Secure Enterprise AI Estates

Secure the AI Estate as a System

PBSAI—the Practitioner’s Blueprint for Secure AI—is a research-based reference architecture for securing enterprise AI estates. Rather than treating individual models, agents, security tools, and governance processes as separate problems, PBSAI organizes them as a coordinated socio-technical system built around explicit responsibilities, bounded automation, shared context, structured evidence, human oversight, and governed execution.

Enterprise
AI Estate
Models
Agents
Security Tooling
Human Workflows
Data Pipelines
Compute Fabric
The Unit of Analysis

An AI System Rarely Ends at the Model Boundary

Enterprise AI increasingly operates as part of a larger estate. Models call tools. Agents interact with data, identities, applications, security controls, and other agents. Human operators intervene, approve, investigate, and respond. Cloud and high-performance infrastructure provide the execution substrate.

PBSAI treats this larger socio-technical environment as the relevant security and governance boundary.

The research question is therefore broader than “How do we secure this model?” It becomes: “How do we organize, govern, observe, and defend an enterprise AI estate whose components can interact, reason, automate, delegate, and act?”

Models

LLMs, classical machine-learning models, anomaly detectors, and other analytic systems.

Agents & Orchestration

Tool-using agents, automated workers, workflows, and coordination layers that turn analysis into activity.

Data & Security Infrastructure

Data pipelines, identity systems, monitoring platforms, security tooling, control systems, and evidence stores.

People & Institutions

Analysts, operators, architects, governance functions, decision-makers, workflows, policies, and oversight.

PBSAI Research Premise

From Point Solutions to Estate-Level Architecture

PBSAI explores how governance, cybersecurity, AI-enabled defense, and evidence can be designed as one coordinated systems-engineering problem rather than assembled from disconnected tools and ad hoc automation.

PRINCIPLE 01

Estate-Level Thinking

Organize security and governance around the full AI estate rather than individual models, agents, prompts, or point products.

PRINCIPLE 02

Bounded Agent Responsibilities

Give agent families explicit responsibilities, constraints, inputs, outputs, evidence obligations, and escalation conditions.

PRINCIPLE 03

Evidence by Design

Treat provenance, context, decisions, outputs, and operational evidence as architectural work products rather than reconstructing them after an incident.

PRINCIPLE 04

Governed Automation

Use deterministic logic where possible, constrain AI judgment where it is needed, and preserve human intervention for decisions that require it.

PBSAI Architecture

A Twelve-Domain Model for the Enterprise AI Estate

PBSAI decomposes the estate into twelve architectural responsibility domains spanning governance, security, operations, architecture, resilience, lifecycle management, and AI enablement. These domains are not intended to prescribe an organizational chart or require twelve separate products. They provide a common structure for reasoning about responsibilities, agents, tools, evidence, and dependencies.

A

Governance, Risk & Compliance

Policies, risk appetite, control objectives, compliance status, governance metrics, and oversight.

B

Asset, Configuration & Change

Assets, models, agents, data stores, configurations, changes, drift, and state reconciliation.

C

Identity, Credential & Access Management

Human, service, and agent identities, authentication, credentials, relationships, and authorization inputs.

D

Threat Intelligence, Awareness & Monitoring

Telemetry, intelligence, correlation, anomaly detection, behavioral analysis, monitoring, and hunting.

E

Protective Technologies & Hardening

Preventive and detective controls, hardening, patching, endpoint protection, network protection, and enforcement.

F

Data Security & Privacy

Classification, encryption, data-flow control, privacy, and protection of training, operational, and inference data.

G

Incident Response & Digital Forensics

Triage, investigation, remediation, case management, timelines, root-cause analysis, and lessons learned.

H

Resilience, Continuity & Recovery

Backup, continuity, disaster recovery, resilience exercises, operational recovery, and recovery evidence.

I

Security Architecture & Systems Engineering

Reference architectures, threat models, design review, architectural decisions, and systems-security alignment.

J

Physical & Environmental Security

Facilities, physical access, environmental conditions, sensors, and cyber-physical context affecting the estate.

K

Supply Chain & Lifecycle Security

Supplier risk, provenance, vulnerabilities, component dependencies, advisories, integrity, and lifecycle state.

L

Program Enablement, Knowledge & AI Validation

Security knowledge, analytics, orchestration support, data curation, independent AI validation, and cross-domain enablement.

Before Adding More Autonomy

A Secure AI Estate Needs a Baseline

PBSAI does not assume that intelligent agents can compensate for missing security foundations. The architecture begins with a minimum set of technical and governance capabilities that support trustworthy identity, observation, control, resilience, evidence, and oversight.

These foundations are particularly important because an AI-enabled security architecture can amplify both useful decisions and poorly governed ones.

If identity, attestation, telemetry, policy, or evidence foundations are weak, the architecture may first expose those weaknesses rather than immediately automate around them.

Identity and access foundations for people, services, workloads, and agents
Centralized logging, telemetry, and operational visibility
Platform, workload, and agent attestation
Segmentation and zero-trust security posture
Backup, recovery, resilience, and continuity capabilities
Governance policies and technical control libraries
Human-in-the-loop thresholds and escalation rules
Evidence, schema, and high-value-asset registries
Agent Design Pattern

Deterministic First. Bounded AI Where Needed.

PBSAI does not assume that every security or governance decision should be delegated to a language model.

The reference pattern uses event-driven agents that perform deterministic processing first and invoke AI reasoning only where bounded judgment, interpretation, or language understanding is useful.

Context travels with the work. A shared MCP-style envelope can carry mission, intent, policy references, constraints, decision basis, provenance, classification, and related context, while structured Output Contracts define what an agent is expected to produce.

1

Receive Structured Context

Establish mission, task, policy, constraints, provenance, identity, and relevant evidence.

2

Apply Deterministic Logic

Use rules, validators, thresholds, policy constraints, and known technical logic before probabilistic reasoning.

3

Invoke Bounded AI Assistance

Use models for explicitly scoped reasoning, classification, interpretation, synthesis, or language tasks when appropriate.

4

Produce Structured Output

Emit schema-constrained work products with provenance, evidence, decision basis, and other required context.

5

Escalate or Govern Consequence

Preserve human review and applicable runtime-governance controls before consequential operational action.

Evidence-Centric Architecture

Evidence Should Follow the Decision

One of PBSAI’s central architectural ideas is that governance evidence should not be fragmented across screenshots, isolated dashboards, chat histories, and unrelated tickets. Structured context and outputs can instead support an evidence graph connecting policies, assets, controls, models, agents, incidents, decisions, and outcomes.

Policies & Constraints
Assets & Identities
Models & Agents
Events & Telemetry
Decisions & Outputs
Actions & Outcomes
Relationship to Runtime Governance Engineering

PBSAI Is the Operational Architecture—not the Governance Layer Itself

PBSAI fits within SFT’s broader Runtime Governance Engineering architecture without replacing it. PBSAI organizes the enterprise AI estate and its multi-agent responsibilities. Runtime Governance Architecture defines the general governance model, while AGCP provides a deterministic reference realization for evaluating and controlling consequential execution.

Layer 01

Governance Intent

Policies, obligations, objectives, constraints, authorities, and decision rights establish what is meant to govern the system.

Layer 02

Governance Compilation

Authorized human governance can be translated into machine-evaluable semantics, rules, constraints, invariants, and evidence requirements.

Layer 03

RGA

Runtime Governance Architecture defines the general architecture for governing proposed state transitions across heterogeneous systems.

Layer 04

AGCP

AGCP provides deterministic proposal evaluation, canonical-state resolution, execution gating, structural refusal, lifecycle control, and governance evidence.

Layer 05

PBSAI

PBSAI organizes domains, bounded agent families, shared context, structured outputs, operational tools, and evidence-centered coordination across the AI estate.

Open Technical Artifacts

Inspect the Architectures and Specifications Directly

PBSAI and AGCP are supported by public technical artifacts. The repositories allow researchers and practitioners to inspect evolving architecture, schemas, requirements, examples, conformance material, and implementation-oriented resources rather than relying only on descriptive web pages.

PBSAI

Public Reference Architecture Repository

The PBSAI repository supports the open reference architecture for secure enterprise AI estates. It is the natural technical companion to the PBSAI Governance Ecosystem paper and the archived Version 1.0.0 reference architecture.

The architecture is intended to support governed multi-agent workflows, specialized agent roles, agent identity and delegation, tool-use governance, governance continuity across agent boundaries, and the distinction between orchestration and execution-layer enforcement.

Repository github.com/jwillisSFT/pbsai-reference-architecture
Archive PBSAI Reference Architecture v1.0.0
DOI 10.5281/zenodo.20881774
Paper arXiv:2602.11301
AGCP

Public Specification Repository

The AGCP repository is the live technical source associated with the Artificial Intelligence Governance Control Plane specification. It supports the normative AGCP architecture and the engineering artifacts used to implement and evaluate runtime-governance behavior.

The repository includes material related to runtime-governance requirements, schemas and protocol behavior, lifecycle and ledger semantics, PDP/PEP relationships, conformance testing, and implementation traceability.

Repository github.com/jwillisSFT/agcp-spec
Specification AGCP Specification v1.0.0
DOI 10.5281/zenodo.20297616
Role Runtime-governance specification and conformance source
Repository & Version Discipline

Live Repositories and Archived Releases Serve Different Purposes

The public GitHub repositories expose evolving technical work and are appropriate for implementation exploration, issue review, current development, examples, and technical collaboration. Archived releases and publication records provide stable references for version-specific technical claims.

Reference Deployment Contexts

Designed as an Overlay, Not a Rip-and-Replace Stack

PBSAI is intentionally tool-agnostic. The architecture is designed to sit above and around existing security, infrastructure, AI, and operations platforms rather than requiring organizations to replace established investments wholesale.

Enterprise Environment

AI-Enabled Security Operations

One reference scenario uses PBSAI as a multi-agent management and evidence overlay across an enterprise security operations environment.

  • existing SIEM and monitoring
  • EDR and protective controls
  • identity and access management
  • SOAR and workflow automation
  • cloud and data platforms
  • governance and evidence workflows
Large-Scale Environment

Hyperscale & HPC-Backed AI Estates

The architecture also examines environments where large compute estates support production AI, security analytics, large-scale replay, hunting, model validation, and other high-volume workloads.

  • multi-cluster infrastructure
  • cloud and accelerator platforms
  • integrated telemetry
  • consistent attestation
  • AI-assisted defensive analytics
  • constrained automated response
Research Status

A Reference Architecture Under Evaluation

PBSAI is currently best understood as a research architecture and engineering blueprint.

Its value is in making the enterprise AI-estate problem concrete: defining responsibilities, agent patterns, context, evidence, baseline assumptions, security relationships, governance boundaries, and testable hypotheses.

The next stage of the work includes reference implementations, shared schemas, testbeds, benchmarks, sector-specific overlays, and empirical evaluation across different deployment environments.

Research Agenda

What Needs to Be Tested Next

PBSAI is intended to become increasingly empirical. The architecture defines questions that can be tested through prototypes, controlled experiments, pilot environments, shared benchmarks, reference implementations, and comparative studies.

Reference Implementations

Build representative agents, context envelopes, Output Contracts, evidence registries, and interoperability patterns that make the architecture executable.

Shared Schemas

Develop common structures for context, provenance, evidence, outputs, decisions, controls, identities, and cross-domain coordination.

Multi-Agent Testbeds

Evaluate bounded automation, coordination, investigation, response, oversight, and governance behavior in repeatable experimental environments.

Operational Metrics

Measure investigation latency, coverage, false alerts, response quality, analyst workload, automation failures, and other operational outcomes.

Governance Outcomes

Test whether structured evidence and domain responsibilities improve auditability, traceability, oversight, assurance, and governance clarity.

Sector-Specific Overlays

Explore how the architecture should adapt to differing technical, regulatory, operational, and mission contexts without losing its core governance principles.

Foundational Research

The PBSAI Governance Ecosystem

The PBSAI Governance Ecosystem paper presents the multi-agent AI reference architecture for securing enterprise AI estates and provides the research context for the twelve-domain model, secure baseline, agent design patterns, shared context, Output Contracts, evidence architecture, deployment concepts, and evaluation agenda.

The archived PBSAI Reference Architecture Version 1.0.0 and its associated public repository provide a more implementation-oriented technical companion to that research paper.

Research Collaboration

Help Test What a Secure Enterprise AI Estate Should Look Like

PBSAI is intended to advance through implementation, experimentation, critique, benchmarking, open technical artifacts, and collaboration. SFT welcomes conversations with universities, researchers, enterprise security teams, AI architects, infrastructure providers, public institutions, and other organizations interested in multi-agent security, AI-estate governance, evidence architecture, reference implementations, runtime governance, or empirical evaluation.

Research and repository status: PBSAI is a research-based, tool-agnostic reference architecture and engineering blueprint for secure enterprise AI estates. It is not presented as a completed commercial product, certification standard, or empirically validated industry benchmark. The PBSAI and AGCP GitHub repositories are evolving public technical sources. For version-specific claims, formal citation, conformance, or reproducible technical reference, use the applicable release, tag, archived publication, specification version, or DOI rather than relying solely on the current state of a live repository.