Skip to content

A Unified Policy Architecture (UPA): The Governance Kernel for Enterprise AI Operating Systems

Sep 2026 · 0 citations
Computer Science

TL;DR

The Unified Policy Architecture is introduced, a governance architecture for Enterprise AI Operating Systems that provides a unified policy model for governing AI and agents, tools, workflows, memory, enterprise resources, and agent-to-agent interactions and enterprise business rules.

Abstract

Enterprise AI is evolving into an Enterprise Operating System where autonomous AI agents can plan, reason, use memory, invoke tools, execute workflows, and collaborate with other agents. This shift creates a new governance challenge: existing authorization, security, guardrails, and compliance mechanisms are fragmented and are not designed to govern autonomous AI as a unified system. This paper introduces the Unified Policy Architecture (UPA), a governance architecture for Enterprise AI Operating Systems. UPA provides a unified policy model for governing AI and agents, tools, workflows, memory, enterprise resources, and agent-to-agent interactions and enterprise business rules. It extends policy control beyond authorisation to include runtime obligations, human approvals, compliance, audit evidence, and governance evaluation. We present UPA's governance model, declarative policy language foundations, policy evaluation semantics, extensible plugins, industry policy packs, and an evaluation framework for enterprise governance. We also identify extensions for multi-agent coordination, provenance-aware policies, and stateful runtime governance. UPA provides a foundation for building secure, accountable, and governable Enterprise Operating Systems for autonomous AI.

View source

Similar papers

Open access Aug 2026

AI Governance Engineering: A Framework for Secure, Explainable, and Trustworthy Enterprise Artificial Intelligence Systems

This paper argues for a transition from AI Governance as Compliance to AI Governance Engineering , a systems-oriented discipline in which governance is embedded throughout the enterprise intelligence lifecycle, enabling enterprise intelligence systems that are secure, explainable, trustworthy, and governable by design.

Faruk Çelikkanat · 0 citations
Open access 2026

The Agentic Enterprise Capability Framework (AECF): A Governance-First Architecture for Scalable AI Agent Deployments

The study contributes an integrated architectural model, propositional formalization, and validation agenda for governed enterprise AI agent deployments, and introduces the co-evolution constraint: technical capability layers cannot mature independently of governance capacity.

Khammal Adil, Hamzane Ibrahim, Marzak Abdelaziz et al. · 0 citations
Open access Aug 2026

Enterprise Governance of Reusable Agentic AI Skills A Runtime Governance Framework Built on Dynamic Capability Projection and the Agent Harness as Trust Boundary

Enterprises are increasingly building agentic AI systems out of reusable skills — modular units that bundle prompts, reasoning strategies, tool integrations, and execution policies, and that get reused across many AI use cases. This pattern speeds up delivery, but it creates a risk that current AI governance frameworks...

Sandeep Kumar Anuguthala · 0 citations
Open access Sep 2026

Runtime Policy Firewall: A Zero-Trust Governance Layer for Enterprise Agentic AI

Enterprise adoption of generative AI is shifting from passive question answering to autonomous agentic execution. Modern agents can decompose goals, retrieve business context, call tools, update records, send messages, initiate transactions, and coordinate workflows across multiple systems. This creates productivity op...

Swapneswar Ray · 0 citations
Review Open access Sep 2026

Governing Agentic AI in Enterprise Workflows: A Bounded-Autonomy Framework for Delegated Authority and Controlled Execution

Agentic AI can interpret information, plan, make workflow decisions, and use enterprise tools. Yet technical capability does not establish authoritative meaning, legitimate process state, organisational permission, or accountable execution. The challenge is to preserve adaptability while ensuring that consequential act...

B. Jørgensen, Z. Ma · 0 citations
#artificial intelligence Preprint Aug 2026

OpenAgentFlow: Enabling System-Wide Safety Boundaries for Heterogeneous AI Agent Fleets

OpenAgentFlow is presented, a control-plane/action-plane architecture that establishes the action-commit boundary as a shared enforcement interface and shows that a shared action-commit boundary provides a practical basis for system-wide governance across heterogeneous agent execution paths.

Dong-Sheng Chen, Xiang-Yu Zhao, Xin Yao et al. · 0 citations

Related blog posts

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.