Secure the AI Estate as a System
PBSAI—the Practitioner’s Blueprint for Secure AI—is a research-based reference architecture for securing enterprise AI estates. Rather than treating individual models, agents, security tools, and governance processes as separate problems, PBSAI organizes them as a coordinated socio-technical system built around explicit responsibilities, bounded automation, shared context, structured evidence, human oversight, and governed execution.
AI Estate
An AI System Rarely Ends at the Model Boundary
Enterprise AI increasingly operates as part of a larger estate. Models call tools. Agents interact with data, identities, applications, security controls, and other agents. Human operators intervene, approve, investigate, and respond. Cloud and high-performance infrastructure provide the execution substrate.
PBSAI treats this larger socio-technical environment as the relevant security and governance boundary.
The research question is therefore broader than “How do we secure this model?” It becomes: “How do we organize, govern, observe, and defend an enterprise AI estate whose components can interact, reason, automate, delegate, and act?”
Models
LLMs, classical machine-learning models, anomaly detectors, and other analytic systems.
Agents & Orchestration
Tool-using agents, automated workers, workflows, and coordination layers that turn analysis into activity.
Data & Security Infrastructure
Data pipelines, identity systems, monitoring platforms, security tooling, control systems, and evidence stores.
People & Institutions
Analysts, operators, architects, governance functions, decision-makers, workflows, policies, and oversight.
From Point Solutions to Estate-Level Architecture
PBSAI explores how governance, cybersecurity, AI-enabled defense, and evidence can be designed as one coordinated systems-engineering problem rather than assembled from disconnected tools and ad hoc automation.
Estate-Level Thinking
Organize security and governance around the full AI estate rather than individual models, agents, prompts, or point products.
Bounded Agent Responsibilities
Give agent families explicit responsibilities, constraints, inputs, outputs, evidence obligations, and escalation conditions.
Evidence by Design
Treat provenance, context, decisions, outputs, and operational evidence as architectural work products rather than reconstructing them after an incident.
Governed Automation
Use deterministic logic where possible, constrain AI judgment where it is needed, and preserve human intervention for decisions that require it.
A Twelve-Domain Model for the Enterprise AI Estate
PBSAI decomposes the estate into twelve architectural responsibility domains spanning governance, security, operations, architecture, resilience, lifecycle management, and AI enablement. These domains are not intended to prescribe an organizational chart or require twelve separate products. They provide a common structure for reasoning about responsibilities, agents, tools, evidence, and dependencies.
Governance, Risk & Compliance
Policies, risk appetite, control objectives, compliance status, governance metrics, and oversight.
Asset, Configuration & Change
Assets, models, agents, data stores, configurations, changes, drift, and state reconciliation.
Identity, Credential & Access Management
Human, service, and agent identities, authentication, credentials, relationships, and authorization inputs.
Threat Intelligence, Awareness & Monitoring
Telemetry, intelligence, correlation, anomaly detection, behavioral analysis, monitoring, and hunting.
Protective Technologies & Hardening
Preventive and detective controls, hardening, patching, endpoint protection, network protection, and enforcement.
Data Security & Privacy
Classification, encryption, data-flow control, privacy, and protection of training, operational, and inference data.
Incident Response & Digital Forensics
Triage, investigation, remediation, case management, timelines, root-cause analysis, and lessons learned.
Resilience, Continuity & Recovery
Backup, continuity, disaster recovery, resilience exercises, operational recovery, and recovery evidence.
Security Architecture & Systems Engineering
Reference architectures, threat models, design review, architectural decisions, and systems-security alignment.
Physical & Environmental Security
Facilities, physical access, environmental conditions, sensors, and cyber-physical context affecting the estate.
Supply Chain & Lifecycle Security
Supplier risk, provenance, vulnerabilities, component dependencies, advisories, integrity, and lifecycle state.
Program Enablement, Knowledge & AI Validation
Security knowledge, analytics, orchestration support, data curation, independent AI validation, and cross-domain enablement.
A Secure AI Estate Needs a Baseline
PBSAI does not assume that intelligent agents can compensate for missing security foundations. The architecture begins with a minimum set of technical and governance capabilities that support trustworthy identity, observation, control, resilience, evidence, and oversight.
These foundations are particularly important because an AI-enabled security architecture can amplify both useful decisions and poorly governed ones.
If identity, attestation, telemetry, policy, or evidence foundations are weak, the architecture may first expose those weaknesses rather than immediately automate around them.
Deterministic First. Bounded AI Where Needed.
PBSAI does not assume that every security or governance decision should be delegated to a language model.
The reference pattern uses event-driven agents that perform deterministic processing first and invoke AI reasoning only where bounded judgment, interpretation, or language understanding is useful.
Context travels with the work. A shared MCP-style envelope can carry mission, intent, policy references, constraints, decision basis, provenance, classification, and related context, while structured Output Contracts define what an agent is expected to produce.
Receive Structured Context
Establish mission, task, policy, constraints, provenance, identity, and relevant evidence.
Apply Deterministic Logic
Use rules, validators, thresholds, policy constraints, and known technical logic before probabilistic reasoning.
Invoke Bounded AI Assistance
Use models for explicitly scoped reasoning, classification, interpretation, synthesis, or language tasks when appropriate.
Produce Structured Output
Emit schema-constrained work products with provenance, evidence, decision basis, and other required context.
Escalate or Govern Consequence
Preserve human review and applicable runtime-governance controls before consequential operational action.
Evidence Should Follow the Decision
One of PBSAI’s central architectural ideas is that governance evidence should not be fragmented across screenshots, isolated dashboards, chat histories, and unrelated tickets. Structured context and outputs can instead support an evidence graph connecting policies, assets, controls, models, agents, incidents, decisions, and outcomes.
PBSAI Is the Operational Architecture—not the Governance Layer Itself
PBSAI fits within SFT’s broader Runtime Governance Engineering architecture without replacing it. PBSAI organizes the enterprise AI estate and its multi-agent responsibilities. Runtime Governance Architecture defines the general governance model, while AGCP provides a deterministic reference realization for evaluating and controlling consequential execution.
Governance Intent
Policies, obligations, objectives, constraints, authorities, and decision rights establish what is meant to govern the system.
Governance Compilation
Authorized human governance can be translated into machine-evaluable semantics, rules, constraints, invariants, and evidence requirements.
RGA
Runtime Governance Architecture defines the general architecture for governing proposed state transitions across heterogeneous systems.
AGCP
AGCP provides deterministic proposal evaluation, canonical-state resolution, execution gating, structural refusal, lifecycle control, and governance evidence.
PBSAI
PBSAI organizes domains, bounded agent families, shared context, structured outputs, operational tools, and evidence-centered coordination across the AI estate.
Inspect the Architectures and Specifications Directly
PBSAI and AGCP are supported by public technical artifacts. The repositories allow researchers and practitioners to inspect evolving architecture, schemas, requirements, examples, conformance material, and implementation-oriented resources rather than relying only on descriptive web pages.
Public Reference Architecture Repository
The PBSAI repository supports the open reference architecture for secure enterprise AI estates. It is the natural technical companion to the PBSAI Governance Ecosystem paper and the archived Version 1.0.0 reference architecture.
The architecture is intended to support governed multi-agent workflows, specialized agent roles, agent identity and delegation, tool-use governance, governance continuity across agent boundaries, and the distinction between orchestration and execution-layer enforcement.
Public Specification Repository
The AGCP repository is the live technical source associated with the Artificial Intelligence Governance Control Plane specification. It supports the normative AGCP architecture and the engineering artifacts used to implement and evaluate runtime-governance behavior.
The repository includes material related to runtime-governance requirements, schemas and protocol behavior, lifecycle and ledger semantics, PDP/PEP relationships, conformance testing, and implementation traceability.
Live Repositories and Archived Releases Serve Different Purposes
The public GitHub repositories expose evolving technical work and are appropriate for implementation exploration, issue review, current development, examples, and technical collaboration. Archived releases and publication records provide stable references for version-specific technical claims.
Designed as an Overlay, Not a Rip-and-Replace Stack
PBSAI is intentionally tool-agnostic. The architecture is designed to sit above and around existing security, infrastructure, AI, and operations platforms rather than requiring organizations to replace established investments wholesale.
AI-Enabled Security Operations
One reference scenario uses PBSAI as a multi-agent management and evidence overlay across an enterprise security operations environment.
- existing SIEM and monitoring
- EDR and protective controls
- identity and access management
- SOAR and workflow automation
- cloud and data platforms
- governance and evidence workflows
Hyperscale & HPC-Backed AI Estates
The architecture also examines environments where large compute estates support production AI, security analytics, large-scale replay, hunting, model validation, and other high-volume workloads.
- multi-cluster infrastructure
- cloud and accelerator platforms
- integrated telemetry
- consistent attestation
- AI-assisted defensive analytics
- constrained automated response
A Reference Architecture Under Evaluation
PBSAI is currently best understood as a research architecture and engineering blueprint.
Its value is in making the enterprise AI-estate problem concrete: defining responsibilities, agent patterns, context, evidence, baseline assumptions, security relationships, governance boundaries, and testable hypotheses.
The next stage of the work includes reference implementations, shared schemas, testbeds, benchmarks, sector-specific overlays, and empirical evaluation across different deployment environments.
What Needs to Be Tested Next
PBSAI is intended to become increasingly empirical. The architecture defines questions that can be tested through prototypes, controlled experiments, pilot environments, shared benchmarks, reference implementations, and comparative studies.
Reference Implementations
Build representative agents, context envelopes, Output Contracts, evidence registries, and interoperability patterns that make the architecture executable.
Shared Schemas
Develop common structures for context, provenance, evidence, outputs, decisions, controls, identities, and cross-domain coordination.
Multi-Agent Testbeds
Evaluate bounded automation, coordination, investigation, response, oversight, and governance behavior in repeatable experimental environments.
Operational Metrics
Measure investigation latency, coverage, false alerts, response quality, analyst workload, automation failures, and other operational outcomes.
Governance Outcomes
Test whether structured evidence and domain responsibilities improve auditability, traceability, oversight, assurance, and governance clarity.
Sector-Specific Overlays
Explore how the architecture should adapt to differing technical, regulatory, operational, and mission contexts without losing its core governance principles.
The PBSAI Governance Ecosystem
The PBSAI Governance Ecosystem paper presents the multi-agent AI reference architecture for securing enterprise AI estates and provides the research context for the twelve-domain model, secure baseline, agent design patterns, shared context, Output Contracts, evidence architecture, deployment concepts, and evaluation agenda.
The archived PBSAI Reference Architecture Version 1.0.0 and its associated public repository provide a more implementation-oriented technical companion to that research paper.
Help Test What a Secure Enterprise AI Estate Should Look Like
PBSAI is intended to advance through implementation, experimentation, critique, benchmarking, open technical artifacts, and collaboration. SFT welcomes conversations with universities, researchers, enterprise security teams, AI architects, infrastructure providers, public institutions, and other organizations interested in multi-agent security, AI-estate governance, evidence architecture, reference implementations, runtime governance, or empirical evaluation.