ch-agentic-safety
13 Agentic Safety and Universal Online Decision Learning
Information boundaries, compositional authority, and faithful audit
Agentic systems are increasingly deployed not as a single policy answering a single query, but as populations of persistent processes that communicate, delegate, call tools, modify shared artifacts, and act in external systems. In that setting safety is not solely a property of the model at one decision point. It is a property of the closed-loop information structure generated by the whole deployment.
Witsenhausen’s intrinsic model is therefore directly relevant. It asks which observations are available to each decision maker, how actions alter later observations, and how local policies compose into a team strategy. UODL adds progressive revelation and persistent structure. Together they suggest that an agentic safety claim must name at least four things: the actual information category, the executable capability category, the subcategory of admitted executions, and the observer through which execution is audited.