Computer-implemented security and governance system for workforces of generative AI agents with share-based execution, tamper-proof log chain, and write access denied by default.

DE202026003452U1Undetermined Publication Date: 2026-10-08SCHNEIDER FELIX ANDREAS SIMON
0 Cites 0 Cited by

Patent Information

Application Number
DE202026003452
Authority / Receiving Office
DE · DE
Patent Type
Utility models
Current Assignee / Owner
Filing Date
2026-08-06
Publication Date
2026-10-08
Estimated Expiration
2036-08-31
Patent Text Reader

Abstract

A computer-implemented security and governance system for a plurality of generative AI agents, comprising: a) an approval unit configured to permit operations of a specified class of operations requiring approval—at least operations that modify the inventory, role, or tool assignment of the agent workforce, as well as changes to inventory data outside of a write scope assigned to the respective agent or operation—to be executed only after human approval, wherein each approval is executed as a uniquely redeemable authorization date bound to the requested item and the requester context, the use of which by an actor outside the requester context or for a different item is rejected and logged, wherein the requester context comprises the identity of the requesting agent, its session, or its role instance.b) a protocol unit configured to store each governance-relevant operation as an entry in an appendage-only protocol chain, wherein machine detectability of both subsequent modification of individual entries and truncation of the chain end is achieved by checksum chaining, in which each entry contains a checksum formed from the checksum of the preceding entry and the content of the current entry, in conjunction with a chain head anchor held outside the data set storing the chain, and / or by cryptographic signing of the entries including a gap- and truncation-detecting sequential count using a key held outside the data set; c) an access control unit that controls access by generative AI agents to inventory data according to a stored access policy, whereby access is denied without explicit permission.and which includes at least: a delimited write area assigned to the agent or the respective process, outside of which write access is denied; a data source register that permits access to inventory data only upon explicit entry; and a tool authorization that permits tool calls by an agent only if the tool is subject to an authorization assigned to the agent, d) wherein each release request, each release grant and each access denial by the access control unit is stored as an entry in the log chain according to feature b) and the redemption of a release requires a check against the entry of the associated release request.
Need to check novelty before this filing date? Find Prior Art