Skip to content
Open access

Governing AI reasoning to mitigate assumption injection in assurance workflows

Jul 2026 · Discover Artificial Intelligence · Vol 6 · 0 citations · 35 references

TL;DR

A governed context evolution mechanism for mitigating assumption injection in AI-assisted assurance workflows is proposed and demonstrated that explicit gap preservation and replay-derived promotion provide practical mechanisms for supporting auditability, traceability, and human control over contextual assumptions in AI-assisted assurance.

Abstract

Security assurance depends on clearly defined contextual conditions, including assumptions, environmental constraints, and stakeholder expectations. As artificial intelligence tools are increasingly used to analyze evidence and generate assurance artifacts, they often operate on incomplete or underspecified system descriptions. In such settings, AI systems may introduce plausible but unverified assumptions in order to produce coherent outputs. This paper refers to this risk as assumption injection: the silent introduction or modification of contextual assumptions that changes the basis on which assurance claims are interpreted. This paper proposes a governed context evolution mechanism for mitigating assumption injection in AI-assisted assurance workflows. The mechanism treats contextual incompleteness as an explicit and governed state by representing unresolved assumptions as context gaps. AI tools may analyze these gaps and propose advisory refinements, but they cannot modify the authoritative assurance context directly. Authoritative changes occur only through decision-gated promotion, provenance-aware DecisionRecords, and replay-based validation. A reference implementation and illustrative case study demonstrate how the mechanism separates advisory artifacts from authoritative state, preserves unresolved gaps, and rejects refinements that rely on undeclared structure. The evaluation is positioned as a proof of concept rather than a full industrial validation. Within these bounds, the case study demonstrates that explicit gap preservation and replay-derived promotion provide practical mechanisms for supporting auditability, traceability, and human control over contextual assumptions in AI-assisted assurance. The paper concludes by discussing scalability, analyst burden, semantic drift, conflict handling, and the conditions under which the mechanism would require further engineering before deployment in large assurance environments.

Read PDF

Similar papers

Preprint Aug 2026

Correct Is Not Governed: Provenance Integrity in Agentic Workflows

Agentic workflows are commonly evaluated by whether they reach the correct outcome. That is insufficient in institutional settings, where a correct action may rely on the wrong authority, an unsupported completion claim, or work made stale by a later change. We define governed execution as work whose decisions, complet...

Jesus Salas · 4 citations
Review Sep 2026

An AI-Ready Decision Digital Thread Schema for Digital Engineering

Digital engineering (DE) and model-based systems engineering (MBSE) improve traceability for requirements, architecture, and verification, but concept decisions—the governance events that turn evolving evidence into binding commitments—are poorly captured. Rationale, assumptions, alternatives, model baselines, and appr...

R. Chinnam, A. Murat, Satyendra Rana et al. · 0 citations
#artificial intelligence Preprint Oct 2026

A Deterministic and Auditable AI Security Risk Assessment Framework with ATLAS Aligned Executable Rules and Formal Verification

Artificial intelligence systems are increasingly deployed in high impact and safety critical settings, yet security assessment remains difficult to reproduce and defend under audit. Existing approaches often rely on narrative checklists or assessor driven scoring, and they lack an explicit, machine evaluable mapping fr...

Yi-Xuan Huang, Basel Halak, Boojoong Kang University of Southampton et al. · 0 citations
#artificial intelligence Preprint Sep 2026

ActGov: Governing LLM Agent Actions via Policy-Constrained Validation

Large language model (LLM) agents increasingly execute long-horizon workflows through external tools, allowing untrusted outputs to influence subsequent actions and exceed user authorization. Existing defenses isolate injected content or constrain execution with predefined plans and static policies, but these approache...

Kai-Yuan Zhang, Yu-Ke Peng, Ke Jiang et al. · 1 citation · ⚡1
Open access Sep 2026

RACER: Remediation Assurance Contracts for Evidence-Gated, Risk-Bounded Autonomous Recovery in Cloud Systems

AI agents can diagnose cloud incidents, synthesize operational commands, and invoke state-changing APIs, but a plausible remediation is not necessarily safe to execute. This study presents RACER, a runtime-assurance mechanism that treats every AI-generated repair as an untrusted proposal until it is bound to a machine-...

Prudvi Saisaran Ponduru, Pavani Priya Vyshnavi Nandanavanam, Sai Kesav Kumar Ponduru · 0 citations
#software testing Review Sep 2026

From Agent Output to Authorized Transition

This paper presents the Agile-V Assurance Spine, a cross-domain transition contract for software, firmware, and PCB engineering, and contributes a precise vocabulary, compositional architecture, domain profiles, mapping to open-source implementations, and an adversarial evaluation agenda.

Christopher Koch · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.