I-D Action: draft-das-agentic-tool-binding-03.txt

internet-drafts@ietf.org Sat, 05 September 2026 14:29 UTC

Return-Path: <internet-drafts@ietf.org>
X-Original-To: i-d-announce@ietf.org
Delivered-To: i-d-announce@mail2.ietf.org
Received: from [10.244.9.145] (gaia.k8s.ietf.org [4.156.85.76]) by mail2.ietf.org (Postfix) with ESMTP id 605E613601E29 for <i-d-announce@ietf.org>; Sat, 5 Sep 2026 07:29:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788618542; bh=BOKfsL15hO+yZSOqul++fh3k1Lp4Y8f1tMX1JMHA8sI=; h=From:To:Subject:Date; b=I+HirNFYPD3XOPe1xMf0w1ElzZZiDrjFPtavwWWuNCW9J8m/uz5/Lrg847R7iBtiP kJ9wZviKqvpmNI4PeDcqyopb6PrbSdIa8kX9VA+AAluUrvp928PenMW3bcU1CU6XDr mr72fKcxR8XtePW4wKAnpfJzyow4QRRKiiJBwOUw=
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
Subject: I-D Action: draft-das-agentic-tool-binding-03.txt
X-Test-IDTracker: no
X-IETF-IDTracker: 12.74.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <178861854216.277590.1981385634370127937@dt-datatracker-9769b79f-xztnc>
Date: Sat, 05 Sep 2026 07:29:02 -0700
Message-ID-Hash: KOKOQDNAU6NYQ365MVTERNFWC4TEIL4K
X-Message-ID-Hash: KOKOQDNAU6NYQ365MVTERNFWC4TEIL4K
X-MailFrom: internet-drafts@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-i-d-announce.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Reply-To: internet-drafts@ietf.org
List-Id: Internet Draft Announcements only <i-d-announce.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/i-d-announce/OrWr66lwNd87oRuR1-EmfNy3QdQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/i-d-announce>
List-Help: <mailto:i-d-announce-request@ietf.org?subject=help>
List-Owner: <mailto:i-d-announce-owner@ietf.org>
List-Post: <mailto:i-d-announce@ietf.org>
List-Subscribe: <mailto:i-d-announce-join@ietf.org>
List-Unsubscribe: <mailto:i-d-announce-leave@ietf.org>

Internet-Draft draft-das-agentic-tool-binding-03.txt is now available.

   Title:   tool_use Is Not invoke(): Binding Execution-Finality to Agentic Tool-Call Interfaces and MCP
   Author:  Sangam Das
   Name:    draft-das-agentic-tool-binding-03.txt
   Pages:   51
   Dates:   2026-09-05

Abstract:

   Frontier runtimes already standardized the dangerous moment.  A model
   emits a tool_use block, a tool_calls array, or an MCP tools/call
   payload.  The host then invokes whatever name and arguments the model
   printed.  Alignment, allowlists, and OAuth sit around that moment.
   They do not sit on it.

   The consequence of this gap is no longer confined to email or payment
   demos.  In defense, energy, grid control, industrial process control,
   and other critical-infrastructure deployments, the same tool_use
   block already reaches actuation-class systems -- logistics and
   targeting-adjacent decision support, SCADA and PLC interfaces,
   medical devices, autonomous platforms.  In these environments,
   detection after the fact is not mitigation; it is an incident report
   written after the effect has already occurred.  An agent that can act
   at machine speed but cannot be halted at machine speed is a system
   running without brakes: the first uncontrolled invocation is not a
   warning sign, it is the accident.  Command authority, human
   oversight, and legal review all operate on human time.  An unbound
   tool_use block operates on machine time.  When those two clocks
   diverge, the gap belongs to whichever side reaches the effect first
   -- and today, nothing structurally guarantees that side is
   authorization.

   This document does not invent another assistant API.  It binds the
   Agent Candidate Act profile [I-D.das-agentic] onto the three
   interface families those runtimes and their customers already ship:
   tool_use / computer_use style interfaces, function-calling and
   structured tool-response interfaces, and Model Context Protocol
   tools/call.  The model may emit the block.  The block remains non-
   effective.  A local enforcer builds the act, binds the argument
   digest, and refuses invoke() until scoped authority is verified and
   consumed at the dispatch sink.

   For consequence classes above a defined threshold -- FINANCIAL,
   PHYSICAL, NETWORK_CONTROL, and any act reaching defense or critical-
   infrastructure actuation -- this binding treats fail-closed as the
   only conforming behavior: absent successfully verified, current, act-
   bound authority, the candidate act stays non-effective regardless of
   model confidence, prior session trust, or upstream alignment signal.
   Each enforcement decision, allow or deny, commits a Ledger-Anchored
   Validation Receipt (LAVR) -- a signed, hash-chained enforcement
   artifact bound to the specific candidate act and its argument digest
   at the moment of decision.  An LAVR is not a log entry assembled
   afterward for audit; it is the proof that the finality boundary
   actually gated this act before any effect could occur, and its
   absence is itself a fail-closed condition.

   The implementation target is a middleware function that a host loop
   can call without changing the model vendor. tool_use is not invoke().

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-das-agentic-tool-binding/

There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-das-agentic-tool-binding-03.html

A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-das-agentic-tool-binding-03

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts