Cybersecurity & AI Systems / Working paper

Pre-Execution Control Planes for AI and Software Supply Chains

A Deterministic Approach to Admissibility Enforcement

Skip Middleton · ORCID 0009-0001-4524-467X

Abstract overview

This paper considers systems that translate external information into executable behavior, including AI agents and software dependencies. It describes an admissibility layer that evaluates candidate actions before execution, using IVD-ACP as its reference architecture. The discussion covers explicit authority states, a reported agent-environment example, and the relevance of execution boundaries to software supply-chain incidents.

Editorial summary of the author’s abstract. The linked paper contains the full argument.

Why this question matters

The focus is the boundary between an incoming instruction and an authorized action. That distinction is useful when evaluating agent-tool access, dependency execution, and other workflows in which automation can change a system.

Scope and status

The examples describe a limited evaluation context. This working paper should not be read as independent verification of broad security effectiveness or as a claim of production deployment.

For the current public description of the systems, see Invariant Vector Defense.

Keywords

  • pre-execution control
  • software supply chains
  • AI agent security
  • admissibility

Suggested citation

Middleton, Skip. “Pre-Execution Control Planes for AI and Software Supply Chains A Deterministic Approach to Admissibility Enforcement.” Working paper, April 2, 2026. Posted on SSRN April 28, 2026. https://doi.org/10.2139/ssrn.6512098.

Related research

From Implicit Execution to Deterministic Control →

Selected essays & commentary →