Concept Paper AI-GUARD · AIGP + AIAP August 2026

Written In Blood

Every rule in aviation exists because someone died producing it. That is the part of the analogy nobody quotes — and it is the only part that tells you where your AI estate actually stands.

People board an aircraft they did not design, flown by someone they have never met.

They are right to.

Not because aviation is inherently safe. Because a century of catastrophe was converted into machinery: certification, identity, operating rules, clear authority, instrumentation, maintenance records, incident evidence, independent oversight, and the power to ground an aircraft the moment conditions stop being acceptable.

Trust was not extended to aviation. It was engineered, one crash at a time.

Persistent identity — tail numberNot present
Filed flight plan — declared purposeNot present
Bounded, time-limited clearanceNot present
Cockpit instrumentation in flightPartial at best
Flight recorder — connected evidenceLogs only
Authority to ground the operationUndefined

That is the equipment list for your AI estate. You are flying pre-regulation, and the incidents that write the rules have not happened to you yet.

01 · The framing

Safety does not exist outside operation

Aviation safety is not a document reviewed before departure. It is embedded in the act of flying — the rules, identities, permissions, instruments, logs and escalation paths are part of the operating system itself.

Which reframes the governance question entirely. It was never “is this model safe?” It is: under what conditions may this AI system operate, who may authorise it, how much authority may it exercise, how will its behaviour be monitored, and what evidence will remain after it acts?

Ask those five questions of your current estate and count how many have an owner, let alone an answer.

Your governance exists before deployment and after the incident. It is absent during the only moment that matters.

This is the gap AI-GUARD occupies, and it is worth being precise about the claim. AI-GUARD is not an attempt to become the FAA for AI. Regulators, standards bodies, enterprise policy owners, risk functions and domain authorities remain the external sources of obligation and judgment.

AI-GUARD is the operational safety machinery that makes those obligations enforceable at runtime — connecting policy to identity, authority, execution, observation and evidence, so that governance is present when AI actually acts.

Governance should not be the brake on autonomy. It should be the system that makes justified autonomy possible.
02 · The protocol model

Two protocols. Two sides of one coin.

A licensed pilot is not cleared to fly any aircraft, on any route, in any conditions. The licence and the clearance are different instruments, and confusing them is how people die. Enterprise AI collapses them into a single permission model and calls it access control.

AIGP AI Governance Protocol Governs the operation
  • What is being invoked?
  • For what declared purpose?
  • Under which policy and control conditions?
  • What context, evidence and provenance must accompany the invocation?
  • How is the decision or output made observable and accountable?

Without AIAP: can describe and constrain an operation, but cannot govern delegated action.

AIAP AI Agency Protocol Governs the authority
  • Who or what is allowed to act?
  • What actions may it perform?
  • On which resources, within which boundaries?
  • For how long does that authority exist?
  • When must authority be reduced, revoked, or earned again?

Without AIGP: can grant bounded authority, but lacks the envelope explaining purpose, context, evidence and accountability.

AIGP asks whether the operation is legitimate. AIAP asks whether this actor has legitimate agency within that operation. Neither is sufficient alone. Together they create a complete runtime relationship between intelligence and authority — and AI-GUARD makes the answer executable.

03 · The analogy, mapped

What aviation built, and what you are missing

The mapping is not literal. It is an operating model — and read down the middle column, it is also an inventory of everything the last century of flight considered non-negotiable.

Aviation safety concept AI-GUARD equivalent Governance meaning
Aircraft identity / tail number AI-IDENTITY Every model, agent, helper, application and service has a persistent, verifiable identity.
Pilot and crew credentials AIAP agency Identity alone does not authorise action. Agency is explicitly granted, bounded and time-limited.
Flight plan / mission AIGP purpose The system declares why it is operating, what it intends to do, and the conditions under which the operation is valid.
Airspace rules and procedures AIGP envelope Policies, standards, risk requirements and domain rules are translated into enforceable operating constraints.
Cockpit instruments and telemetry AI-OBSERVE Behaviour, state, drift, exceptions and control decisions are visible while operation is occurring.
Flight data recorder Decision provenance Critical inputs, decisions, authority, controls, actions and outcomes are preserved as durable evidence.
Dispatch / operational control AI-GUARD control plane Operations are activated, governed, coordinated, constrained and stopped through an enterprise control plane.
Aircraft systems in operation AI-RUN Agents and governed workloads execute inside a controlled runtime environment.
Safety investigation and analytics AI-LENSE Evidence is interpreted across time, context, relationships and outcomes to understand what happened and why.
Protected keys and critical systems AI-VAULT Secrets and sensitive credentials remain isolated, controlled, and released only under governed conditions.
Passengers and people on the ground Affected people The real object of safety is not the machine. It is the people, organisations, rights, assets and outcomes affected by its operation.
Grounding an aircraft Kill switch / revocation When conditions are no longer acceptable, authority can be revoked and operation stopped immediately.

Take the last row seriously. Aviation can put an entire fleet on the ground in an afternoon. Ask who in your organisation holds that authority over your agents, how it is exercised, and how long it takes to work.

04 · Operational flow

What a governed AI flight looks like

The value of the aviation model is that it frames governance as a lifecycle rather than a gate. A governed AI operation runs from declared intent, through bounded execution, to preserved evidence.

01
Register Identity is established

Agent, application, model, helper and service identities are registered. Persistent identity answers the first question: what is this thing?

02
File the flight plan Purpose is declared

The AIGP envelope establishes use case, model, prompt or task, applicable policy, expected controls, region, and evidence requirements.

03
Clear for operation Agency is granted

AIAP determines who may act, what actions are allowed, on which resources, within which constraints, and for how long. Identity is persistent; agency is ephemeral.

04
Fly inside the envelope Execution is governed

AI-RUN executes the workload while AI-GUARD enforces the active governance and agency conditions. Permissions are not assumed merely because an agent exists.

05
Instrument the flight Behaviour is made visible

AI-OBSERVE captures operational signals and control state. Exceptions, drift, denied actions, delegation and relevant behaviour become visible in context — while the operation is still running.

06
Preserve the black box Evidence survives the action

The trajectory is retained as a connected record: identity, purpose, authority, controls, actions and outcomes, reconstructable after the fact by someone who was not there.

In a mature system, the question after an AI action is not “what do we think happened?” It is “what does the evidence show happened?”
05 · The destination

Autonomy is earned, not assumed

Aviation does not require the same level of direct human intervention for every second of every flight. Authority changes with context, phase, system capability, weather, failure conditions and evidence. AI should be governed with the same maturity.

Which retires the tired debate. Not “human in the loop” versus “human on the loop” — a posture chosen once at design time — but a live question: what level of agency is justified now?

Agency ladder Evidence required →
0
Ungoverned ← Most enterprises are here

Agents hold standing permissions granted at deployment. Authority does not expire, does not narrow under risk, and is not tied to any declared purpose. Nobody can say what is justified because nothing is being justified.

1
Observed

AI may advise or recommend. Human authority remains dominant. Evidence establishes baseline behaviour.

2
Bounded

AI may perform narrowly defined actions with explicit constraints, short-lived authority and strong supervision.

3
Trusted

AI may exercise broader agency where repeated evidence demonstrates reliable behaviour within a defined operating envelope.

4
Justified autonomy

AI may act with meaningful independence, because identity, purpose, authority, constraints, instrumentation, evidence and revocation are all continuously governed.

AIAP makes the crucial distinction: identity can persist, but agency should be ephemeral. A registered agent is not automatically an authorised agent — just as a licensed pilot is not automatically cleared to fly any aircraft, on any route, for any mission.

Authority can be granted just in time, limited to a specific purpose and resources, reduced as risk rises, expanded as evidence supports it, or revoked immediately. AIGP supplies the context that makes that agency meaningful.

The more consequential the action, the stronger the required evidence that actor, purpose, authority, conditions and expected outcome are aligned.
06 · Evidence architecture

The black box is not an audit log

A flight recorder is valuable because it preserves a coherent account of an event. A pile of unrelated log entries is not equivalent — and the difference only becomes apparent at the exact moment you cannot afford to discover it.

What you have Disconnected logs

Entries across seven systems that do not share an identifier, a clock, or a notion of purpose. Sufficient to prove a control existed. Insufficient to reconstruct what the system did, on whose authority, or why it was allowed to.

What is required Decision provenance

A connected record of the operation: identity, purpose, policy, agency, invocation, context, control decisions, model interaction, actions, observations, exceptions, outcomes, and how each changed over time.

Controls tell us what should happen. Evidence tells us what did happen. Governed autonomy requires both.

Traditional governance evaluates static artifacts: a policy document, an approval, a model card, a risk assessment, a control configuration. Those remain useful. But autonomous systems pose a temporal problem those artifacts cannot address — whether the system remained legitimate as context, authority, behaviour and outcomes changed.

That is why observation and evidence are first-class governance capabilities here, not reporting features. The goal is not to prove a control existed. It is to establish whether autonomous action remained justified across the entire trajectory.

07 · The proposition

The machinery already exists

Enterprises do not need another dashboard that reports an AI system was approved. They need an operational framework that can answer, in real time and after the fact, whether the system had a legitimate purpose, whether the actor had legitimate agency, whether it stayed inside its envelope, and whether the evidence supports the autonomy it exercised.

AI-GUARD

Every participating actor and system holds a persistent identity. AIGP governs the operation itself — purpose, context, controls, provenance. AIAP governs the agency exercised within it: who may act, what they may do, where, and for how long. Authority is granted just-in-time and remains revocable rather than hardening into permanent implicit permission.

Like a modern aircraft, the system is continuously instrumented during operation rather than governed by periodic review. The resulting evidence reconstructs the trajectory of decisions, actions, authority and outcomes rather than leaving disconnected logs behind. Through a common control plane, autonomous operation can be constrained, reduced, revoked or halted as conditions change — and as evidence accumulates, that same mechanism provides a controlled pathway from supervised automation toward justified autonomy.

AIGP governs the conditions under which intelligence operates. AIAP governs the conditions under which intelligence may act. Evidence determines when autonomy is justified.

The transition

We already know how society learned to trust complex autonomous and semi-autonomous systems. We did not ask for perfect machines or perfect humans. We engineered a safety system around operations — and we paid for every line of it.

AI now needs the same transition: from trust by assertion to trust supported by identity, bounded agency, instrumentation, evidence and accountable operation.

Aviation learned this the expensive way. The rules were written in blood because there was no other way to discover them. That excuse is no longer available — the model exists, the discipline is documented, and the only open question is whether AI governance adopts it before its own incidents force the issue, or after.

Two protocols. One governed system.

AIGP + AIAP → Justified autonomy

AI-GUARD · AIGP + AIAP · Concept Narrative
August 2026