Как измерить остаточный риск автономных ИИ-агентов: фреймворк CPSAINT и FRIESA-K
Исследователи в июле 2026 года представили на arXiv фреймворк для количественной оценки остаточного риска ИИ-агентов. CPSAINT раскладывает агента на семь слоёв целостности — от физического состояния и сенсоров до среды и времени, а FRIESA-K переводит каждый путь отказа в конкретное число, выводя эффективность контроля из марковской модели, а не из экспертной оценки «на глаз».
AI-processed from arXiv cs.AI; edited by Hamidun News
In July 2026, researchers published a framework on arXiv for quantitatively assessing the residual risk of agentic AI — a pairing of two models, CPSAINT and FRIESA-K, that translates every failure scenario of an autonomous agent into a specific numerical risk value.
What problem are the authors solving
Agentic AI is gaining access to real-world actions — orders, payments, robot control — faster than risk-assessment methods can keep up. In the authors' own words, existing approaches provide only half of the picture, out of two possible halves: some describe failure mechanisms but don't produce a transferable estimate of residual risk; others quantify risk but treat the internal failure pathway as a black box.
"Agentic AI is crossing trust boundaries faster than current risk
models can describe," is how the authors put it in the abstract of the arXiv study.
CPSAINT and FRIESA-K combine both perspectives: first they break the system down into layers where a failure can occur, then they map each valid failure pathway to a strictly defined numerical risk estimate. The authors call this structural composability — a formal link between a correct failure pathway and a precisely defined "risk instance."
What the framework consists of
CPSAINT is a seven-layer decomposition of agent integrity, where each layer is responsible for a distinct area in which the system's integrity can be violated. Together with the FRIESA-K functional, it forms a "mechanism-to-magnitude" pipeline for resilient agentic and embodied AI.
- The seven layers of CPSAINT: physical state, sensors, data, computation, actuators, environment, and time
- FRIESA-K — the residual risk functional: each failure pathway is mapped to a numerical estimate
- The resistance term K is derived from a controlled absorbing Markov model, rather than assigned "by eye"
- Governance observability is accounted for as a separate additive penalty, rather than as a new variable inside the functional
- Validation — on two contrasting scenarios: a warehouse robot and a financial agent
Why the resistance term K matters
The key distinguishing feature of FRIESA-K is how "resistance" K is calculated — that is, the effectiveness of control measures. Instead of an informal expert estimate, the authors tie K to the dynamics of the system's states via a controlled absorbing Markov model. This way, control effectiveness is derived from how the system actually transitions between states and is "absorbed" by failure, rather than from a subjective score. Governance observability, meanwhile, is carved out into a separate additive penalty — so as not to conflate a system's governability with its technical resilience, or let one substitute for the other within the same formula.
Where the framework was tested
The framework was run on two intentionally different scenarios: a hard-real-time warehouse robot and a financial agent equipped with governance tools. According to the authors, in both cases the same grammar of seven layers, the same variable semantics, and the same dynamic-resistance construction held. In other words, the same "core" apparatus describes both a physical robot with strict timing requirements and a purely software-based agent in financial services — without reinventing the model for each domain.
What this means
The work offers a compact core that links a failure mechanism to its risk magnitude and makes it possible to reason about trust in agents across different domains in a common language. For an industry where AI agents are increasingly gaining access to money and physical actions, a transferable and verifiable estimate of residual risk marks a step away from vague "safety scores" toward numbers backed by state dynamics rather than expert intuition.
Need AI working inside your business — not just in your newsfeed?
I build production AI for companies — custom CRM, internal tools, autonomous agents, workflow automation. Owned by you, shaped to your process, no per-seat tax. Built by Zhemal Khamidun, CPO of AlpinaGPT (AI platform, 6,000+ users).
The AI world, distilled — once a week
Seven stories that actually mattered, hand-picked. No noise, no reposts, no press releases.
Done! Check your inbox for a confirmation.