Jadwal Sholat

Memuat jadwal sholat…

Computer Science editorial

Open AccessOA2026

AgentKernel: The Trust-Native Agentic Operating System

A mandatory enforcement boundary for the full agent lifecycle
Zhenhua Zou; Sheng Guo; Qiuyang Zhan; Lepeng Zhao; Shuo Li; Zhuotao Liu· 2026· DOI 10.48550/arXiv.2609.29647

The core problem

Modern AI agents routinely cross trust boundaries: they ingest untrusted content, combine it with privileged instructions, persist intermediate beliefs in long-term memory, and invoke privileged tools. This creates an attack surface in which malicious payloads can enter through model inputs and cause harmful tool actions. Current governance stacks remain application-level middleware that share a process trust boundary with the agents they monitor. The authors argue that agents need an operating-system substrate providing mandatory, non-bypassable services for identity, input mediation, memory governance, and execution control. They introduce AgentKernel, a trust-native agent operating system built around the premise that security must be a first-class design constraint.

Innovation

The paper positions AgentKernel as the missing OS layer beneath orchestration frameworks, agent runtimes, governance platforms, and execution sandboxes. Through systematic comparison, the authors demonstrate that a single integrated architecture can enforce security across the full agent lifecycle. Key results include: kernel-managed identity enables trustworthy cross-organization collaboration; graduated perception replaces brittle single-point filters; information-flow-controlled memory improves retrieval fidelity while limiting poisoning; and semantic-to-kernel enforcement permits broader tool privileges behind a non-bypassable boundary. The analysis shows that structural security acts as a capability multiplier, allowing agents to safely use more powerful tools and collaborate across trust domains.
Modern AI agents routinely cross trust boundaries: they ingest untrusted content, combine it with privileged instructions, persist intermediate beliefs in long-term memory, and invoke privileged tools. This creates an attack surface in which malicious payloads can enter through model inputs and cause harmful tool actions. Current governance stacks remain application-level middleware that share a process trust boundary with the agents they monitor. The authors argue that agents need an operating-system substrate providing mandatory, non-bypassable services for identity, input mediation, memory governance, and execution control. They introduce AgentKernel, a trust-native agent operating system built around the premise that security must be a first-class design constraint.
AgentKernel wraps the agent lifecycle in a mandatory enforcement boundary organized into four pillars: Identity, Perception, Cognition, and Execution. Each pillar adapts classical OS security principles to failures at the semantic plane, including delegation abuse, prompt injection, memory poisoning, and tool misuse. The architecture treats structural security as a capability multiplier: kernel-managed identity supports trustworthy cross-organization collaboration; graduated perception replaces brittle single-point filters; information-flow-controlled memory improves retrieval fidelity while limiting poisoning; and semantic-to-kernel enforcement permits broader tool privileges behind a non-bypassable boundary. The authors use systematic comparison and security analysis to show how a single integrated architecture can enforce security across the full agent lifecycle.

Why it matters

The authors argue that current application-level middleware shares a process trust boundary with the agents it monitors, making it insufficient to prevent semantic-plane attacks. AgentKernel addresses this by providing mandatory, non-bypassable services at the OS level. The four-pillar design adapts classical OS security principles—such as reference monitors, least privilege, and information flow control—to the unique challenges of AI agents. The paper discusses how this approach enables broader tool privileges without sacrificing security, and how it can be integrated with existing orchestration frameworks and runtimes. Limitations and future work are not explicitly detailed in the abstract, but the systematic comparison suggests that AgentKernel is a foundational layer that could be extended to support emerging agent capabilities.

Who should read this

CS practitioners and researchers

Opening member content…