Computer-implemented method, data processing arrangement and computer program product for enabling an automated action

By integrating blockchain and machine learning with smart contracts, the method enables flexible and secure AI governance, addressing the challenges of defining and monitoring AI system powers and authority, enhancing accountability and adaptability.

WO2026153657A1PCT designated stage Publication Date: 2026-07-23WEHBERG GÖTZ GÖSTA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
WEHBERG GÖTZ GÖSTA
Filing Date
2025-06-24
Publication Date
2026-07-23

AI Technical Summary

Technical Problem

Current AI governance frameworks struggle to define and monitor the specific powers and authority of AI systems, leading to issues like 'carte blanche' access, inadequate identity verification, and limited applicability of blockchain technology, particularly in high-risk scenarios.

Method used

A method utilizing blockchain technology to store release rules and authorizations for AI agents, combining rule-based approaches with machine learning to enable flexible and controlled decision-making, incorporating smart contracts and non-fungible tokens to represent powers of action and decision-making authority.

Benefits of technology

Provides a flexible and secure mechanism for authorizing AI systems, ensuring transparent and tamper-proof governance, adaptable to specific scenarios, and addressing the limitations of existing protocols like OAuth 2.0.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025067750_23072026_PF_FP_ABST
    Figure EP2025067750_23072026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to a computer-implemented method (50) for enabling an automated action, comprising: providing a rule data set having enabling rules in at least one block of a blockchain (52), and retrieving the rule data set by means of a blockchain read-out device (54), characterized by evaluation of the rule data set by means of an agent device (56), the enabling rules and a machine learning method being taken into account for an enabling decision (58) for the automated action. The present invention further relates to a corresponding data processing arrangement and to a corresponding computer program product.
Need to check novelty before this filing date? Find Prior Art

Description

[0001]

[0002] Computer-implemented procedure, data processing arrangement, and computer program product for releasing an automated action

[0003] The present invention relates to a computer-implemented method for releasing an automated action according to the preamble of claim 1, a data processing arrangement for releasing an automated action according to the preamble of claim 12, and a computer program product according to claim 16.

[0004] The present invention relates to the technical field of artificial intelligence (AI) and, in particular, the governance of AI systems. With the increasing prevalence and capabilities of AI technologies, the need for effective control and management mechanisms to ensure their safe and responsible use is also growing.

[0005] AI systems, particularly so-called digital agents, are capable of autonomously performing complex tasks and making decisions. However, these capabilities also present challenges, especially regarding the control and accountability for the actions of these systems. AI governance aims to create frameworks and processes that ensure the ethical, secure, and legally compliant use of AI technologies.

[0006] A key aspect of AI governance is the authorization and legitimacy of AI systems. This involves clearly defining and documenting the powers, authority, and scope of action of an AI system and on whose behalf it acts. This is particularly relevant in areas where AI systems act on behalf of people or organizations and potentially make far-reaching decisions. Existing AI governance approaches, such as those implemented by IBM watsonx.governance, CalypsoAl, Copyleaks, and G2 AI governance tools, primarily focus on establishing general principles and creating transparency. However, these solutions reach their limits when it comes to defining and monitoring the specific powers and authority of an AI system in any given case.

[0007] Current authorization protocols such as OAuth 2.0 (known from the website "https: / / oauth.net / 2 / ") do offer access control options, but are not specifically tailored to the requirements of AI systems and their

[0008] NC-2025-1131 1Governance is aligned. It primarily covers the question of whether a system may access certain resources, but does not consider the more complex aspects of the decision-making powers and authority of AI agents.

[0009] The Model Context Protocol (MCP) is known from the website "https: / / modelcontextprotocol.io / introduction". Developed by the company Anthropic, it represents an open standard that enables developers to establish bidirectional connections between data sources and AI-powered tools. While it represents progress in the integration of AI systems, it does not comprehensively address governance aspects, particularly the issue of authorizing and legitimizing AI agents for specific decisions and actions.

[0010] Over the past 25 years, a terminology has emerged within the community dealing with authorization issues, describing the various moving parts and commonly referred to as "P*P architecture" ("Policy*Point", hereinafter also referred to as PowerPoint to emphasize the aspect of granting power of attorney in the sense of a "Power of Attorney"):

[0011] Power Enforcement Point (PEP) - usually the application or an intermediary that requests a decision from the PDP and enforces its outcome.

[0012] Power Decision Point (PDP) - the externalized authorization engine that evaluates an authorization policy based on a series of inputs and makes an access decision or other release decision.

[0013] Power Information Point (PIP) - Provider of data that contributes to the approval decision.

[0014] Power Administration Point (PAP) - Administration level for creating and managing authorization policies.

[0015] Power Verification Point (PVP) – Identification of the identities that fulfill the role of the PIP or PAP. Due to insufficient AI governance, the combination of MCP and OAuth is reaching its limits. Three main challenges remain unresolved (with the MCP and OAuth protocols representing a number of other currently used methods):

[0016] "Carte blanche" access: To avoid overwhelming users with authorization requests, current practices often require approval from the IT administrator. However, companies don't want the IT administrator granting permission for applications to communicate with each other company-wide, instead of the business owner. While this eliminates the need to send users through an OAuth flow, it also potentially grants apps and agents carte blanche. This approach is inconsistent with a data privacy policy based on the "need-to-know" principle (also known as the "principle of least privilege"). Furthermore, it can create unintended asymmetries between an agent's data access and the responsibility of the employee responsible for that agent.Company managers must therefore define which access rights are granted to which application and which agent. They can.

[0017] NC-2025-1131 2. To appoint an agent to do this instead of doing it oneself. Ultimately, the authorized business manager (i.e., a person) must bear the responsibility.

[0018] Last but not least, the relevant attempts to utilize blockchain technology (or "Decentralized Ledger Technology") remain limited in their usefulness for AI governance. Such approaches have so far been marketed, for example, under the heading of "benign AI." These approaches remain, in part, at the level of ethical or axiomatic principles. Their governance framework is limited to bilateral relationships. They therefore do not cover the network of relationships necessarily required for effective governance, such as identity verification (PVP), authenticated and authorizing bodies (PAP), authenticated and authorized AI users (PIP), AI systems assigned to users, and AI subsystems (PEP), etc. These approaches are thus similar to a truck's "tachograph" or an airplane's "flight recorder." Insofar as these approaches address questions of authorization at all, they are also limited to access rights, etc.B. in the form of multi-factor authentication for device access (MFA).

[0019] Based on known methods for releasing an automated action, the present invention aims to provide a computer-implemented method that enables a comparatively more flexible, simultaneously controlled release of automated actions by AI systems.

[0020] The invention solves this problem by a method according to claim 1. The basic idea of ​​the present invention is to utilize the tamper-proof nature of blockchain technology for storing release rules or authorizations for actions of autonomously acting AI agents, incorporating all necessary roles. Blockchain technology offers promising opportunities for implementing AI governance concepts and their peer-to-peer architecture. Due to its decentralized, transparent, and tamper-proof nature, blockchain is particularly well-suited for documenting and verifying authorizations and powers of action of AI systems. Concepts such as smart contracts, tokens, and NFTs (non-fungible tokens) can be used to map and automatically enforce complex governance structures. Machine learning plays an increasingly important role in the development of advanced AI systems.This technology enables AI agents to learn from data and continuously improve their performance. In the context of AI governance, the challenge lies in reconciling the flexibility and adaptability of machine learning methods with the need for clear rules and controls.

[0021] Secure release of a computer system by its user may require that both user authorization and verification of relevant identities form the basis for the release of the computer. This means that the relevant roles of a functioning governance structure are represented. The present invention allows this method and its underlying relationship network to be operationalized, i.e., used practically, by implementing them in a suitable data processing arrangement and a computer program.

[0022] NC-2025-1131 3The invention combines rule-based approaches stored in a blockchain with machine learning methods to enable flexible yet controlled decision-making processes for AI agents.

[0023] With authorization: It is not sufficient to limit the discussion to access rights. Access rights are limited to answering the question "is this subject allowed to perform this action with this resource?" While the process of verifying and granting these access rights can be partially automated based on the definition or use of roles (so-called RBAC / Role-based Access Control), attributes (so-called ABAC / Attribute-based Access Control), or policies (so-called PBAC / Policy-based Access Control), this is not sufficient.

[0024] Authorized agents, however, evaluate, make decisions, and act. Therefore, an authorization mechanism must also cover these rights, thus answering the question: "From whom has this subject received the authority to make specific decisions or perform certain actions (individual versus joint power of attorney, company headquarters, agent / authorizer, etc.), which decisions may it make and how, and which actions may it carry out with a specific resource (e.g., signing authority, authority to issue instructions, access to the necessary information, in modern parlance: 'need-to-know')?" The aforementioned triangular relationship also encompasses the question of the "authorization of the agent / authorizer," i.e., a kind of second-order approval that ensures a four-eyes principle in the use of computers. Therefore, a kind of "control head" is needed.The "superstructure," which contains the fundamental powers from which the authorization of access in individual cases can be derived, is comparable to a kind of "commercial register" for digital agents. This enables the trusting party to exercise dual, transparent control. Agents must operate within the limits and powers defined by the authorizing party (and, if applicable, its grantor). Even if one agent authorizes another, a human being must be at the top of such an authorization cascade and thus ultimately responsible (ultimate accountability). This is important to mitigate the risk of organizational negligence and prevent breaches of trust.

[0025] Identity of the Authorized Representative / Authorizer: The aspect of verifying the authorizer is also noteworthy, as protocols like OAuth differentiate between authorization and resource servers. While the authorization server verifies the access rights of a person or agent, the resource server refers to the service itself, such as the administration of a patient record or the control of production processes. According to current systems, the authorization server can also be operated by a trust and identification service provider. However, even if the authentication server is operated by the identity service provider (e.g., via SSO protocols like SAML and OIDC or so-called P*P architectures like IDQL, OPA / Rego, XACML, and Zanzibar), the biometric features currently used (face, finger, iris, vein) are insufficient for unambiguous identity verification.Therefore, in the context of protocols like OAuth, the question of how the authorizing party (and their agent) can securely verify themselves in order to effectively protect an organization and its identities and safeguard it against forgery, theft, and fraud is not currently adequately addressed. For example, the...

[0026] NC-2025-1131 4 previously unpublished international patent application number PCT / EP2O25 / O51218 a method for using a person's DNA to create a unique digital identity document.

[0027] The invention addresses the specific issue of authorizing a computer system in an integrated manner, meaning it appropriately considers all necessary architectural elements (PEP, PDP, PIP, PAP, PVP). In this respect, it complements the existing governance framework. The unique identification of the authorizing party (creation and upgrade of an identity), secure authentication (identification of the individual to third parties), transparent authorization (granting decision-making authority or power of attorney to the computer system), and legitimation (proof of the power of attorney by the computer system) are closely interrelated, as it is insufficient to demonstrate certain powers of attorney if the authorizing individual is not clearly identified. The authorized computer system must be able to reliably demonstrate the fact and scope of its authorization in order to act legitimately.

[0028] Similar to a commercial register for companies, which records the powers of attorney for managing directors and authorized signatories, the invention, in a preferred embodiment, utilizes Web3 tokens, NFTs, and smart contracts in the form of—depending on the group of stakeholders—a public, partially public, or private blockchain to represent the powers of action and decision-making of AI systems. In this sense, the invention represents a "commercial register for AI systems" that globally discloses the powers of action of digital agents (see the following table).

[0029] "

[0030] "

[0031] "

[0032]

[0033] NC-2025-1131 5 This is particularly—but not exclusively—necessary for AI systems in a high-risk category, for example, as defined by EU AI legislation. The scope of the decision-making powers actually granted, i.e., the respective delegation of authority, is thus (partially / within the circle of those affected) public and verifiable by third parties (e.g., by reference to such a Web3-based AI register in an organization's purchasing guidelines published on its website, in a QR code of a chatbot in a CRM interface, on the subscription page of an AI agent, etc.). The tokens and smart contracts are thus bound to the identity of the authorizing party, whereby zero-knowledge proofs can be maintained. Ultimately, such AI governance, which addresses the question of the delegation of human authority, i.e., the permission to make decisions, also serves to safeguard the identity of the individual concerned.The protection of identity and authority together therefore safeguards the sovereignty of the individual or an organization. The following paragraphs explain definitions for the technical terms used in the claim statement. These definitions should not be understood as limiting the disclosure, but rather as indicating some possible implementations of the invention, without excluding interpretations not mentioned in the definitions. Accordingly, the invention also includes other possible implementations besides those mentioned in the following paragraphs.

[0034] The term "rule set" refers to a structured collection of data containing rules or guidelines for specific processes or decisions. In the context of the present invention, the rule set comprises specific release rules stored in a blockchain, serving as the basis for deciding whether to release automated actions. In the simplest case, a release rule is a yes / no decision, meaning, for example, that release is granted if a condition is met. If the AI ​​agent, for instance, fulfills the condition of having issued a required certificate, the requested action is released.

[0035] "Approval rules" are defined criteria or conditions that must be met for a specific action or decision to be authorized. In the present invention, these rules are used to determine whether an automated action may be performed by an AI system.

[0036] A "blockchain" is a decentralized, distributed database that stores information in a chain of blocks. Each block contains cryptographically linked data records. In the present invention, the blockchain is used to securely and tamper-proof store rule data records.

[0037] Several blockchain platforms support the implementation of smart contracts and token standards that can be used for the present invention. Ethereum is one of the best-known and most widely used platforms that enables smart contracts and supports various token standards. The ERC-721 standard on Ethereum defines non-fungible tokens (NFTs) that can be used to represent unique authorizations or specific powers of action in the invention. Additionally, Ethereum supports the ERC-20 standard for fungible tokens and the ERC-1155 standard for multi-token implementations.

[0038] NC-2025-1131 6Binance Smart Chain (BSC) offers another platform that works with Ethereum-compatible smart contracts and supports similar token standards. Polygon (formerly Matic Network) provides a Layer 2 scaling solution for Ethereum that also enables ERC-721-compatible tokens and smart contracts, but offers lower transaction costs and higher speeds. Solana and Cardano are further examples. These blockchain platforms can be used in various embodiments of the invention to implement the release rules as smart contracts or to use different token types to represent authorizations and proxies. The choice of the specific blockchain platform may depend on factors such as transaction costs, speed, security requirements, and interoperability.

[0039] The "blockchain read device" is a technical component used to read data from a blockchain and make it available for further processing. In the present invention, it is used to retrieve the rule data set stored in the blockchain. For example, it is a software component that is implemented on a computer, such as a server, or in the cloud as a cloud application.

[0040] In this context, an "agent system" refers to a software-based system capable of autonomous action and decision-making. In the present invention, the agent system is responsible for evaluating the rule data set and making a release decision based on release rules and machine learning methods. For example, it is a software component implemented on a computer, such as a server, or in the cloud as a cloud application.

[0041] "Machine learning" refers to algorithms and statistical models that enable computer systems to improve tasks without explicit programming by learning from data and experience. After such training, which is typically performed with a verified dataset containing input and output (so that the AI ​​can learn the connection between input and output), the AI ​​system can then be used to determine output even for input not previously present in the training data. In the present invention, machine learning is used in combination with release rules to enable more flexible and context-aware decisions regarding the release of automated actions.

[0042] A "smart contract" is a computer program that runs on a blockchain and automatically executes actions when certain conditions are met. In the present invention, smart contracts can be used to implement release rules and automate their execution.

[0043] "Tokens" are digital assets or representations of rights that exist on a blockchain. "Non-fungible tokens" (NFTs) are unique digital assets, while "fungible tokens" are interchangeable digital assets. In the present invention, these token types can be used to represent various aspects of the release rules or authorizations.

[0044] "Coins" are digital currencies or units of value based on a blockchain. In the invention, coins could be used as part of the release rules or as a mechanism for controlling access rights.

[0045] NC-2025-1131 7Coins typically have their own blockchain, while tokens do not have their own blockchain and are hosted on Ethereum, for example.

[0046] A "Kl agent" is an autonomous, intelligent software system capable of performing complex tasks and making decisions. In the present invention, the Kl agent is used as the central element of the machine learning process to make release decisions and dynamically apply rules. A Kl agent can be created using various well-known programs and frameworks. For example, a Kl agent can be developed using Python-based libraries such as LangChain, which is specifically designed for creating Kl applications with large language models. LangChain provides components for orchestrating various Kl services and enables the integration of data sources, storage systems, and external APIs. Alternatively, a Kl agent can be implemented, for example, using Microsoft's Semantic Kernel, which is a cross-platform SDK for integrating Kl services into applications.Semantic Kernel supports various programming languages ​​such as C, Python, and Java and provides functions for scheduling and executing AI-driven tasks. OpenAL's GPT API can serve as the basis for an AI agent, with the agent's intelligence extended through the use of prompt engineering and function calling. Specific functions can be defined that the agent can call based on input and context. For more complex applications, an AI agent can be developed using frameworks such as Microsoft's AutoGen, which enables the creation of multi-agent systems. AutoGen supports communication between different AI agents and can be used for collaborative problem-solving approaches. In the present invention, such an AI agent can be equipped with additional components for blockchain integration. This can be achieved through the use of Web3 libraries such as Web3.py for Python or Web3.JavaScript code is used to enable access to blockchain networks and smart contracts. The AI ​​agent can then retrieve and evaluate the release rules stored on the blockchain, while simultaneously applying machine learning methods for decision-making.

[0047] The invention according to claim 1 offers several decisive advantages over the prior art. First, the combination of release rules stored in a blockchain with machine learning methods enables significantly more flexible and, at the same time, controlled release of automated actions by AI systems. This represents a significant improvement over conventional approaches, which are often limited to rigid, rule-based systems or general governance principles. Furthermore, the use of blockchain technology ensures a high degree of transparency and tamper-proof security in the storage and management of the release rules. This directly addresses the challenges of existing AI governance solutions, which often struggle to define and monitor the specific authorizations and powers of AI systems in a traceable manner on a case-by-case basis.

[0048] Another significant advantage of the invention lies in the use of an agent device for evaluating the rule data set. This intelligent component makes it possible to apply the release rules, thus authorizing further actions. Subsequently, in the context of the respective situation, a

[0049] NC-2025-1131 8 Integration of machine learning methods enables a case-specific, more in-depth analysis to determine suitable actions and timing for those actions. The agent system can learn from experience and continuously improve its decision-making. This leads to significantly greater adaptability and efficiency in releasing automated actions than would be possible with conventional, purely rule-based systems. The invention also addresses the limitations of current authorization protocols such as OAuth 2.0, which are primarily focused on access control and do not adequately consider the more complex aspects of AI agents' decision-making authority. By combining blockchain-based release rules and machine learning, the invention creates a comprehensive system for authorizing and legitimizing AI systems that goes far beyond simple access control mechanisms.Finally, the invention offers a solution to the challenge of reconciling the flexibility and adaptability of AI systems with the need for clear rules and controls. This is particularly relevant in areas where AI systems act on behalf of people or organizations and potentially make far-reaching decisions. The proposed solution makes it possible to leverage the advantages of advanced AI technologies without neglecting control and accountability. This enables the safe and responsible use of AI systems in various application areas, representing a significant advancement in AI governance.

[0050] In a preferred embodiment of the computer-implemented method according to the invention, a smart contract is used for the release rules. The use of smart contracts offers the advantage that the release rules can be executed automatically and transparently on the blockchain. This significantly increases the security and traceability of the release process. Smart contracts can be programmed to represent complex conditions and dependencies, enabling a flexible yet controlled implementation of the release rules. Alternatively, the release rules could also be stored in the blockchain in the form of simple if-then statements, but this would offer less flexibility and fewer automation possibilities.

[0051] In a further preferred embodiment of the computer-implemented method according to the invention, the release rules comprise at least one of the following data structures: non-fungible tokens, fungible tokens, or coins. The use of these blockchain-based data structures enables a differentiated and flexible representation of permissions and values ​​within the release rules. Non-fungible tokens can, for example, represent unique authorizations or specific powers of attorney, while fungible tokens and coins can be used for standardized access rights or resource allocations. Coins could serve as a mechanism for assigning priorities or as a means of controlling resource usage within the system. This variety of data structures allows for a precise and granular representation of different aspects of the release rules.Alternatively, the release rules could also be implemented in the form of simple boolean values ​​or numerical thresholds, but this would offer less flexibility and expressiveness.

[0052] NC-2025-1131 9 In a preferred further development, the data structures govern the granting and monitoring of authorization. Granting authorization can, for example, include allowing a digital agent to make medical diagnoses. Monitoring the authorization focuses on the decisions made or actions taken based on the authorization. In the field of medical diagnosis, this refers, for example, to the conformity of a specific diagnosis with the state of scientific knowledge ("real-world evidence"). In another preferred embodiment of the computer-implemented method according to the invention, interoperability standards are taken into account. These can, in principle, refer to protocols such as AuthZen or standards from ISO / IEC JTC 1, ITU-T, and / or OAuth of corresponding organizations such as the IETF, OpenID Foundation, etc.Cloud Native Computing Foundation access rights must be expanded to include the scope of authorizations.

[0053] In another preferred embodiment of the computer-implemented method according to the invention, the release rules take into account a person's identity. Furthermore, the agent system can be configured to perform risk monitoring regarding possible falsification of the person's identity. In other words, the identities underlying the original authorization (i.e., the identity of the person with the role of PIP or PAP) are monitored with respect to any risks.

[0054] In a further preferred embodiment of the computer-implemented method according to the invention, the machine learning process comprises a computer learning agent (CL agent). The use of a CL agent enables intelligent and adaptive evaluation of the release rules. The CL agent can recognize complex relationships, learn from experience, and continuously improve its decision-making. This leads to a significantly more flexible and context-aware application of the release rules than would be possible with static rule sets. The CL agent can also incorporate various factors and data sources into its decision-making, resulting in a more comprehensive and precise assessment of the release situation. Suitable implementation methods include, for example, a so-called "Large Language Model (LLM)" architecture. Alternatively, the machine learning process could also be based on simpler statistical models or decision trees.AI governance is thus managed by an independent AI support system, namely through the AI ​​agent. The AI ​​agent monitors and controls the use of individual AI systems or digital agents by selecting the appropriate contract type from among various smart contract and / or token types based on AI principles, authorizing the relevant AI or digital agent (including the organization's name, the authorizing party's name, the scope of the authorization such as specific powers, types of transactions, subscription amount, and regional coverage), and creating documentation and transparency (programming languages ​​such as XACML 3.0 and Alfa can be used for this purpose). Furthermore, intelligent contract and token management can be implemented by automating the creation, monitoring, and management of smart contracts or tokens (using applications such as Alchemy, Infura, Etherscan for Ethereum, and / or the Solana Program Library and Solana Web3).(JS for Solana and / or Binance Smart Chain) can be used. Direct identity mapping of access authorization or indirect monitoring of access control procedures such as OAuth or RBAC, ABAC, and PBAC can also be advantageously employed. Verification processes for validating transactions and data recorded in the blockchain, including ongoing risk assessment, are also included.

[0055] NC-2025-1131 10 implements patterns and trends in blockchain data for informed decision-making and can also optimize resource utilization within a blockchain network.

[0056] The following is a first detailed example of how to design and train the AI ​​agent.

[0057] The AI ​​agent is based on a hybrid approach. Rule-based elements are used for unambiguous checks, such as verifying the identity of a human user or their login credentials. A statistical AI-based approach is used for more ambiguous checks. A prime example of statistical AI-based controls is security checks to assess whether an agent might be exceeding its intended mandate in the context of a particular decision or transaction. Different approaches play a role in the specific models: Primary AI-based checks run on a general LLM (in some variants fine-tuned) with sophisticated prompts. For additional checks, custom models can be used in selected processes, for example, for risk assessments based on known characteristics.In these cases, the processed data is essentially text information.

[0058] The input data primarily comprises actors, actions, and authorizations, but can be supplemented with additional context. For example, if an agent proposes a clinical diagnosis code, the input would list the systems involved (agent, data sources, target system) as actors, each with a textual actor description as context, the proposed code and its justification (if available), and the full context of the authorization the agent relies on to perform the transaction. The outputs are risk and trust levels with justifications. The main input data is primarily procedural and does not require preprocessing. Regarding textual context information, AI agents can be configured to interpret missing context as a risk or lack of trust.

[0059] Model training can be performed outside the AI ​​ecosystem beforehand. The platform serves only to provide and utilize these models, and the model lifecycle must be managed externally. Regarding the general LLM (Large Lifecycle Management), customer-specific fine-tuning is not initially required. Improving the results through supervised refinement (human user feedback) is possible in future development.

[0060] The AI ​​agent and the method according to the invention are offered either as an installable software program or "as a Service," meaning they are fully hosted and managed by the provider. For individual deployment in the user's own public cloud environment, the size depends on the number of agents and the volume of decisions or actions these agents produce. In all cases, the AI ​​agent environment is not a model training environment. All efforts required for model training or fine-tuning within the project take place outside the platform in a suitably sized environment. Similarly, the core LLM functionality operates on the basis of Public Cloud Foundation Model Services.

[0061] NC-2025-1131 11The operation of the trained machine learning procedure thus takes place in the cloud.

[0062] The technical problem being addressed in the real world is that agentic AI is increasingly being used with agents serving different purposes and originating from different vendors based on varying implementations. The additional governance layer of the AI ​​agent ensures that only properly authorized agents are permitted, and scope audits indicate elevated risk levels if agents inadvertently operate outside their permitted scope.

[0063] To obtain training data, the AI ​​agent's behavior is manually tested using a series of test cases and real-world workloads. A comparison can be made with manually (human-determined) approvals. This process validates the desired results within the context of the specific use case. It is important to note that the AI ​​agent's mixed-model approach (including rules) guarantees a level of safety at least as good as that of a purely rule-based system. The statistics-based AI components within the AI ​​agent would never approve an action blocked by a rule; however, they would flag actions that have passed rule-based checks if they appear risky or potentially outside the scope of the application.

[0064] To ensure that the AI ​​agent works reliably, it is trained in a preferred version of the inventive method using a clearly defined prompt engineering strategy. Among others, the following strategies can be used:

[0065] System Prompting: Integration into the broader AI governance framework.

[0066] Few shots: Examples of judgments from court databases (justice portals, OpenJur, DeJure etc.) or role assessments (Kienbaum, Mercer, Hay, etc.).

[0067] Contextual Prompting: Situational factors regarding role and authority

[0068] Chain of Thoughts: Establishing a logical line of reasoning, e.g., from budget to subscription limits and powers of attorney.

[0069] Tree of Thoughts: Mapping of several logical lines of reasoning and scenarios, e.g. from functional responsibility (IT, purchasing, HR, strategy, etc.) to required decision-making skills (CIO as “coach”, “service provider” or “entrepreneur”, etc.) and corresponding powers.

[0070] In a preferred configuration, the prompt input primarily includes actors, actions, and permissions, but can be supplemented with additional context. For example, if an agent proposes a clinical diagnosis, the actor input requires listing the systems involved (agent, data sources, target system against which to store), each with a textual actor description as context, and the proposed code and justification, if available (textual description), as well as the full context of the approval on which the agent relies to execute the transaction.

[0071] NC-2025-1131 12 For example, the most important input data is primarily process-related and does not need to be preprocessed. Regarding textual context information, G-agents can be configured to view a lack of context as a risk / lack of trust.

[0072] Furthermore, in some variants, the results can include corresponding risk and confidence levels with justifications. The additional governance layer of the G-Agent ensures that only properly authorized agents are permitted, and scope checks indicate increased risk levels when agents operate outside their authorized scope. Pilot applications demonstrate that only authorized actions are allowed, and unauthorized actions are rejected or appropriately flagged.

[0073] The accuracy of any statistics-based AI has its limits. However, due to the multifaceted nature of AI agent implementation, this does not lead to any security risks compared to purely rule-based controls. On the other hand, unnecessarily stringent risk assessments could create operational obstacles. This can be addressed by adjusting risk and alert thresholds globally or for specific audits.

[0074] In a further preferred embodiment of the computer-implemented method according to the invention, the AI ​​agent comprises a multi-layered architecture containing at least one of the following layers: retrieval layer, orchestration layer, reasoning layer, learning layer, and compliance layer. To verify compliance with the mandate, the integration of further components may be necessary; for example, in the case of verifying the compliance of a diagnosis, the integration of RAG AI for researching the state of the art or evidence. This multi-layered architecture enables a modular and efficient organization of the various functions of the AI ​​agent. The retrieval layer can be responsible for procuring relevant information (e.g., from the blockchain), while the orchestration layer handles the coordination of various tasks and processes.The reasoning layer enables complex inferences and decision-making, while the learning layer ensures the agent's continuous improvement. The compliance layer ensures that all of the agent's actions are in accordance with predefined rules and guidelines. This structure allows for flexible adaptation and expansion of the AI ​​agent's capabilities. Alternatively, the AI ​​agent could be implemented as a monolithic system, but this would limit maintainability and scalability.

[0075] Power of attorney concepts are modeled using, for example, XACML 3.0 and its corresponding data structures. This requires careful design to capture the legal nuances. XACML is well-suited for this purpose, as powers of attorney fundamentally involve authorization decisions based on delegated authority. Just as with access control and its various approaches (ABAC, RBAC, PBAC, etc.), policies, attributes, roles (P*P, etc.), and other elements can be comprehensively represented in the power of attorney framework.

[0076] Use criteria. For example, the delegation functions of XACML 3.0 can represent powers of attorney, in which the principal transfers certain powers to the agent. They would define, in particular, the following:

[0077] Delegation guidelines that define which powers are transferred.

[0078] NC-2025-1131 13 Limitations on Scope that Define the Boundaries of the Delegated Powers

[0079] • Time restrictions for limited-term powers of attorney

[0080] A corresponding review of the power of attorney must then take into account, among other things, the following:

[0081] • Verification of powers - Confirmation that the power of attorney is valid and active

[0082] • Review of the scope of application - ensuring that the requested measure falls within the scope of the delegated powers

[0083] • Status of the client - verification of the client's legal capacity and the position of the authorized representative

[0084] • Revocation process - verification of whether the power of attorney has been revoked

[0085] XACML can computationally enforce the rules for powers of attorney, but it cannot capture all legal intricacies such as fiduciary duties, good faith requirements, or complex differences between jurisdictions. Therefore, XACML is used as part of a broader G-agent system that also includes verifying compliance with legal regulations.

[0086] Alfa is preferred. Alfa offers a more readable way to express XACML policies for authorization scenarios. Advantages of Alfa for this use case include:

[0087] • Readability: Easier to write and maintain than raw XACML

[0088] • Type safety: Improved validation of attribute types

[0089] • Modularity: Reusable policy components can be defined

[0090] • Clarity of business rules: Makes the delegation logic more transparent

[0091] Alfa compiles to standard XACML 3.0, so you get full expressiveness with a better authoring experience.

[0092] In another preferred embodiment of the computer-implemented method according to the invention, the AI ​​agent comprises a lead AI agent and at least one team AI agent. A "lead AI agent" is a superior AI component within a hierarchical agent architecture that acts as a central coordination and control instance. The lead AI agent can make strategic decisions, monitor the overall system performance, and consider complex dependencies between various automated actions. In some aspects, the lead AI agent can act as an intermediary between the central agent facility and downstream agents, forwarding authorizations and monitoring compliance with higher-level governance policies.The lead AI agent can also select and evaluate different available contract types between AI systems and initiate performance comparisons between different AI systems. A "team AI"...

[0093] NC-2025-1131 "14Agent" designates a specialized AI component that operates as an execution unit within the hierarchical structure and focuses on specific tasks or domains. Team AI agents can process direct authorization requests for specific automated actions, utilizing the authority delegated by the Lead AI agent. In some cases, Team AI agents can make local decisions within their defined scope of competence without consulting the Lead AI agent. Team AI agents can interact with resource components to access specific resources and provide feedback on the execution of automated actions to the Lead AI agent, thereby contributing to the continuous improvement of the overall system.

[0094] The Lead AI Agent performs several key tasks: the intelligent selection of AI systems or agents suitable for a given application, the management of the authorization process through centralized (Lead Agent and Agent Team) versus decentralized processes (Lead Agent authorizes Agent Team), the AI-based evaluation and selection of the various available contract types between AI systems or agents, the setup and execution of performance comparisons between different AI systems or agents, the intelligent verification of security levels between different AI systems or agents, and the evaluation and scoring of various AI system providers or operators in specific application areas. In other words, the Lead AI Agent acts as a governance agent, functioning as a kind of "super-agent" or "meta-agent" and managing a "marketplace for AI systems."operates, develops and orchestrates digital agents.

[0095] In another preferred embodiment of the computer-implemented method according to the invention, the AI ​​agent is used to evaluate a medical data record from a medical database and to authorize the provision of a medical diagnosis record if the medical data record meets at least one predefined diagnostic criterion. This application of the AI ​​agent in the medical field enables efficient and precise pre-selection of diagnostic cases. The AI ​​agent can analyze complex medical data and identify relevant patterns that point to specific diagnoses. This can support the work of physicians by allowing them to focus on the cases most likely to require a particular diagnosis or treatment. The use of predefined diagnostic criteria ensures that the process remains standardized and traceable.One possible diagnostic criterion could be the existence of a declaration of consent from a doctor and / or an affected patient to process the data using an AI agent for diagnostic purposes.

[0096] In another preferred embodiment of the computer-implemented method according to the invention, the AI ​​agent is used to compare the physician's diagnostic dataset with a diagnostic dataset determined by a machine learning method and, in the case of a match, to provide the physician's diagnostic dataset for treatment. This comparison process enables additional validation of the physician's diagnosis by the AI ​​agent. By comparing its own machine-learning-generated diagnosis with that of the physician, the AI ​​agent can achieve greater accuracy and reliability of the diagnosis. In the case of a match, the diagnosis is confirmed, which increases confidence in the treatment decision. This approach combines the expertise of human physicians with the analytical capabilities of AI.

[0097] NC-2025-1131 15 Capabilities of the AI ​​system. Alternatively, the AI ​​agent could also be used to identify differences between diagnoses and return them to the physician for further review, representing a more interactive form of decision support. The retrieval layer, for example, can process structured medical datasets in various formats. For a breast cancer detection diagnostic system, for instance, X-ray images can be provided as DICOM (Digital Imaging and Communications in Medicine) files, which, in addition to the image data, also contain metadata such as patient age, acquisition date, and device settings. The data structures typically include image matrices with pixel values ​​stored in standardized formats such as 16-bit grayscale values. Additionally, structured annotation data in JSON or XML format, containing the precise coordinates and classifications of tumors, can be provided.The orchestration layer coordinates the data flow between different processing modules and can use metadata objects containing information about data origin, processing status, and quality ratings. This layer exchanges control messages, which can be implemented as structured data formats. In this example, the reasoning layer works with feature vectors extracted from the image data, as well as with probabilistic models representing probability distributions for different diagnostic classes. The information is exchanged as numerical arrays or tensors, which can contain both raw data and calculated features. The learning layer manages training datasets consisting of input-output pairs—for example, X-ray images coupled with verified diagnoses from radiologists. This layer exchanges gradient information and model parameters, such as...They are structured as multidimensional arrays. The compliance layer uses audit logs in structured formats that include timestamps, user identifications, and action descriptions. These can be stored as JSON objects or in relational database structures to ensure traceability and regulatory compliance.

[0098] In a further preferred embodiment of the computer-implemented method according to the invention, the KL agent is used to evaluate a supply chain data set from a supply chain database and to create a production planning data set if the supply chain data set meets at least one predefined operating criterion. The predefined operating criterion can, for example, include the requirement that the supplier does not promote child labor. Another operating criterion can be an environmental protection indicator that specifies how environmentally friendly the supplier's business practices are. Accordingly, an optimized production planning data set can be determined that, for example, avoids suppliers using child labor and preferentially includes particularly environmentally friendly companies. This application of the KL agent in the area of ​​supply chain and production planning enables efficient and dynamic optimization of operational processes.The AI ​​agent can analyze complex supply chain data, recognize patterns, and make predictions relevant for effective production planning. By considering predefined operational criteria, it ensures that the generated production planning datasets meet the specific requirements and goals of the company. This leads to improved resource utilization, reduced costs, and increased production efficiency.

[0099] NC-2025-1131 16 In another preferred embodiment of the computer-implemented method according to the invention, the AI ​​agent is used to compare the supply chain dataset with a supply chain reference dataset determined by a machine learning method and to adjust the supply chain dataset based on an updated operating criterion when a difference is found. This comparison and adjustment process enables continuous optimization and updating of the supply chain data. By comparing it with a machine-learned reference dataset, the AI ​​agent can identify deviations or potential improvements in the current supply chain. The ability to adjust the supply chain dataset based on updated operating criteria ensures that the supply chain is always up-to-date and optimally aligned with current business conditions.This can lead to improved adaptability, efficiency, and competitiveness for the company. Alternatively, the comparison and adjustment of supply chain data could also be carried out manually by experts, but this would be more time-consuming and potentially less accurate, especially when processing large volumes of data.

[0100] In another preferred embodiment of the computer-implemented method according to the invention, the AI ​​agent is used to monitor a robot so that physical actions by the robot are authorized if the physical actions meet at least one predefined safety criterion. This application of the AI ​​agent in the robot control enables intelligent and adaptive safety monitoring. The AI ​​agent can analyze the robot's movements and actions in real time and compare them with predefined safety criteria. This allows for fast and precise decision-making as to whether a particular physical action by the robot is safe and can be authorized. This approach can increase safety in human-robot collaborations while simultaneously optimizing the efficiency of robot operations.The AI ​​agent can also learn from experience and continuously improve its monitoring capabilities. Alternatively, the monitoring and approval of robot actions could also be carried out by hard-coded safety algorithms, which, however, might be less flexible in responding to unforeseen situations and offer less potential for continuous improvement.

[0101] Based on known data processing arrangements for releasing an automated action, the invention further addresses the challenge of providing a data processing arrangement that enables a comparatively more flexible and simultaneously controlled release of automated actions by AI systems.

[0102] The invention solves this problem by means of a data processing arrangement according to claim 12. Preferred embodiments are set forth in dependent claims 13 to 15, wherein the same advantages apply as initially described for the computer-implemented method according to the invention. Based on known computer program products for releasing an automated action, the invention further addresses the challenge of providing a computer program product that

[0103] NC-2025-1131 enables comparatively more flexible and simultaneously controlled release of automated actions by AI systems.

[0104] The invention solves this problem by means of a computer program product according to claim 16. The same advantages as initially explained for the computer-implemented method according to the invention apply analogously.

[0105] Two further detailed embodiments of applications of the method according to the invention are explained below.

[0106] One example illustrates the application in the healthcare sector. Since healthcare services are complex, simply delegating authority via tokens is usually insufficient. This example therefore demonstrates how AI-based decision support for physicians can be combined with smart contract-based governance. A digitalization strategy for healthcare providers enables a holistic view of digitalization. This strategic perspective considers key trends in healthcare and patient needs, encompassing benefits, necessary processes, architecture, and digital competencies. A strategy-driven approach addresses digitalization beyond individual use cases, thus preventing the need to "see the forest for the trees."

[0107] Healthcare providers must leverage proven new technologies such as AI, VR, ML, cloud computing, and robotics. AI can both ensure the utilization of existing expertise from experienced practitioners across the organization and further develop this expertise through data utilization and evidence generation for even better therapies. The compelling use of AI and data will thus help to explore and improve effectiveness beyond conventional quality assurance. The AI-driven approach encompasses both comprehensive data aggregation across various sources and in-depth, treatment-specific analyses.

[0108] Therefore, data governance must evolve into AI governance. Scientific experience in developing evidence through real-world data (i.e., beyond ex-ante clinical trials) has been rather underdeveloped to date. AI governance helps to thoroughly structure the process in order to maintain the trust of chief physicians in hospitals in the future and to boldly utilize AI. AI systems should be based on real-world evidence for diagnostics and treatments. Since this must be clearly defined within the organization, e.g., as roles and responsibilities, the authority of such AI must be included. Smart contracts can help monitor the compliance of such AI. Newly generated evidence based on real-world data must be clearly differentiated and subject to approval.Therefore, AI governance requires a genuine transformation process – not limited to a “technical” governance issue – in which tech and med cultures come together, appreciate each other, and create a new, innovation-driven digital health care mindset.

[0109] This can be illustrated by the example of representing real-world evidence for breast cancer detection in a smart contract. This topic can be complex, but here is a simplified scenario.

[0110] NC-2025-1131 18 Illustration: Real-world evidence databases containing patient data, diagnoses, and treatment histories serve as the data source. The smart contract functions include data validation, where the smart contract receives data from validated medical databases; conditional validation, where the smart contract checks whether the data meets certain criteria (e.g., age, family history, mammography results); and diagnostic recommendation, where the smart contract provides a diagnostic recommendation based on predefined medical criteria, which is compared with the recommendation of the physician-supporting AI system.

[0111] The AI ​​governance process includes expert review, where the healthcare provider or physician reviews the smart contract's recommendation, compares it to the AI ​​system's recommendation, and either confirms or rejects it. There is also an automated notification feature, where the smart contract automatically sends notifications to patients or physicians based on the results. As new insights are generated based on real-world evidence, reviews and approvals are initiated to subsequently inform both the AI ​​and AI governance related to the smart contract.

[0112] As a further example, an application from the manufacturing industry is presented. Since both the supply chain and shop floor operations in manufacturing are complex, simply delegating authority via tokens is insufficient. This example therefore demonstrates how AI-based design can be combined with smart contract-based governance. Shop floor operations in manufacturing have previously been comprehensively addressed using standard operating procedures (SOPs) and parameters to ensure good manufacturing practices (GMP). Process analyses have attempted to understand the stochastic aspects and increase transparency, where operator judgment and thus heuristic decision-making are typically crucial. Many experts have spent decades working to explicitly translate such heuristics into rule definitions.Software companies have tried to translate these heuristics into suitable code; however, this has yielded mixed results depending on the complexity of the operations.

[0113] Traditionally, the approach to developing and defining operational processes has been rule-based. Supply chain managers and shop floor operators have relied on rules for lot-sizing optimization, sequencing, network and material balancing, and so on. However, a weakness of such a rule-based approach is its limited capacity to handle the increasing complexity and customization of manufacturing. There is a gap between seeing and knowing to recognize existing complexity, and a gap between knowing and acting to manage complexity effectively. Technology for detecting complexity (and thus closing the see-know gap) through improved diagnostic tools, digital twins, and sensors has developed rapidly. For example, tracking and tracing tools help to understand the structure of the supply chain network.

[0114] For managing higher complexity (i.e., closing the knowledge-action gap), the requirements regarding self-organization have always been clearly defined, but there have been few tools and

[0115] NC-2025-1131 19 solutions that helped with practical implementation. In shop floor operations, for example, early attempts referred to Wildemann's modular factory, Warnecke's fractals, then Ptak's DDMRP and the beginnings of machine learning. Suitable technology for handling higher complexity in a self-organizing manner and at scale remained immature for a long time.

[0116] This is where artificial intelligence (AI) and large language models (LLM) come into play. Autonomous driving, for example, has evolved from a rule-based to an AI- and LLM-based system, such as Tesla's Full Self-Driving (FSD) technology. FSD 12 was based on a new concept that Tesla believes will transform autonomous vehicles and represent a leap toward artificial general intelligence capable of operating in real-world physical situations. Instead of relying on hundreds of thousands of rules, algorithms, or lines of code like all previous versions of self-driving software, this new system taught itself how to drive by processing billions of video frames of people operating a vehicle. Similarly, ChatGPT and other large language model chatbots can be trained to generate responses by processing billions of words of human text.

[0117] This means that manufacturing becomes self-trained and self-organizing, rather than rule-based in the traditional sense. Instead of teaching a "golden standard" based on rules, AI and LLM will mimic best practices. For shop floor operations, resilience is enhanced by imitating successful shop floor and supply chain managers. Faced with a diagnosis, the neural network chooses a path based on what operators have successfully done in thousands of similar situations. Just as Tesla had to analyze millions of video clips of driving situations, manufacturing companies will need to feed their systems with a large number of quality-assured examples of effective operations.

[0118] The sheer volume of data, which facilitates self-learning, will not only enable the imitation of practices, but there is a good chance that it will create new practices for even more effective management of the manufacturing supply chain and operations in a "batch size 1" world.

[0119] This means that data governance must evolve towards AI readiness. Manufacturing chief operating officers need to be able to determine the resilience of their supply chain and feel comfortable with GMP compliance. While processes exist to modify existing practices, they are not necessarily AI-compatible. Therefore, AI governance requires a genuine transformation process—not limited to a purely "technical" governance issue—where AI and engineering cultures converge, mutually value each other, and create a new, innovation-driven digital manufacturing mindset.

[0120] A good example is a representation of current PPS best practices regarding the production of a pharmaceutical product in a smart contract. This can be complex, but here is a simplified scenario for illustration: The data source consists of databases containing PPS schemas, supply chain planning, and shop floor histories. The smart contract functions include data validation, where the smart contract retrieves data from validated operational and supply chain databases; conditional checking, where the smart contract verifies whether the data meets certain criteria (e.g., lot size, product characteristics, order type, etc.); and a

[0121] NC-2025-1131 20PPS recommendation, where the smart contract provides a PPS recommendation based on predefined operational criteria, which is compared with the recommendation of the KL system that supports the operations team.

[0122] The AI ​​governance process includes an expert review where the operations manager reviews the smart contract's recommendation, compares it to the AI ​​system's recommendation, and either confirms or rejects it. There is also an automated notification feature where the smart contract automatically sends alerts to the operations governance team, such as the COO and CHRO, based on the results. As new best practices emerge based on real-world experience, reviews and approvals are initiated to subsequently inform both AI and AI governance related to the smart contract.

[0123] Non-restrictive and non-exhaustive examples are described with reference to the following figures.

[0124] The following schematic diagrams illustrate the invention:

[0125] Figure 1 is a flowchart of a computer-implemented method according to the invention for

[0126] Release of an automated action, and

[0127] Figure 2 shows a sequence diagram of an embodiment of the invention.

[0128] Authorization procedure for a AI agent, and

[0129] Figure 3 is a system diagram illustrating different variants of authorization agents.

[0130] The following description sets out exemplary aspects of the present disclosure. However, it should be noted that this description is not intended to limit the scope of the present invention. Rather, the description also includes combinations and modifications of the exemplary aspects described herein.

[0131] Figure 1 shows a flowchart of a computer-implemented method 50 according to the invention for releasing an automated action. The method integrates all roles of the P*P architecture described above. The method comprises several successive steps, which are shown in logical order. For example, a verification of the persons involved can be performed before the start of the depicted method.

[0132] The first step (52) involves providing a rule set with approval rules in at least one block of a blockchain. This step is fundamental to the process, as it lays the foundation for the subsequent decision-making processes. The use of a blockchain ensures a high degree of security and immutability of the rules. In the next step (54), the rule set is retrieved using a blockchain read device. This device is specifically designed to read the rules stored in the blockchain.

[0133] NC-2025-1131 21 reads data efficiently and reliably. The third step 56 involves evaluating the rule data set using an agent setup. This takes into account the release rules and a machine learning procedure for a release decision for the automated action. The agent setup could, for example, be a complex neural network or another advanced AI system capable of interpreting the rules and applying them to the specific context. In the fourth step 58, the release rules are verified. This step represents a critical decision point where the system makes a decision based on the evaluated rules and the results of the machine learning procedure.

[0134] The last two steps represent the possible outcomes of the decision-making process. Step 60 represents the approval of the automated action if all criteria are met. Step 62, on the other hand, represents the rejection of the action if the approval criteria are not met. The combination of blockchain-based rules and machine learning enables flexible yet controlled decision-making. This is particularly advantageous in dynamic environments where conditions can change rapidly, but a certain degree of predictability and traceability must still be ensured.

[0135] Figure 2 illustrates a sequence diagram of an embodiment of the method according to the invention with a KL agent in a centralized configuration without OAuth authentication. The diagram shows the interactions between different components of the system over time (with the arrows pointing downwards from the top). The components shown include the authorization component 21 (PAP), the user component 22 (PIP) – both components, PAP and PIP, have undergone identity verification (PVP) with respect to the individuals acting on their behalf – the KL agent 23 (PDP), the lead KL agent 24 (PEP), the team KL agent 25 (PEP), and a resource component 26. These components represent different roles and functions within the authorization system. The lead KL agent 24 acts as the higher-level coordinating instance within the hierarchical KL structure and performs several central tasks.It can process authorization requests from the agent setup and evaluate them according to the release rules stored on the blockchain. The Lead Kl Agent can act as an intermediary between the central agent setup and the downstream Team Kl Agents 25, forwarding authorizations and monitoring compliance with overarching governance policies. In some aspects, the Lead Kl Agent can also make strategic decisions affecting multiple Team Kl Agents, taking into account complex dependencies between different automated actions. It can also monitor the overall performance of the Kl Agent team and adjust authorization strategies as needed. The Team Kl Agent 25 operates as a specialized execution unit within the Kl hierarchy, focusing on specific tasks or domains.It can process direct authorization requests for specific automated actions, utilizing the permissions delegated by the Lead Kl agent. The Team Kl agent can interact with Resource Component 26 to access specific resources required to execute the authorized actions. In some cases, the Team Kl agent can also make local decisions within its defined scope.

[0136] NC-2025-1131 22 competence area, without having to consult the Lead Kl Agent. It can provide feedback on the execution of automated actions to the Lead Kl Agent and thereby contribute to the continuous improvement of the overall system.

[0137] The process begins with a series of online authorization steps 27, which take place between the authorization component 21 (PAP) and the user component 22 (PIP). These steps are based on the verification of the identities performing these roles (PVP). These steps serve for the initial authentication and authorization of the user. This authorizes the Kl-Agent 23 (PDP) based on a verified user identity. A verification step 28 then follows between the user component 22 (PIP) and the Kl-Agent 23 with a user authorization, followed by a confirmation step 29 back to the user component 22 or authorization component 21. These steps ensure that the user has the necessary permissions. The authorization token step 30 between the authorization component 21 and the Kl-Agent 23 transmits the authorization information in the form of a token, e.g.,implemented as a smart contract or NFT on a blockchain.

[0138] Steps 31 to 43 below illustrate a cascade of authorization and delegation requests between the various AI components (AI Agent 23, Lead AI Agent 24, Team AI Agent 25) and the resource component 26. These steps demonstrate how authorization propagates through different levels of the system, with each component verifying and passing on its specific permissions. Delegation steps 33, 34, 38, and 39 are particularly noteworthy, showing how authorizations are passed from one AI component to the next, i.e., from the Lead AI Agent 24 to at least one Team AI Agent 25. This enables a flexible and scalable authorization structure that can adapt to complex organizational hierarchies. Access token steps 35 and 40, as well as resource access steps 41 and 43, clarify how ultimate access to the resource component 26 is controlled and executed.Any third party (relying party) that relies on the authority of the Lead or Team Kl (PEP) can verify this authority through access to the token. The Kl agent (PDP) monitors individual accesses, actions, and decisions of the Lead and Team Kl (PEP) for compliance with the given authorization.

[0139] This centralized configuration without OAuth authentication offers the advantage of direct control over the entire authorization process. Using a AI agent as the central control element enables consistent application of authorization rules across the entire system. At the same time, it provides the flexibility to integrate machine learning methods to continuously improve decision-making and adapt to changing conditions.

[0140] Figure 3 presents a system diagram illustrating different variants of authorization agents 11. The diagram is organized in a matrix structure and shows four main configurations, represented by boxes 1, 2, 3, and 4.

[0141] The vertical axis of the diagram represents team integration 5, which is divided into two main categories: Centralized team integration 7 and decentralized team integration 8. This distinction is crucial for the

[0142] NC-2025-1131 23 Architecture of the authorization system and influences how decisions are made and permissions are distributed. The horizontal axis describes the transparency over a power of attorney 6 and differentiates between systems with OAuth authorization 9 and without OAuth authorization 10. This distinction has significant implications for the implementation of the authorization process and interoperability with other systems.

[0143] Box 1 represents a configuration with centralized team integration and OAuth authorization. This option offers a high degree of control over the authorization process while utilizing the widely adopted OAuth standard. Box 2 shows centralized team integration without OAuth authorization. This configuration allows for a customized authorization solution that may be better adapted to specific requirements but is potentially less interoperable. Box 3 illustrates decentralized team integration with OAuth authorization. This option offers greater flexibility in the team structure while using standardized authorization protocols. Box 4 represents decentralized team integration without OAuth authorization. This configuration offers the highest flexibility and adaptability but requires more effort in implementation and maintenance.The diagram for different variants of authorization agents 11 provides a comprehensive overview of the possible implementation approaches. It enables developers and system architects to select the configuration best suited to their specific requirements.

[0144] A number of exemplary embodiments have been described. However, it is understood that various modifications can be made without deviating from the spirit and scope of the disclosure. Accordingly, alternative implementations also fall within the scope of protection of the following claims.

[0145] NC-2025-1131 24 REFERENCE MARK LIST

[0146] 1-4 boxes

[0147] 5 Team Integration

[0148] 6. Transparency regarding power of attorney

[0149] 7 Central Team Integration

[0150] 8 Decentralized Team Integration

[0151] 9. With OAuth authorization

[0152] 10 Without OAuth authorization

[0153] 11 Diagram of different variants of authorization agents 21 Authorization component

[0154] 22 User component

[0155] 23 Kl-Agent

[0156] 24 Lead Kl-Agent

[0157] 25 Team Kl-Agent

[0158] 26 Resource component

[0159] 27 Online Authorization

[0160] Steps 28-43

[0161] 50 Computer-implemented method

[0162] 52 Provisioning a rule data set in blockchain

[0163] 54 Retrieving the rule data set

[0164] 56 Evaluating the rule data set using agent setup 58 Checking release rules

[0165] 60 Release

[0166] 62 rejections

[0167] NC-2025-1131 25

Claims

PATENT CLAIMS 1. Computer-implemented method (50) for releasing an automated action, comprising: - Providing a rule data set with release rules in at least one block of a blockchain (52), and - retrieving the rule data set using a blockchain read device (54), characterized by - Evaluating the rule data set using an agent setup (56), taking into account the release rules and a machine learning procedure for a release decision (58) for the automated action.

2. Computer-implemented method (50) according to claim 1, characterized in that A smart contract is used for the release rules.

3. Computer-implemented method (50) according to claim 1 or 2, characterized in that The release rules must contain at least one of the following data structures: non-fungible tokens, fungible tokens, coins.

4. Computer-implemented method (50) according to one of the preceding claims, characterized in that the machine learning method comprises a KL agent (23).

5. Computer-implemented method (50) according to claim 4, characterized in that the AI ​​agent (23) comprises a multi-layered architecture containing at least one of the following layers: retrieval layer, orchestration layer, reasoning layer, learning layer, compliance layer.

6. Computer-implemented method (50) according to claim 4 or 5, characterized in that the AI ​​agent comprises a lead AI agent and at least one team AI agent.

7. Computer-implemented method (50) according to one of claims 4 to 6, characterized in that the AI ​​agent (23) is used to evaluate a medical data set from a medical database, and NC-2025-1131 26 to grant release (60) for the provision of a medical diagnosis record if the medical record meets at least one predefined diagnosis criterion.

8. Computer-implemented method (50) according to claim 7, characterized in that the AI ​​agent (23) is used to compare the medical diagnosis data set with a diagnosis data set determined by a machine learning method, and to provide the medical diagnosis data set for treatment in the event of a match.

9. Computer-implemented method (50) according to one of claims 4 to 6, characterized in that the KL agent (23) is used to evaluate a supply chain data set from a supply chain database and to create a production planning data set if the supply chain data set meets at least one predefined operating criterion.

10. Computer-implemented method (50) according to claim 9, characterized in that the AI ​​agent (23) is used to compare the supply chain data set with a supply chain reference data set determined by a machine learning method and to adjust the supply chain data set if there is a difference based on an updated operating criterion.

11. Computer-implemented method (50) according to one of the preceding claims, characterized in that the AI ​​agent (23) is used to monitor a robot such that physical actions of the robot are released if the physical actions meet at least one predetermined safety criterion.

12. Data processing order for the release of an automated action, comprising: - a blockchain which is operated by means of a computer network and is designed to provide a rule set with release rules in at least one block (52), and - a blockchain read device that is trained to retrieve the rule data record (54), characterized by - an agent facility trained to evaluate the rule data set (56), taking into account the release rules and a machine learning procedure for a release decision (58) for the automated action. NC-2025-1131 2713. Data processing arrangement according to claim 12, characterized in that The agent setup is trained to use a smart contract for the release rules.

14. Data processing arrangement according to claim 12 or 13, characterized in that The agent setup is trained to consider release rules that include at least one of the following data structures: non-fungible tokens, fungible tokens, coins.

15. Data processing arrangement according to one of claims 12 to 14, characterized in that the agent device is configured to employ a computer agent (23) with a machine learning method.

16. A computer program product comprising instructions which, when executed by a computer, cause the computer to perform the method according to any one of claims 1 to 10. NC-2025-1131 28