From Edge AI to Governed Autonomous Edge Intelligence
Why autonomous AI agents need security, governance, and bounded authority by design SGAEIA Research Series — Article 1 Aridio Silva Independent Researcher, Brazil Creator of SGAEIA — Secure Governed Autonomous Edge Inte
Why autonomous AI agents need security, governance, and bounded authority by design
SGAEIA Research Series — Article 1
Aridio Silva
Independent Researcher, Brazil
Creator of SGAEIA — Secure Governed Autonomous Edge Intelligence Architecture
ORCID: 0009–0008–2411–6995
Contents
- Why developers need to think beyond model security
- From a recommendation to an action
- Delegation should not silently expand authority
- Bound authority and make it withdrawable
- Apply Zero Trust to agent actions
- Make governance part of the engineering lifecycle
- Design security in from the start
- Governed Autonomous Edge Intelligence
- Replace technologies without weakening security properties
- Questions to take into your next design review
- References
This developer-focused edition distills the public Zenodo article into architectural questions and design principles. It is conceptual: no private protocols, implementation logic, state machines, policy internals, or reconstruction-enabling details are disclosed.
Why developers need to think beyond model security
For many years, AI systems mostly analyzed data, generated predictions, classified information, or produced content. People considered the output and decided what to do next. Agentic AI changes that pattern: an agent may interpret a goal, call a tool, use an external service, coordinate with another agent, and cause a change in a digital or physical system [3, 5].
At the same time, AI workloads are moving from centralized cloud platforms toward devices, gateways, local servers, private infrastructure, and cloud services. Edge deployment can help address latency, connectivity, privacy, resilience, bandwidth, and operational constraints. When autonomy and distribution meet, however, a system distributes more than computation: it may distribute the authority to act [1, 2].

Figure 1 — From Computation to Authority. This figure contrasts distributed computation with the additional distribution of operational authority in Agentic Edge AI. © 2026 Aridio Silva | Project SGAEIA | CC BY 4.0.
That change creates a practical engineering question: how can an AI system receive enough authority to be useful while keeping that authority limited, reviewable, and withdrawable? Protecting models, data, networks, and devices remains necessary, but developers also need to reason about which actions an agent may take, under what conditions, and on whose behalf.
From a recommendation to an action
Imagine two systems monitoring industrial telemetry. One recommends that an operator stop a machine. Another is authorized to authenticate to an industrial control system, invoke a tool, stop the machine, open an incident record, and ask another agent to investigate. Both use AI, but the second crosses from producing information into exercising operational authority [3, 5].
This distinction applies beyond industrial control. Any agent that can change a record, invoke a service, access a resource, delegate a task, or trigger a physical action creates security questions about the action itself. The central concern is not simply whether the model produced a plausible response; it is whether the requested action is authorized in its current context.
Delegation should not silently expand authority
A multi-agent workflow can pass work from a person to an agent, from that agent to another agent, and then through a tool or service to an external system. Authentication helps establish which actor is making a request, but identity alone does not explain what that actor may do, why it may do it, or who granted the relevant permission [4, 8].
A useful public design principle is that delegated authority should remain equal to or narrower than the authority from which it came. In practical terms, a downstream agent should not gain broader permission merely because a task passed through another component. Developers should be able to explain the origin and limits of authority at an appropriate level, while implementation details remain specific to the system and its threat model [4, 15].

Figure 2 — Chain of Delegated Authority in a Multi-Agent System. This conceptual figure traces how authority can pass among agents and systems while remaining bounded by its originating grant. © 2026 Aridio Silva | Project SGAEIA | CC BY 4.0.
Bound authority and make it withdrawable
The article describes authority as a combination of identity, scope, resource, action, context, time, and delegation constraints. These are conceptual dimensions, not a required implementation schema. They help teams ask whether a permission is attached to the right actor, resource, operation, environment, period, and delegation boundary [15].

Figure 3 — Bounded and Revocable Authority for Autonomous AI Agents. The figure summarizes authority as explicit, contextual, constrained, and capable of withdrawal. © 2026 Aridio Silva | Project SGAEIA | CC BY 4.0.
Authority also needs a way to be reduced or withdrawn when an agent is compromised, behaves unexpectedly, violates policy, or operates under changed conditions. Stopping a model process alone may not be enough if other components can still accept its requests. The broader architectural principle is that enforcement should not depend solely on an autonomous agent choosing to obey a limit [9, 15].
Apply Zero Trust to agent actions
A network location or deployment environment is not, by itself, proof that an agent should be trusted. Agents can run at the edge, call cloud services, use external tools, collaborate with remote agents, or cross administrative boundaries. A Zero Trust perspective therefore asks for authorization to be evaluated in relation to the requested action and its relevant context [9, 10].
For engineering teams, this means treating each consequential action as a decision point. The system should have a way to assess the actor, permission, policy, resource sensitivity, context, and delegation conditions that matter for that action. The article presents this as a principle for governed Agentic AI, not as a claim that one particular runtime design guarantees security [9, 10].
Make governance part of the engineering lifecycle
Policies, standards, procedures, and audits remain important, but a policy stored only in a document cannot directly stop an unauthorized machine-speed action. For autonomous systems, governance needs to connect to engineering mechanisms that can make constraints machine-readable, enforceable, observable, and testable [8, 11, 15].
The article frames this direction as executable governance: policies define constraints, system components enforce them, telemetry records relevant decisions, evidence helps show whether controls were applied, and tests examine whether intended security properties hold. This does not remove human governance. It gives people more timely information to inspect and challenge.
Evidence-as-Code extends this idea by treating evidence about architecture, controls, tests, policy enforcement, and system behavior as something that can be generated and evaluated through repeatable processes. The aim is to ask not only whether a system passed a past review, but what evidence supports the claim that it remains within its authorized boundaries under the conditions being assessed. Such evidence has limits and does not by itself certify a deployment [11, 15].
Design security in from the start
In distributed multi-agent systems, adding identity, authority, delegation, revocation, auditability, trust boundaries, and policy enforcement after deployment can require substantial redesign. Security-by-Design treats these properties as architectural concerns; Security-First makes security assumptions part of early engineering choices; and Shift-Left brings threat analysis and verification earlier into development [12, 14, 15].
Threat modeling and applicable security guidance can help teams identify risks and derive requirements, tests, and evidence. The specific methods and controls should fit the system, domain, and threat model. Naming a framework or using a checklist is not evidence that a system is secure [6, 7, 13, 14].
Governed Autonomous Edge Intelligence
The article uses Governed Autonomous Edge Intelligence for the direction that emerges when distributed edge intelligence and autonomous action are considered together. Its central proposition is that a sustainable architecture needs to connect intelligence with authority, security, governance, and evidence. The aim is not to eliminate useful autonomy, but to make the authority to act explicit, bounded, traceable, enforceable, reviewable, and withdrawable [1, 2, 3, 5, 15].
SGAEIA — Secure Governed Autonomous Edge Intelligence Architecture — is presented in the public article as an open, technology-neutral research initiative exploring these architectural requirements. It is a research architecture, not a claim of production certification or universal assurance. Its public discussion focuses on concepts, properties, and research direction rather than implementation-sensitive mechanisms [15].
The article describes five connected dimensions: intelligence (perception, reasoning, planning, decisions, and collaboration); authority (permission to act and delegate); security (identity, authentication, policy, and runtime protection); governance (risk, accountability, compliance, and traceability); and evidence (observability, auditability, and material that can support verification). These dimensions may apply across edge devices, industrial systems, vehicles, IoT sensors, gateways, robotics, private infrastructure, regional nodes, and cloud services [15].

Figure 4 — Governed Autonomous Edge Intelligence (SGAEIA). This high-level illustration connects intelligence, authority, security, governance, and evidence across edge-cloud environments. © 2026 Aridio Silva | Project SGAEIA | CC BY 4.0.
Replace technologies without weakening security properties
Models, agent runtimes, communication protocols, identity systems, policy engines, and infrastructure components change quickly. A reference architecture tied too closely to one implementation may become difficult to evolve. The article therefore explores security-preserving substitution: a component should be replaceable without silently weakening the architectural security properties associated with it [15].
This is a design objective, not an automatic outcome of technology neutrality. Teams still need to evaluate each replacement against the properties, assumptions, and evidence relevant to their system.
Questions to take into your next design review
When an AI agent can act, ask: Should it be allowed to perform this action? Who granted the authority? Can it delegate that authority, and under what limits? What conditions change the decision? How can authority be withdrawn? What evidence will let a reviewer understand what happened [3, 5, 15]?
The architectural shift can be summarized simply: Edge AI distributes computation; Agentic Edge AI distributes computation and authority. Governed Autonomous Edge Intelligence asks how that authority can remain bounded, enforceable, auditable, and revocable. The result is a research direction summarized by the SGAEIA principle: Autonomous AI. Governed by Design. Trusted by Evidence.
References
- Zhou, Z., Chen, X., Li, E., Zeng, L., Luo, K., & Zhang, J. (2019). “Edge Intelligence: Paving the Last Mile of Artificial Intelligence With Edge Computing.” Proceedings of the IEEE, 107(8), 1738–1762. DOI: 10.1109/JPROC.2019.2918951.
- Singh, R., & Gill, S. S. (2023). “Edge AI: A Survey.” Internet of Things and Cyber-Physical Systems, 3, 71–92. DOI: 10.1016/j.iotcps.2023.02.004.
- Wang, L., Ma, C., Feng, X., et al. (2024). “A Survey on Large Language Model Based Autonomous Agents.” Frontiers of Computer Science, 18, 186345. DOI: 10.1007/s11704-024-40231-1.
- South, T., Marro, S., Hardjono, T., Mahari, R., Whitney, C. D., Chan, A., & Pentland, A. (2025). “Position: AI Agents Need Authenticated Delegation.” Proceedings of the 42nd International Conference on Machine Learning, PMLR 267, 82211–82231. PMLR.
- Datta, S., Nahin, S. K., Chhabra, A., & Mohapatra, P. (2025). “Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges.” arXiv:2510.23883.
- OWASP GenAI Security Project. (2025). “Agentic AI — Threats and Mitigations.” OWASP Agentic Security Initiative.
- OWASP GenAI Security Project. (2026). OWASP Top 10 for Agentic Applications 2026. OWASP.
- OWASP GenAI Security Project. (2026). Agent Control Standard (ACS). OWASP.
- Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust Architecture. NIST SP 800-207. DOI: 10.6028/NIST.SP.800-207.
- Chandramouli, R., & Butcher, Z. (2023). A Zero Trust Architecture Model for Access Control in Cloud-Native Applications in Multi-Cloud Environments. NIST SP 800-207A. DOI: 10.6028/NIST.SP.800-207A.
- Tabassi, E. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1. DOI: 10.6028/NIST.AI.100-1.
- Scarfone, K., Souppaya, M., & Dodson, D. (2022). Secure Software Development Framework (SSDF) Version 1.1. NIST SP 800-218. DOI: 10.6028/NIST.SP.800-218.
- OWASP Foundation. Threat Modeling Cheat Sheet. OWASP Cheat Sheet Series.
- CISA et al. (2023). Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software. CISA publication.
- Silva, Aridio. (2026). SGAEIA — Secure Governed Autonomous Edge Intelligence Architecture. Research artifact. DOI: 10.5281/zenodo.22557796.
About the Author
Aridio Silva is an independent researcher based in Brazil working on the architecture, security, governance, and trustworthiness of autonomous and distributed artificial intelligence systems.
His research focuses on Agentic AI, Multi-Agent Systems, Edge AI, AI Security, Zero Trust, Security-by-Design, AI Governance, Spec-Driven Development, and continuous security assurance.
He is the creator and lead researcher of SGAEIA — Secure Governed Autonomous Edge Intelligence Architecture, an open research initiative investigating architectural foundations for secure, governed, auditable, and trustworthy autonomous AI systems operating across distributed edge-cloud environments.
Research & Project Resources
Aridio Silva — Independent Researcher, Brazil
- ORCID: https://orcid.org/0009-0008-2411-6995
- Google Scholar: https://scholar.google.com/citations?user=rPn5O48AAAAJ
- Zenodo — SGAEIA Community: https://zenodo.org/communities/sgaeia
- OpenAIRE: https://explore.openaire.eu/search/find?fv0=Aridio%20Silva&f0=q
- Medium: https://medium.com/@aridiosilva
- GitHub: https://github.com/aridiosilva
- LinkedIn: https://www.linkedin.com/in/aridio-silva-74997111/
- SGAEIA Research Artifact / DOI: https://doi.org/10.5281/zenodo.22557796
- Homepage: https://aridiosilva.com
- SGAEIA Homepage: https://aridiosilva.com/sgaeia
- SGAEIA LinkedIn: https://www.linkedin.com/company/sgaeia/
Figures
The cover image is not numbered. Figures 1–4 are numbered sequentially and referenced consistently in the article.
All final images follow the SGAEIA Image Editorial Standard and contain embedded publication metadata.
- Creator: Aridio Silva
- Copyright: © 2026 Aridio Silva
- Project: SGAEIA
- License: CC BY 4.0
- Institutional URL: https://aridiosilva.com/sgaeia
The images are original conceptual illustrations prepared for this article. They remain within the public disclosure boundary by communicating concepts, properties, and high-level governance relationships without exposing private protocols, algorithms, state machines, policy logic, or reconstruction-enabling implementation details.
Suggested citation
Silva, A. (2026). From Edge AI to Governed Autonomous Edge Intelligence (Version 1.0). Zenodo. https://doi.org/10.5281/zenodo.22715250.
License
Except where otherwise noted, the text and original conceptual illustrations in this article are licensed under the Creative Commons Attribution 4.0 International License (CC BY 4.0).
© 2026 Aridio Silva. You may share and adapt this work for any purpose, provided appropriate attribution is given.
The SGAEIA software research artifact remains subject to its own Apache License 2.0.
Autonomous AI. Governed by Design. Trusted by Evidence.
Read the complete article on the SGAEIA homepage
For the full public article and its figures, visit the SGAEIA homepage.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.