Spherity AI Safety Series — Executive Brief

Governing AI That Acts Across Companies

How responsible leaders build first-mover advantage through AI safety and alignment

Author
Affiliation
Dr. Carsten Stöcker — Spherity GmbH
Published
Updated
Research cut-off
· Research, incidents, standards and implementation evidence reviewed to this date
This version
https://spherity.github.io/spherity-research/governing-ai-that-acts-across-companies.html
Latest version
https://spherity.github.io/spherity-research/governing-ai-that-acts-across-companies.html
Browse this paper

In brief

What does this research establish?

AI systems acting across companies need more than model-level alignment: protected execution must bind each effect to current authority, shared limits, runtime evidence and accountable resource controls. This series connects incentive design, continuous assurance and privacy-preserving eligibility checks while stating where its formal and synthetic evidence does not establish general AI safety.

Key takeaways

  • Authority, evidence, aggregate limits and exact actions must be checked at protected resource boundaries, not left to agent prompts or voluntary compliance.
  • Runtime assurance must retain episode risk, shared dependencies and pending effects when agents join, retire or are replaced.
  • Cross-domain verification can prove action eligibility with scoped evidence while limiting unnecessary disclosure and preserving local enforcement sovereignty.
  • The business advantage is qualified delegation: leaders can authorize more useful action sooner where evidence and controls justify it.

Download the executive brief

Download the executive brief

Governing AI That Acts Across Companies. The leadership argument, two operating use cases and the integrated three-paper research programme.

First page of the Spherity executive brief Governing AI That Acts Across Companies.
Executive brief. A leadership guide to the Spherity AI Safety series and its operational controls. Published under CC BY 4.0.

Executive brief

AI safety and alignment become operational governance questions when AI receives authority to spend, release data, change software, book scarce resources or coordinate physical work across companies. Agent swarms can divide work and expand productive capacity, but the same coordination can propagate misaligned goals, deceptive behavior and correlated failure.

This four-part series proposes a layered response: incentive-compatible programs are mediated by deterministic protected controllers; runtime supervisors admit actions only when current mandate and action-bound assurance remain valid; and cross-domain verifiers can establish exact action eligibility without exposing every underlying record. The evidence is deliberately bounded. Formal proofs depend on stated models, while synthetic testing, state exploration and omission counterexamples challenge implementation assumptions rather than certify general alignment.

Keywords: AI safety; AI agents; agent swarms; protected execution; runtime assurance; private verification; operational alignment; cross-company AI governance

Why AI safety across companies matters now

Model behavior is only one part of the risk. A capable agent may still act under an expired mandate, exceed a shared budget through parallel actions, reuse stale evidence, conceal an adverse finding or lose accountability when a worker is replaced. Cross-company activity adds distinct trust roots, legal duties, data-access rules and resource owners. The system therefore needs controls that survive organizational boundaries and remain authoritative when the agent itself is not.

The strategic opportunity is qualified delegation. Organizations that can show why an action was eligible, which evidence was current, who authorized it, which limit it consumed and what outcome occurred can safely automate higher-value work sooner. That creates a defensible first-mover advantage without treating speed as permission to weaken controls.

The three-paper research sequence

  1. Program Equilibria and Protected Execution asks when a resource-bounded agent has no profitable unilateral deviation and how a protected controller can enforce exact action, current authority, delegation scope and aggregate budgets.
  2. Risk-Bounded Runtime Assurance asks how a supervisor can preserve a quantified continuation-risk bound under partial observation, worker churn, shared dependencies and delayed effects.
  3. Private Verification across Trust Domains asks how relying domains can verify exact action eligibility, prohibitions and adverse evidence without turning all underlying records into public data.

Together, the papers form a control chain from incentives, through ongoing assurance, to cross-domain eligibility and enforcement. None of the layers should be mistaken for a complete solution by itself.

Use case 1: industrial cooperation across two protected boundaries

Two engineering organizations may ask separate AI systems to coordinate a shared task, such as allocating compute, scheduling a test facility or preparing a joint technical package. Each organization retains its own authority and resource boundary, while the joint plan defines shared scope, budget and assurance obligations. Local approvals alone are insufficient because risk can arise from the combined sequence of actions.

Two organizations use separate protected controllers for a shared AI job, with agreed scope, a joint safety plan and controlled outcome records.
Figure 1. One shared job and two protected resource boundaries. Each LLM proposes; its protected controller checks evidence, approves against current state and enforces at the resource. Dashed lines carry agreed scope and the joint safety plan. Green arrows show controlled effects and outcome records. The joint assurance model must cover both organizations; two local approvals alone do not establish joint safety. Source: Spherity GmbH.

The practical pattern is proposal first, protected decision second, controlled effect third, and durable outcome evidence last. This keeps the agent useful while making the resource owner—not the model—the final authority for an external effect.

Use case 2: a managed agent-swarm platform

A platform may replace or resize agent workers during a customer episode. Safety state cannot disappear with the worker. The protected episode account must retain current authority, shared spending, continuation risk, pending effects and incident context across replacement. Tenant isolation addresses one boundary; provider-wide review is still needed for shared dependencies and systemic failures.

A managed platform routes bounded agent-worker proposals through protected authority, budget, risk and pending-effect controls.
Figure 2. A proposed managed-platform design for one customer episode. Agents propose within a bounded worker pool. Protected controls retain current authority, shared spending, episode risk and pending effects across worker replacement. The provider enforces its own resource boundary; a customer or partner retains local acceptance and enforcement. Outcome records return to protected state. Other tenants remain isolated, while provider-wide incident review addresses shared dependencies. The figure illustrates responsibilities, not a validated platform-wide safety guarantee. Source: Spherity GmbH.

This architecture supports bounded autonomy rather than unlimited autonomy. It allows the platform and customer to place enforcement where each controls the relevant resource, while maintaining an auditable chain of decisions and outcomes.

Leadership action: build safety as reusable execution infrastructure

Boards and executive teams should define which external effects AI may control, require owners for authority and risk budgets, fund independent assurance, and create intervention paths that remain available when systems are operating at machine speed. Product and platform leaders should turn these decisions into reusable control services rather than bespoke review for every workflow.

The near-term CTA is concrete: select one cross-company action with material value and bounded consequences; model its authority, evidence, limits, pending effects and failure paths; implement protected admission at the resource boundary; and compare decision quality, throughput, intervention latency and evidence reuse against the current process.

Evidence, tests and boundaries

The technical papers use mathematical models, machine-checked or executable logic, exhaustive finite-state exploration, synthetic scenarios and counterexamples created by removing controls. These methods are valuable because they make assumptions inspectable and show which invariants fail when a guard is omitted. They do not establish that a policy is ethically or legally adequate, that a model is generally aligned, that field calibration is correct, or that unmodeled physical effects are safe.

Deployment therefore requires staged validation, monitoring, independent challenge and incident learning. The series is a vendor-neutral reference contribution, not a conformity certificate or guarantee of safe outcomes.

Selected references

  1. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0).
  2. NIST, Zero Trust Architecture, SP 800-207.
  3. W3C, Verifiable Credentials Data Model v2.0.
  4. W3C, ODRL Information Model 2.2.
  5. OpenAI, Hugging Face incident and the road ahead.
  6. Anthropic, Alignment assessment of cybersecurity incidents.

How to cite the series

Stöcker, Carsten (2026). Governing AI That Acts Across Companies: How Responsible Leaders Build First Mover Advantage through AI Safety and Alignment. Spherity GmbH. https://spherity.github.io/spherity-research/governing-ai-that-acts-across-companies.html. Licensed CC BY 4.0.

Creative Commons Attribution 4.0 International

Open research

License and citation

This research page, the executive brief and all three linked AI Safety series papers is licensed by its named author under the Creative Commons Attribution 4.0 International License (CC BY 4.0). Reuse must credit every named author, link to this canonical version and the license, and indicate whether changes were made.

How to cite this work

Dr. Carsten Stöcker (2026-09-28). “Governing AI That Acts Across Companies: How responsible leaders build first-mover advantage through AI safety and alignment.” Spherity GmbH. https://spherity.github.io/spherity-research/governing-ai-that-acts-across-companies.html. Licensed CC BY 4.0.

Direct answers

Questions this research answers

How can organizations govern AI agents that act across companies?

They can place protected decision and enforcement points at each resource boundary, require current authority and action-bound evidence, preserve shared limits and pending effects across agent changes, and return durable outcome records to the assurance state.

Why is AI safety a leadership and business issue rather than only a model issue?

Leaders decide which authority, budgets, data and physical or digital effects AI may control. Reusable safeguards can qualify systems for demanding work sooner, while weak controls can scale misaligned objectives, deception and systemic harm across organizational boundaries.

What does this series prove—and what does it not prove?

The papers provide conditional formal results, executable controller checks, finite-state exploration, synthetic scenarios and omission counterexamples under stated assumptions. They do not prove general alignment, policy adequacy, field calibration, unmodeled physical safety or safe behavior outside the mediated effects.

What is the practical sequence across the three papers?

Paper 1 establishes incentive-compatible protected execution; Paper 2 adds risk-bounded runtime assurance under partial observation; Paper 3 adds privacy-preserving action-eligibility verification and controlled execution across trust domains.