Urgent.News

What's breaking now, across thousands of outlets.

AI

Recursive Governance: When Agents Write the Rules They Execute

We almost lost forty modules to a file that never changed. The sync job ran every six hours, mirroring our shared working directory into a test workspace. At 21:47 on a Tuesday, it removed about forty private modules that should have been ignored. The filter file was missing one pattern. That's it. One pattern. A colleague had restructured the source tree three days earlier, added a directory,…

Recursive governance occurs when agents create and enforce their own rules, which can lead to conflicts and inconsistencies as the rules evolve over time. A key problem arises when static policy files are used, as they cannot adapt to changes in the underlying system. To address this, agents were given the ability to write their own rules.

Initially, agents could append to a rule store, resolving conflicts and archiving stale patterns without human intervention. However, over time, the rule store became increasingly complex, with rules contradicting each other and growing in size. This made it difficult to determine which rule was actually in effect. The issue was exacerbated by the lack of lifecycle tooling for rules, as they did not have birth dates, parents, or gravestones.

To improve governance, five non-removable MCP (Multi-Component Policy) tools were implemented within the agent runtime. These tools include propose_rule, amend_rule, ratify_rule, veto_rule, and check_consistency. propose_rule allows agents to submit new rules with rationales and ownership information. amend_rule enables agents to submit changes to existing rules, which are then compared to avoid overwriting. ratify_rule involves voting on open proposals with per-shard quorum. veto_rule provides a human exit mechanism, with justifications recorded for audit purposes. check_consistency scans the rule graph and applies an allow/deny list on tool names to prevent conflicts.

These five tools were initially run as separate services, but are now integrated into the agent runtime contract. Each proposal undergoes a two-phase commit process, with an observation window and a consistency score requirement. The rule set is stored as structured memory events in an append-only namespace, governance://rules/, allowing agents to replay the exact rule state at any past timestamp.

By implementing this recursive governance system, the forty modules that were almost lost due to a missing pattern in the filter file would have been protected. The system's ability to audit and validate rules ensures that unexpected changes are caught and prevented before they become policy.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in AI

The ML you need to operate LLMs, not train them

You do not need to understand backpropagation to run a large language model well in production. You need a smaller, more practical thing: the operator's mental model.

  • Tokens differ from words; longer or uncommon words split into multiple tokens.
  • Temperature and topp parameters are model-specific constraints, not interchangeable dials.

Your AI Agent Will Do Something Terrible. Here's How to Survive It.

Here's a pattern I keep seeing. A team wires up an AI agent that can do real things — send emails, run commands, query and modify the database, call external APIs. The demo is magical.

  • Implement least privilege principle for AI agents
  • Require human approval for high-impact actions
  • Treat all input as untrusted to prevent prompt injection

Best LLM Gateways in 2026: A Production-Ready Comparison

TL;DR An LLM gateway is production-ready when it adds negligible latency under load, fails over across providers without application code, enforces budgets per team, governs MCP tool calls, and deploys where compliance requires.

  • Bifrost is open-source Go-based LLM gateway with high performance
  • Favored for enterprises needing scalability and reliability
  • Not published details for Kong AI Gateway and Cloudflare AI Gateway

More from Tuesday 6 October →