I-D Action: draft-das-agentic-tool-binding-03.txt
internet-drafts@ietf.org Sat, 05 September 2026 14:29 UTC
Return-Path: <internet-drafts@ietf.org>
X-Original-To: i-d-announce@ietf.org
Delivered-To: i-d-announce@mail2.ietf.org
Received: from [10.244.9.145] (gaia.k8s.ietf.org [4.156.85.76]) by mail2.ietf.org (Postfix) with ESMTP id 605E613601E29 for <i-d-announce@ietf.org>; Sat, 5 Sep 2026 07:29:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788618542; bh=BOKfsL15hO+yZSOqul++fh3k1Lp4Y8f1tMX1JMHA8sI=; h=From:To:Subject:Date; b=I+HirNFYPD3XOPe1xMf0w1ElzZZiDrjFPtavwWWuNCW9J8m/uz5/Lrg847R7iBtiP kJ9wZviKqvpmNI4PeDcqyopb6PrbSdIa8kX9VA+AAluUrvp928PenMW3bcU1CU6XDr mr72fKcxR8XtePW4wKAnpfJzyow4QRRKiiJBwOUw=
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
Subject: I-D Action: draft-das-agentic-tool-binding-03.txt
X-Test-IDTracker: no
X-IETF-IDTracker: 12.74.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <178861854216.277590.1981385634370127937@dt-datatracker-9769b79f-xztnc>
Date: Sat, 05 Sep 2026 07:29:02 -0700
Message-ID-Hash: KOKOQDNAU6NYQ365MVTERNFWC4TEIL4K
X-Message-ID-Hash: KOKOQDNAU6NYQ365MVTERNFWC4TEIL4K
X-MailFrom: internet-drafts@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-i-d-announce.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Reply-To: internet-drafts@ietf.org
List-Id: Internet Draft Announcements only <i-d-announce.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/i-d-announce/OrWr66lwNd87oRuR1-EmfNy3QdQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/i-d-announce>
List-Help: <mailto:i-d-announce-request@ietf.org?subject=help>
List-Owner: <mailto:i-d-announce-owner@ietf.org>
List-Post: <mailto:i-d-announce@ietf.org>
List-Subscribe: <mailto:i-d-announce-join@ietf.org>
List-Unsubscribe: <mailto:i-d-announce-leave@ietf.org>
Internet-Draft draft-das-agentic-tool-binding-03.txt is now available. Title: tool_use Is Not invoke(): Binding Execution-Finality to Agentic Tool-Call Interfaces and MCP Author: Sangam Das Name: draft-das-agentic-tool-binding-03.txt Pages: 51 Dates: 2026-09-05 Abstract: Frontier runtimes already standardized the dangerous moment. A model emits a tool_use block, a tool_calls array, or an MCP tools/call payload. The host then invokes whatever name and arguments the model printed. Alignment, allowlists, and OAuth sit around that moment. They do not sit on it. The consequence of this gap is no longer confined to email or payment demos. In defense, energy, grid control, industrial process control, and other critical-infrastructure deployments, the same tool_use block already reaches actuation-class systems -- logistics and targeting-adjacent decision support, SCADA and PLC interfaces, medical devices, autonomous platforms. In these environments, detection after the fact is not mitigation; it is an incident report written after the effect has already occurred. An agent that can act at machine speed but cannot be halted at machine speed is a system running without brakes: the first uncontrolled invocation is not a warning sign, it is the accident. Command authority, human oversight, and legal review all operate on human time. An unbound tool_use block operates on machine time. When those two clocks diverge, the gap belongs to whichever side reaches the effect first -- and today, nothing structurally guarantees that side is authorization. This document does not invent another assistant API. It binds the Agent Candidate Act profile [I-D.das-agentic] onto the three interface families those runtimes and their customers already ship: tool_use / computer_use style interfaces, function-calling and structured tool-response interfaces, and Model Context Protocol tools/call. The model may emit the block. The block remains non- effective. A local enforcer builds the act, binds the argument digest, and refuses invoke() until scoped authority is verified and consumed at the dispatch sink. For consequence classes above a defined threshold -- FINANCIAL, PHYSICAL, NETWORK_CONTROL, and any act reaching defense or critical- infrastructure actuation -- this binding treats fail-closed as the only conforming behavior: absent successfully verified, current, act- bound authority, the candidate act stays non-effective regardless of model confidence, prior session trust, or upstream alignment signal. Each enforcement decision, allow or deny, commits a Ledger-Anchored Validation Receipt (LAVR) -- a signed, hash-chained enforcement artifact bound to the specific candidate act and its argument digest at the moment of decision. An LAVR is not a log entry assembled afterward for audit; it is the proof that the finality boundary actually gated this act before any effect could occur, and its absence is itself a fail-closed condition. The implementation target is a middleware function that a host loop can call without changing the model vendor. tool_use is not invoke(). The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-das-agentic-tool-binding/ There is also an HTML version available at: https://www.ietf.org/archive/id/draft-das-agentic-tool-binding-03.html A diff from the previous version is available at: https://author-tools.ietf.org/iddiff?url2=draft-das-agentic-tool-binding-03 Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts
- I-D Action: draft-das-agentic-tool-binding-03.txt internet-drafts