},{"issue":"1\u20132","key":"21_CR11","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1007\/s10703-016-0242-y","volume":"49","author":"D Basin","year":"2016","unstructured":"Basin, D., Caronni, G., Ereth, S., Harvan, M., Klaedtke, F., Mantel, H.: Scalable offline monitoring of temporal specifications. Form. Methods Syst. Des. 49(1\u20132), 75\u2013108 (2016)","journal-title":"Form. Methods Syst. Des."},{"key":"21_CR12","unstructured":"Rushby, J.: Noninterference, Transitivity, and Channel-Control Security Policies. SRI International. CSL-92-02 Technical Report (1992)"},{"key":"21_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"235","DOI":"10.1007\/978-3-540-74835-9_16","volume-title":"Computer Security \u2013 ESORICS 2007","author":"R Meyden","year":"2007","unstructured":"Meyden, R.: What, Indeed, Is Intransitive Noninterference? In: Biskup, J., L\u00f3pez, J. (eds.) ESORICS 2007. LNCS, vol. 4734, pp. 235\u2013250. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-74835-9_16"},{"issue":"5","key":"21_CR14","doi-asserted-by":"publisher","first-page":"236","DOI":"10.1145\/360051.360056","volume":"19","author":"DE Denning","year":"1976","unstructured":"Denning, D.E.: A lattice model of secure information flow. Commun. ACM 19(5), 236\u2013243 (1976)","journal-title":"Commun. ACM"},{"key":"21_CR15","doi-asserted-by":"crossref","unstructured":"Goguen, J.A., Meseguer, J.: Security policies and security models. In: IEEE Symposium on Security and Privacy, pp. 11\u201320 (1982)","DOI":"10.1109\/SP.1982.10014"},{"issue":"1","key":"21_CR16","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3603371","volume":"56","author":"M Brcic","year":"2023","unstructured":"Brcic, M., Yampolskiy, R.V.: Impossibility results in AI: a survey. ACM Comput. Surv. 56(1), 1\u201324 (2023)","journal-title":"ACM Comput. Surv."},{"key":"21_CR17","doi-asserted-by":"crossref","unstructured":"Myers, A.C.: JFlow: practical mostly-static information flow control. In: ACM POPL, pp. 228\u2013241 (1999)","DOI":"10.1145\/292540.292561"},{"key":"21_CR18","doi-asserted-by":"crossref","unstructured":"Cooper, R., Marzullo, K.: Consistent Detection of Global Predicates, pp. 167\u2013174. ACM PADD Workshop (1991)","DOI":"10.1145\/122759.122774"},{"issue":"1","key":"21_CR19","doi-asserted-by":"publisher","first-page":"173","DOI":"10.1109\/TC.2015.2409839","volume":"65","author":"W Zhu","year":"2016","unstructured":"Zhu, W., Cao, J., Raynal, M.: Predicate detection in asynchronous distributed systems: a probabilistic approach. IEEE Trans. Comput. 65(1), 173\u2013186 (2016)","journal-title":"IEEE Trans. Comput."},{"key":"21_CR20","unstructured":"Papadimitriou, C.H.: Computational Complexity, Addison-Wesley (1994)"},{"key":"21_CR21","doi-asserted-by":"publisher","first-page":"117","DOI":"10.1016\/S0065-2458(03)58003-2","volume":"58","author":"A Biere","year":"2003","unstructured":"Biere, A., Cimatti, A., Clarke, E.M., Strichman, O., Zhu, Y.: Bounded model checking. Adv. Comput. 58, 117\u2013148 (2003)","journal-title":"Adv. Comput."}],"container-title":["Lecture Notes in Computer Science","Artificial General Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-33195-3_21","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T05:24:27Z","timestamp":1784697867000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-33195-3_21"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032331946","9783032331953"],"references-count":21,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-33195-3_21","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"23 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"AGI","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Artificial General Intelligence","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"San Francisco","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 July 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 July 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"agi2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/agi-conf.org\/2026\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}