Authority Must Hold Through Commit
A response to Jun He and Deying Yu, "When AI Agents Commit: Cognitive Serializability Across Data, Evidence, Policy, and Authority" (arXiv:2609.20261)
Abstract
He and Yu identify a difficult transaction problem for autonomous agents. An agent may derive an action from database records, retrieved evidence, policy, beliefs, and delegated authority. Any of those inputs may change before the action becomes durable. Their Transactional Cognitive Toolkit responds with versioned definitions, authority plans, sealed envelopes, commit guards, constrained grants, and co-committed receipts. The result is a technical account of how authority can remain valid through commit. Kaal's public scholarship supplies the institutional reason for that requirement. Authority drift arises when every individual check passes but the aggregate result exceeds what the principal authorized. The paper provides a promising implementation path for that diagnosis. It also states an important limit. Serializability can establish consistency under represented predicates. It cannot establish semantic truth, complete mediation, or legitimate institutional design.
The derivation and the effect need one valid point
Conventional database isolation orders submitted transactions. That guarantee is not enough for an agent whose proposed mutation depends on information outside the transaction. A policy may change. Evidence may be superseded. A delegation may expire. The database can serialize the final write while leaving the reasoning that produced it tied to an obsolete state.
He and Yu formalize the missing relation. Under strict Cognitive Serializability, a committed effect must admit a serial order and a logical point at which every value exposed to the derivation remains unchanged. Their weaker Effect-Compatible Cognitive Admission does not claim to reconstruct or serialize the original stochastic reasoning. It asks whether the effect remains valid under the current dependency vector and policy.
The implementation combines immutable, versioned definitions with registry-derived authority plans. It seals the proposed action and checks guards before commit. External grants are bound to the sealed envelope and its witnesses. Receipts are committed with the effect. In 28 controlled histories, the prototype blocked the injected anomalies and added a reported mean commit overhead of 3.22 milliseconds.
Authority is not an input that can be checked once
The institutional problem is authority drift. Kaal defines it as a condition in which every individual check passes while the aggregate conduct falls outside what the user authorized (Kaal 2026, claim 7314479-015). He and Yu show one precise mechanism through which that failure can occur. Authority can be valid when reasoning begins and invalid when the effect commits.
This connection sharpens the design requirement. Every integration must settle identity, authority, permitted data use, responsibility, and remedy (Kaal 2026, claim 7314479-009). Those terms cannot remain background documentation. They must appear in the executable dependency set that controls the effect.
The receipt matters for the same reason. An institution needs a durable artifact produced at execution time. That artifact should let a third party determine whether policy governed the act, whether data remained within permitted boundaries, and whether the result is attributable without requiring access to the underlying content (Kaal 2026, claim 7314479-048). A co-committed receipt can make that institutional requirement technically concrete.
What the paper establishes
The paper is strongest as a conditional systems result. If the relevant dependencies are registered, mediation captures the values exposed to reasoning, and the commit path controls the consequential effect, the proposed protocol can preserve a common valid point across derivation and mutation. That is a useful extension of the authority-drift diagnosis. It moves the problem from a general warning to a falsifiable transaction property.
The work also avoids a common overclaim. Its weaker admission rule recertifies the effect. It does not claim to validate the agent's original reasoning. This distinction is institutionally significant. A safe effect can be admitted even when the stochastic path that proposed it cannot be reproduced.
The remaining institutional limits
Serializability does not prove that a policy is legitimate or that evidence is true. It proves consistency only for represented predicates and captured dependencies. An omitted source, an unmediated side effect, or a covert channel falls outside the theorem. Byzantine failures in the trusted computing base also remain outside the stated model.
These limits define the next research task. The dependency registry must itself be governed. Someone must decide which sources, policies, delegations, and remedies are material. Informal deliberation alone cannot bind agents at machine speed, yet a regime limited to pure formal verification can exclude the stakeholders whose authority gives the rules legitimacy (Kaal 2026, claim 6886078-001).
The institutional conclusion is narrow but important. Authorization is not valid merely because it existed when the agent began to reason. It must survive until the effect becomes durable. He and Yu provide a serious technical account of that requirement. The remaining challenge is to ensure that the executable contract represents the full institutional settlement rather than only the dependencies that were easiest to encode.
References
He, Jun, and Deying Yu. 2026. "When AI Agents Commit: Cognitive Serializability Across Data, Evidence, Policy, and Authority." arXiv:2609.20261v1. arXiv:2609.20261.
Kaal, Wulf A. 2026. "Governance as a Product (GaaP): A Reputation-Weighted Institutional Architecture for Autonomous AI Agent Governance." SSRN. SSRN 6886078.
Kaal, Wulf A. 2026. "Institutional Requirements for Sovereign Local Agent Runtimes." SSRN. SSRN 7314479.