Saved in:
Bibliographic Details
Main Author: Sharma, Anil Kumar
Format: Recurso digital
Language:
Published: Zenodo 2026
Subjects:
Online Access:https://doi.org/10.5281/zenodo.20047601
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866901287593836544
author Sharma, Anil Kumar
author_facet Sharma, Anil Kumar
contents Version 2 of the FreightBox Zero legal gate architecture paper. Expands the original single-layer description (trust_mask session enforcement) to a full three-layer agent safety stack. Layer 1: TRUST mask bits in AnkrOS session tokens make BL issuance, telex release, LC presentation, OFAC adjudication, and credit write-off structurally impossible for any AI agent session — not policy-prohibited, structurally impossible. Layer 2: AEGIS DAN gate (port 4850) intercepts every agent tool call before execution; L3/L4 actions trigger WhatsApp HITL approval routed to the designated human; the agent waits. Layer 3: KavachOS (port 4855) generates a deterministic seccomp-bpf kernel profile from trust_mask + domain; every syscall is filtered and logged in a PRAMANA SHA-256 tamper-evident receipt chain, satisfying EU AI Act Article 14 at the infrastructure layer. The three layers are independent and complementary — all three must fail simultaneously for a legal gate to be breached. Includes a failure mode matrix showing what each layer prevents and what it cannot prevent, motivating the three-layer design. Platform live at freightbox.org. V1 DOI: 10.5281/zenodo.20047472.
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_20047601
institution Zenodo
language
publishDate 2026
publisher Zenodo
record_format zenodo
spellingShingle FreightBox Zero: Three-Layer Agent Safety Stack for AI-Operated Regulated Entities (v2)
Sharma, Anil Kumar
nvocc
freight-forwarding
ai-agents
legal-gate-architecture
three-layer-safety
bill-of-lading
mletr
ucp-600
trust-mask
ankros
autonomous-operations
freightbox
ebl
dcsa
maritime-ai
ankr
aegis
kavachos
seccomp-bpf
kernel-governance
pramana
hitl
eu-ai-act
article-14
dan-gate
prompt-injection
supply-chain-attack
tamper-evident
Version 2 of the FreightBox Zero legal gate architecture paper. Expands the original single-layer description (trust_mask session enforcement) to a full three-layer agent safety stack. Layer 1: TRUST mask bits in AnkrOS session tokens make BL issuance, telex release, LC presentation, OFAC adjudication, and credit write-off structurally impossible for any AI agent session — not policy-prohibited, structurally impossible. Layer 2: AEGIS DAN gate (port 4850) intercepts every agent tool call before execution; L3/L4 actions trigger WhatsApp HITL approval routed to the designated human; the agent waits. Layer 3: KavachOS (port 4855) generates a deterministic seccomp-bpf kernel profile from trust_mask + domain; every syscall is filtered and logged in a PRAMANA SHA-256 tamper-evident receipt chain, satisfying EU AI Act Article 14 at the infrastructure layer. The three layers are independent and complementary — all three must fail simultaneously for a legal gate to be breached. Includes a failure mode matrix showing what each layer prevents and what it cannot prevent, motivating the three-layer design. Platform live at freightbox.org. V1 DOI: 10.5281/zenodo.20047472.
title FreightBox Zero: Three-Layer Agent Safety Stack for AI-Operated Regulated Entities (v2)
topic nvocc
freight-forwarding
ai-agents
legal-gate-architecture
three-layer-safety
bill-of-lading
mletr
ucp-600
trust-mask
ankros
autonomous-operations
freightbox
ebl
dcsa
maritime-ai
ankr
aegis
kavachos
seccomp-bpf
kernel-governance
pramana
hitl
eu-ai-act
article-14
dan-gate
prompt-injection
supply-chain-attack
tamper-evident
url https://doi.org/10.5281/zenodo.20047601