<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.2 20190208//EN" "http://jats.nlm.nih.gov/publishing/1.2/JATS-journalpublishing1.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="review-article" dtd-version="1.2" xml:lang="en">
    <front>
        <journal-meta>
            <journal-id journal-id-type="pmc">F1000Research</journal-id>
            <journal-title-group>
                <journal-title>F1000Research</journal-title>
            </journal-title-group>
            <issn pub-type="epub">2046-1402</issn>
            <publisher>
                <publisher-name>F1000 Research Limited</publisher-name>
                <publisher-loc>London, UK</publisher-loc>
            </publisher>
        </journal-meta>
        <article-meta>
            <article-id pub-id-type="doi">10.12688/f1000research.169927.1</article-id>
            <article-categories>
                <subj-group subj-group-type="heading">
                    <subject>Review</subject>
                </subj-group>
                <subj-group>
                    <subject>Articles</subject>
                </subj-group>
            </article-categories>
            <title-group>
                <article-title>Trustworthy agentic AI systems: a cross-layer review of architectures, threat models, and governance strategies for real-world deployment</article-title>
                <fn-group content-type="pub-status">
                    <fn>
                        <p>[version 1; peer review: awaiting peer review]</p>
                    </fn>
                </fn-group>
            </title-group>
            <contrib-group>
                <contrib contrib-type="author" corresp="yes">
                    <name>
                        <surname>ADABARA</surname>
                        <given-names>IBRAHIM</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Conceptualization</role>
                    <role content-type="http://credit.niso.org/">Investigation</role>
                    <role content-type="http://credit.niso.org/">Project Administration</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Original Draft Preparation</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Review &amp; Editing</role>
                    <uri content-type="orcid">https://orcid.org/0000-0001-8949-7540</uri>
                    <xref ref-type="corresp" rid="c1">a</xref>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>Olaniyi Sadiq</surname>
                        <given-names>Bashir</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Supervision</role>
                    <role content-type="http://credit.niso.org/">Validation</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Review &amp; Editing</role>
                    <uri content-type="orcid">https://orcid.org/0000-0001-7868-4076</uri>
                    <xref ref-type="aff" rid="a2">2</xref>
                </contrib>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>Nuhu Shuaibu</surname>
                        <given-names>Aliyu</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Methodology</role>
                    <role content-type="http://credit.niso.org/">Resources</role>
                    <role content-type="http://credit.niso.org/">Supervision</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Review &amp; Editing</role>
                    <uri content-type="orcid">https://orcid.org/0000-0002-5171-675X</uri>
                    <xref ref-type="aff" rid="a2">2</xref>
                </contrib>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>Ibrahim Danjuma</surname>
                        <given-names>Yale</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Formal Analysis</role>
                    <role content-type="http://credit.niso.org/">Methodology</role>
                    <role content-type="http://credit.niso.org/">Resources</role>
                    <role content-type="http://credit.niso.org/">Supervision</role>
                    <role content-type="http://credit.niso.org/">Visualization</role>
                    <uri content-type="orcid">https://orcid.org/0000-0003-4226-4760</uri>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>Maninti</surname>
                        <given-names>Venkateswarlu</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Conceptualization</role>
                    <role content-type="http://credit.niso.org/">Data Curation</role>
                    <role content-type="http://credit.niso.org/">Resources</role>
                    <role content-type="http://credit.niso.org/">Software</role>
                    <role content-type="http://credit.niso.org/">Supervision</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Review &amp; Editing</role>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <aff id="a1">
                    <label>1</label>Computing, Kampala International University - Western Campus, Bushenyi, Western Region, Uganda</aff>
                <aff id="a2">
                    <label>2</label>Electrical, Telecommunication, and Computer Engineering, Kampala International University - Western Campus, Bushenyi, Western Region, Uganda</aff>
            </contrib-group>
            <author-notes>
                <corresp id="c1">
                    <label>a</label>
                    <email xlink:href="mailto:adabara.ibrahim@studwc.kiu.ac.ug">adabara.ibrahim@studwc.kiu.ac.ug</email>
                </corresp>
                <fn fn-type="conflict">
                    <p>No competing interests were disclosed.</p>
                </fn>
            </author-notes>
            <pub-date pub-type="epub">
                <day>11</day>
                <month>9</month>
                <year>2025</year>
            </pub-date>
            <pub-date pub-type="collection">
                <year>2025</year>
            </pub-date>
            <volume>14</volume>
            <elocation-id>905</elocation-id>
            <history>
                <date date-type="accepted">
                    <day>3</day>
                    <month>9</month>
                    <year>2025</year>
                </date>
            </history>
            <permissions>
                <copyright-statement>Copyright: &#x00a9; 2025 ADABARA I et al.</copyright-statement>
                <copyright-year>2025</copyright-year>
                <license xlink:href="https://creativecommons.org/licenses/by/4.0/">
                    <license-p>This is an open access article distributed under the terms of the Creative Commons Attribution Licence, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
                </license>
            </permissions>
            <self-uri content-type="pdf" xlink:href="https://f1000research.com/articles/14-905/pdf"/>
            <abstract>
                <p>Agentic Artificial Intelligence systems, characterized by autonomous reasoning, memory augmentation, and adaptive planning, are rapidly reshaping technological landscapes. Unlike traditional AI or large language models, agentic AI integrates decision-making with persistent execution, enabling complex interactions across dynamic environments. However, this evolution introduces novel security risks, governance challenges, and ethical considerations that current frameworks inadequately address. This survey provides a cross-layer review of agentic AI, encompassing architectural paradigms, threat taxonomies, and governance strategies. It consolidates findings from adjacent domains such as cybersecurity, AI safety, multi-agent coordination, and ethics, offering a holistic understanding of vulnerabilities and mitigation approaches. We integrate insights from recent advances in defense architectures and governance innovations, highlighting the limitations of static policies in addressing dynamically evolving threats. Real-world deployments from industrial automation to military and policy applications reveal both successful integrations and notable failures, underscoring the urgency of resilient oversight mechanisms. Furthermore, we identify critical research gaps in benchmarking, memory integrity, adversarial defense, and normative embedding, emphasizing the need for interdisciplinary collaboration to develop adaptive, accountable, and transparent systems. This review serves as a narrative synthesis rather than a systematic literature review, aiming to bridge technical, governance, and ethical perspectives. By integrating cross-disciplinary findings, it lays the foundation for future research on securing, aligning, and governing agentic AI in real-world contexts. Ultimately, this work calls for cooperative innovation to ensure that agentic AI evolves as a trustworthy, accountable, and beneficial technology.</p>
            </abstract>
            <kwd-group kwd-group-type="author">
                <kwd>Agentic Artificial Intelligence</kwd>
                <kwd>Autonomous Systems</kwd>
                <kwd>Multi-Agent Systems. Memory-Augmented Reasoning</kwd>
                <kwd>Threat Modeling</kwd>
                <kwd>Secure Execution</kwd>
                <kwd>Lifecycle Control</kwd>
                <kwd>AI Governance</kwd>
            </kwd-group>
            <funding-group>
                <award-group id="fund-1">
                    <funding-source>None</funding-source>
                </award-group>
                <funding-statement>The author(s) declared that no grants were involved in supporting this work.</funding-statement>
            </funding-group>
        </article-meta>
    </front>
    <body>
        <sec id="sec1" sec-type="intro">
            <title>1. Introduction</title>
            <p>The rapid emergence of agentic AI systems, AI agents endowed with memory, reasoning, planning, and tool-use capabilities, represents a paradigm shift from traditional machine learning and static decision-support models. These systems are increasingly deployed in domains where autonomous decision-making interacts with dynamic, high-stakes environments such as healthcare, critical infrastructure, and cybersecurity. While their autonomy promises unprecedented efficiency and innovation, it also introduces novel risks that challenge existing frameworks for safety, ethics, and governance.
                <sup>
                    <xref ref-type="bibr" rid="ref1">1</xref>
                </sup> From a security perspective, agentic AI increases the attack surface. Autonomous decision-making enables new forms of adversarial manipulation, including cognitive exploits, stealth execution, and knowledge poisoning. Conventional layered security models, originally designed for static computing architectures, are inadequate for defending adaptive, distributed agents. Researchers argue that cross-layer security strategies integrating hardware, software, and governance measures are necessary to address these vulnerabilities holistically.
                <sup>
                    <xref ref-type="bibr" rid="ref2">2</xref>
                </sup>
            </p>
            <p>The concept of &#x201c;trustworthiness&#x201d; itself is contested. Scholars Conradie &amp; Nagel
                <sup>
                    <xref ref-type="bibr" rid="ref3">3</xref>
                </sup> and Freiman
                <sup>
                    <xref ref-type="bibr" rid="ref4">4</xref>
                </sup> caution against anthropomorphizing AI with human attributes such as &#x201c;trust&#x201d; and &#x201c;responsibility,&#x201d; noting that these qualities must instead be framed as properties of socio-technical systems that include human oversight and institutional. This highlights the need to shift the focus from asking whether AI itself can be &#x201c;trusted&#x201d; to how we can build systems that support human-centered trust relationships through technical safeguards and governance. Governance frameworks such as the EU AI Act, NIST&#x2019;s AI Risk Management Framework, and ISO/IEC standards have laid initial foundations, but they lack granularity for managing agentic systems that self-adapt, collaborate, and act semi-independently. Integrating principles of zero-trust architectures, explainable AI, and adaptive oversight mechanisms is now seen as crucial for aligning agentic AI with societal expectations of accountability and safety.
                <sup>
                    <xref ref-type="bibr" rid="ref5">5</xref>,
                    <xref ref-type="bibr" rid="ref6">6</xref>
                </sup> Finally, real-world deployments from national crisis response to autonomous cybersecurity demonstrate both the potential and fragility of agentic AI. Cases of unanticipated failures, bias amplification, and adversarial exploitation underscore the urgency of developing a cross-layer understanding that integrates architecture, threats, and governance strategies.
                <sup>
                    <xref ref-type="bibr" rid="ref7">7</xref>
                </sup> In light of these challenges, this review is motivated by the need to bridge technical insights with ethical and regulatory perspectives, offering a holistic framework to guide both researchers and policymakers in building trustworthy agentic AI systems.</p>
            <p>This review adopts a narrative review methodology rather than a systematic literature review (SLR). Unlike SLRs, which employ rigid inclusion and exclusion criteria, a narrative review enables a broad, integrative synthesis across multiple disciplines. This flexibility is essential for agentic AI, where developments in architectures, security threats, and governance evolve rapidly and often emerge outside traditional peer-reviewed channels, including industry white papers and policy documents.
                <sup>
                    <xref ref-type="bibr" rid="ref8">8</xref>
                </sup>
            </p>
            <p>The scope of this work spans technical, ethical, and regulatory dimensions, providing a cross-layer perspective on:
                <list list-type="bullet">
                    <list-item>
                        <label>&#x2022;</label>
                        <p>

                            <bold>Agentic AI Architectures:</bold> including mono-agent, multi-agent, federated, and blockchain-enabled systems, with a focus on how these architectures influence trustworthiness.</p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>

                            <bold>Threat Models and Security Risks:</bold> covering cognitive exploits, knowledge poisoning, prompt injection, stealth execution, and cross-layer propagation vulnerabilities.</p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>

                            <bold>Governance and Oversight Mechanisms</bold>: analyzing legal frameworks such as the EU AI Act, NIST, ethical norms, and lifecycle accountability approaches.</p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>

                            <bold>Defense Strategies and Risk Mitigation:</bold> reviewing zero-trust frameworks, cryptographic identity mechanisms, and layered defense strategies for resilient deployments.</p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>

                            <bold>Real-World Deployments:</bold> evaluating industrial and governmental use cases, security incidents, and lessons learned for future deployments.</p>
                    </list-item>
                </list>
            </p>
            <p>The literature reviewed draws from AI safety, cybersecurity, governance, ethics, and distributed systems, ensuring an interdisciplinary lens.
                <sup>
                    <xref ref-type="bibr" rid="ref9">9</xref>
                </sup> Unlike prior reviews that focus narrowly on either technical mechanisms or policy considerations, this review integrates both dimensions to reveal emerging gaps in aligning technical safeguards with governance strategies.
                <sup>
                    <xref ref-type="bibr" rid="ref10">10</xref>
                </sup> Furthermore, this review includes insights from adjacent domains such as multi-agent coordination, cybersecurity resilience, and human-centered AI ethics to map a more comprehensive landscape of trust challenges and mitigation strategies.
                <sup>
                    <xref ref-type="bibr" rid="ref11">11</xref>
                </sup> Synthesizing this diverse body of knowledge offers a holistic foundation for researchers, practitioners, and policymakers seeking to understand and secure the future of agentic AI.</p>
            <p>This review makes four key contributions by consolidating insights across technical, adversarial, and governance layers to address the trustworthiness of agentic AI systems.
                <list list-type="order">
                    <list-item>
                        <label>1.</label>
                        <p>Integration of Cross-Layer Perspectives: Unlike prior studies that analyze AI trustworthiness through isolated lenses (technical or ethical), this review integrates findings across architectures, threats, and governance, offering a comprehensive cross-layer framework. This approach aligns with recent calls for merging hardware/software security with policy oversight to address complex AI risks.
                            <sup>
                                <xref ref-type="bibr" rid="ref2">2</xref>
                            </sup>
                        </p>
                    </list-item>
                    <list-item>
                        <label>2.</label>
                        <p>Development of a Layered Threat Taxonomy: The paper introduces a novel taxonomy that categorizes risks specific to agentic AI, including cognitive exploits, shadow agent emergence, and cross-layer propagation vulnerabilities. This taxonomy extends beyond traditional adversarial machine learning, incorporating threats identified in recent cybersecurity research.
                            <sup>
                                <xref ref-type="bibr" rid="ref7">7</xref>,
                                <xref ref-type="bibr" rid="ref12">12</xref>
                            </sup>
                        </p>
                    </list-item>
                    <list-item>
                        <label>3.</label>
                        <p>Synthesis of Governance with Technical Safeguards: This review connects policy frameworks such as the EU AI Act, ISO/IEC governance models, with technical defense strategies such as zero-trust architectures and explainable AI. This synthesis provides actionable guidance for designing systems that are both technically secure and aligned with societal expectations.
                            <sup>
                                <xref ref-type="bibr" rid="ref5">5</xref>,
                                <xref ref-type="bibr" rid="ref6">6</xref>
                            </sup>
                        </p>
                    </list-item>
                    <list-item>
                        <label>4.</label>
                        <p>Identification of Research Gaps and Future Directions: Finally, this paper highlights critical gaps such as lifecycle accountability, benchmarking of agentic AI safety, and federated governance risks, and proposes a roadmap for future research. These findings aim to inspire interdisciplinary collaboration to close existing gaps between technology, security, and regulation.
                            <sup>
                                <xref ref-type="bibr" rid="ref9">9</xref>
                            </sup>
                        </p>
                    </list-item>
                </list>
            </p>
            <p>Collectively, these contributions offer a holistic foundation for understanding and securing agentic AI, guiding both technical innovations and governance frameworks for real-world deployment.</p>
            <p>The remainder of this paper is organized to progressively build a cross-layer understanding of trustworthy agentic AI, beginning with its methodological foundations and advancing toward governance and future research directions. 
                <xref ref-type="sec" rid="sec2">Section 2</xref> outlines the narrative review methodology, describing the sources, search strategy, inclusion rationale, and the domains considered, while also contrasting this approach with prior surveys to highlight the novelty of this work. 
                <xref ref-type="sec" rid="sec7">
Section 3</xref> establishes the technical foundations of agentic AI by defining its distinguishing features, including memory-augmented reasoning, planning capabilities, and interaction with adjacent research areas such as AI safety and distributed systems. Building on this, 
                <xref ref-type="sec" rid="sec12">
Section 4</xref> explores architectural paradigms, from mono-agent to blockchain-enabled systems, and provides a comparative evaluation that emphasizes their strengths and limitations in terms of trustworthiness. 
                <xref ref-type="sec" rid="sec18">
Section 5</xref> develops a layered threat taxonomy, mapping cognitive exploits, knowledge poisoning, stealth execution, and cross-layer propagation risks, while integrating insights from cybersecurity and adversarial machine learning literature. 
                <xref ref-type="sec" rid="sec28">
Section 6</xref> shifts focus to governance frameworks, reviewing existing regulatory approaches, identifying gaps unique to agentic systems, and drawing lessons from adjacent domains like robotics and cybersecurity governance. 
                <xref ref-type="sec" rid="sec35">
Section 7</xref> examines real-world deployments, including industrial, governmental, and policy-driven use cases, and reflects on both successful implementations and documented failures. 
                <xref ref-type="sec" rid="sec40">
Section 8</xref> discusses defense architectures and oversight models, evaluating mechanisms such as layered security frameworks, zero-trust architectures, and cryptographic identity enforcement, while offering a comparative analysis of their effectiveness. 
                <xref ref-type="sec" rid="sec46">Section 9</xref> synthesizes the findings to identify open research challenges, including goal alignment, auditability, and institutional readiness, and proposes future directions to bridge these gaps. Finally, 
                <xref ref-type="sec" rid="sec56">
Section 10</xref> concludes by summarizing key insights, presenting a forward-looking perspective on the evolution of trustworthy agentic AI, and emphasizing the need for interdisciplinary collaboration to ensure safe and accountable deployment. This structured progression from foundations to threats, governance, real-world applications, and future outlook ensures that readers gain a comprehensive understanding of the multifaceted issues surrounding agentic AI trustworthiness.</p>
        </sec>
        <sec id="sec2">
            <title>2. Literature review methodology</title>
            <sec id="sec3">
                <title>2.1 Literature sources and search strategy</title>
                <p>Key distinguishing features of agentic AI systems are summarized in Table A2, while architectural comparisons are provided in Table A3. Additionally, a taxonomy of emerging threats is outlined in Table A4 (Supplementary Material).</p>
                <p>Given the interdisciplinary nature of agentic AI, this review adopts a narrative approach to identify and synthesize relevant literature rather than applying rigid inclusion rules. The search process was designed to capture technical, security, and governance perspectives, allowing the integration of diverse insights from multiple domains. Academic databases such as IEEE Xplore, ACM Digital Library, SpringerLink, ScienceDirect, and arXiv were the primary sources, complemented by policy reports from organizations including the OECD, NIST, and the European Commission. To ensure coverage of cutting-edge developments, recent conference proceedings such as NeurIPS, ICML, and AAAI were also reviewed.
                    <sup>
                        <xref ref-type="bibr" rid="ref13">13</xref>
                    </sup>
                </p>
                <p>The search strategy combined keyword clusters such as &#x201c;agentic AI,&#x201d; &#x201c;autonomous agents,&#x201d; &#x201c;multi-agent systems,&#x201d; &#x201c;cross-layer security,&#x201d; &#x201c;trustworthy AI,&#x201d; &#x201c;AI governance,&#x201d; and &#x201c;threat modeling.&#x201d; Boolean operators and field-specific terms were applied to maximize the retrieval of high-quality and contextually relevant articles. The selection was not limited to peer-reviewed journals; influential technical white papers and government publications were included where they provided substantial insights into emerging practices or regulatory frameworks.
                    <sup>
                        <xref ref-type="bibr" rid="ref14">14</xref>
                    </sup>
                </p>
                <p>Articles were included based on relevance to the cross-layer trustworthiness of agentic AI, covering themes of architectural design, threat taxonomy, governance, and ethical oversight. No strict temporal filter was applied; however, priority was given to literature from the last five years to reflect rapid technological advances. Older works were retained where they provided foundational theoretical frameworks. Unlike systematic reviews, which rely on predefined inclusion thresholds, this narrative review allows the inclusion of conceptually significant studies even if they fall outside narrow search criteria.
                    <sup>
                        <xref ref-type="bibr" rid="ref15">15</xref>
                    </sup> Finally, to address emerging debates, grey literature such as industrial threat reports, AI safety guidelines, and open-source datasets was selectively integrated where it contributed unique evidence not yet present in academic publications.
                    <sup>
                        <xref ref-type="bibr" rid="ref16">16</xref>
                    </sup> This multifaceted strategy ensures the survey encompasses both well-established theories and cutting-edge practices shaping the discourse on trustworthy agentic AI.</p>
            </sec>
            <sec id="sec4">
                <title>2.2 Inclusion and relevance criteria</title>
                <p>The inclusion of literature in this survey was guided by conceptual relevance rather than rigid filtering, consistent with the narrative review methodology. Rather than applying standardized exclusion protocols characteristic of systematic reviews, this study adopted a flexible, rationale-driven selection process that allowed the incorporation of diverse perspectives spanning technical, ethical, and governance dimensions. This approach is particularly appropriate for agentic AI, where developments often emerge from interdisciplinary intersections and non-traditional publication channels.
                    <sup>
                        <xref ref-type="bibr" rid="ref15">15</xref>
                    </sup>

                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Sources were considered relevant if they contributed substantively to at least one of the following dimensions:</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Architectural Foundations papers offering insights into agentic architectures, multi-agent systems, or distributed designs, including blockchain-enabled or federated models.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Threat Models and Security Risks studies that examined adversarial techniques, cross-layer propagation of attacks, or security vulnerabilities specific to autonomous agents.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Governance and Ethical Oversight literature addressing regulatory frameworks, ethical principles, or lifecycle accountability mechanisms for AI systems.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Defense Mechanisms and Mitigation Strategies research proposing zero-trust models, layered defense frameworks, or cryptographic identity enforcement approaches relevant to agentic AI security.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Real-world deployments, case studies, industry reports, or empirical analyses documenting the successes and failures of agentic AI deployments in practice.</p>
                        </list-item>
                    </list>
                </p>
                <p>Priority was given to peer-reviewed publications from recognized journals and conferences, particularly those published in the last five years, reflecting the fast-evolving nature of this field. However, seminal works regardless of publication year were included when they provided foundational theoretical or methodological contributions.
                    <sup>
                        <xref ref-type="bibr" rid="ref17">17</xref>
                    </sup> In addition, high-impact grey literature such as policy briefs, technical white papers, and reports from AI governance bodies were selectively incorporated to capture perspectives not yet reflected in academic discourse.
                    <sup>
                        <xref ref-type="bibr" rid="ref16">16</xref>
                    </sup> Studies that focused exclusively on narrow domains such as standard supervised learning or traditional AI ethics without a direct connection to agentic autonomy, layered security, or governance were excluded. Similarly, sources lacking technical or conceptual rigor (such as opinion articles without evidence) were not retained. This balanced approach ensured the review&#x2019;s inclusivity while maintaining its academic quality.</p>
            </sec>
            <sec id="sec5">
                <title>2.3 Domains covered in this survey</title>
                <p>This survey spans seven interconnected domains that collectively shape the trustworthiness of agentic AI systems: agentic architectures, cybersecurity and adversarial threats, AI safety, governance frameworks, and ethical considerations. These domains were selected because they form the technical, operational, and normative pillars essential for understanding and mitigating risks associated with autonomous agents.</p>
                <p>The first domain, agentic AI architectures, encompasses research on the design and functioning of mono-agent, multi-agent, federated, and blockchain-enabled systems. These architectures define how agents perceive, reason, and act within dynamic environments. Recent works highlight that architectural choices significantly influence security vulnerabilities, coordination strategies, and trust propagation among agents.
                    <sup>
                        <xref ref-type="bibr" rid="ref13">13</xref>
                    </sup> The second domain focuses on cybersecurity and adversarial threats. Agentic AI, due to its autonomous decision-making and interconnected operations, introduces new attack vectors such as cognitive exploits, stealth execution, and cross-layer propagation risks. Studies in adversarial machine learning and zero-trust architectures underscore the need for layered defenses and adaptive security frameworks to counter these evolving threats.
                    <sup>
                        <xref ref-type="bibr" rid="ref2">2</xref>
                    </sup> The third domain, AI safety, addresses the alignment of agentic behavior with human values and intended goals. This includes mitigating risks like reward hacking, goal drift, and emergent behaviors in multi-agent settings. Literature from AI safety research emphasizes the integration of formal verification, runtime monitoring, and explainability mechanisms to ensure predictable and controllable outcomes.
                    <sup>
                        <xref ref-type="bibr" rid="ref9">9</xref>
                    </sup> The fourth domain centers on AI governance and regulatory frameworks. International policies, such as the EU AI Act and NIST AI Risk Management Framework, provide high-level guidelines but often fall short of addressing the adaptive and distributed nature of agentic systems. Recent research advocates for hybrid governance models that combine legal mandates with technical enforcement mechanisms.
                    <sup>
                        <xref ref-type="bibr" rid="ref5">5</xref>
                    </sup> Finally, the fifth domain incorporates ethical and socio-technical considerations. Trust in agentic AI is not merely a technical property but a relational construct shaped by human perceptions, institutional accountability, and societal norms. Scholars have warned against anthropomorphizing AI with human-like trust qualities, instead calling for frameworks that prioritize responsible human oversight and equitable power dynamics in AI deployment.
                    <sup>
                        <xref ref-type="bibr" rid="ref3">3</xref>
                    </sup> By synthesizing insights from these seven domains, this review provides a holistic lens to examine both the opportunities and risks associated with agentic AI, offering guidance for secure, ethical, and accountable real-world deployment. As shown in 
                    <xref ref-type="fig" rid="f1">Figure 1</xref>. mind map of agentic AI domains. This diagram illustrates the seven interconnected domains influencing the trustworthiness of agentic AI systems: architectures, cybersecurity, AI safety, governance, ethical considerations, real-world deployments, and defense mechanisms. These domains form the foundation of the cross-layer framework proposed in the review.</p>
                <fig fig-type="figure" id="f1" orientation="portrait" position="float">
                    <label>
Figure 1. </label>
                    <caption>
                        <title>Mind Map of Agentic AI Domains.</title>
                        <p>Conceptual diagram showing the interconnection of key domains: architectures, AI safety, threats, multi-agent systems, governance, defense, and ethics.</p>
                    </caption>
                    <graphic id="gr1" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/187320/b84a7a26-d91c-4577-b571-86480f29d540_figure1.gif"/>
                </fig>
            </sec>
            <sec id="sec6">
                <title>2.4 Comparison with existing surveys</title>
                <p>Existing surveys on AI trustworthiness have largely focused on either technical mechanisms or policy frameworks, leaving a gap in integrating these perspectives under a unified cross-layer approach. For example, surveys in the domain of cybersecurity and AI have primarily concentrated on adversarial machine learning, intrusion detection, and threat intelligence without addressing how these threats propagate across agentic architectures or interact with governance layers.
                    <sup>
                        <xref ref-type="bibr" rid="ref13">13</xref>
                    </sup> Similarly, reviews from the AI ethics literature tend to emphasize normative principles such as fairness, accountability, and transparency without offering concrete architectural or defensive models applicable to autonomous agents.
                    <sup>
                        <xref ref-type="bibr" rid="ref3">3</xref>
                    </sup>
                </p>
                <p>A few recent works have attempted to bridge technical and governance perspectives. For instance, studies on zero-trust architectures in AI security argue for embedding security across multiple layers of AI systems, yet they do not systematically link these mechanisms to agentic AI&#x2019;s unique properties, such as self-adaptation or collaborative behavior in multi-agent environments.
                    <sup>
                        <xref ref-type="bibr" rid="ref2">2</xref>
                    </sup> Meanwhile, policy-oriented reviews, including those analyzing the EU AI Act and related regulatory frameworks, provide high-level governance principles but lack the technical granularity necessary for implementing safeguards within agentic ecosystems.
                    <sup>
                        <xref ref-type="bibr" rid="ref5">5</xref>
                    </sup> Unlike these prior surveys, the present work adopts a cross-layer narrative perspective, systematically connecting architectural design choices, threat models, and governance strategies. It also incorporates real-world deployment experiences and emerging defense architectures, aspects often overlooked in earlier reviews. Furthermore, this study explicitly integrates adjacent domains such as AI safety, cybersecurity resilience, and robotics governance, creating a broader synthesis that reveals interdependencies between technical risks and institutional responses.
                    <sup>
                        <xref ref-type="bibr" rid="ref9">9</xref>
                    </sup> As shown in 
                    <xref ref-type="fig" rid="f2">Flowchart 1</xref>, the survey methodology. Outlines the narrative review process used in the study, including literature source selection, interdisciplinary integration, and thematic synthesis across technical, ethical, and governance domains. By filling these gaps, this review not only complements but also extends the scope of existing literature, providing a comprehensive framework to guide future research and policy design for trustworthy agentic AI systems.</p>
                <fig fig-type="figure" id="f2" orientation="portrait" position="float">
                    <label>Flowchart 1. </label>
                    <caption>
                        <title>Survey Methodology (Narrative Approach).</title>
                        <p>Depicts the literature review workflow, including source selection, search strategy, inclusion criteria, thematic synthesis, and selection of relevant studies.</p>
                    </caption>
                    <graphic id="gr2" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/187320/b84a7a26-d91c-4577-b571-86480f29d540_figure2.gif"/>
                </fig>
            </sec>
        </sec>
        <sec id="sec7">
            <title>3. Technical foundations of agentic AI systems</title>
            <sec id="sec8">
                <title>3.1 Defining agentic AI and its distinction from LLMs and traditional agents</title>
                <p>Agentic AI refers to a class of artificial intelligence systems endowed with autonomy, memory, reasoning, planning, and proactive tool use, enabling them to operate in dynamic environments with minimal human intervention. Unlike traditional AI agents, which are typically task-specific and rule-bound, agentic AI demonstrates goal-directed behavior, the capacity for self-decomposition of complex tasks, and the ability to coordinate with other agents in multi-agent ecosystems.
                    <sup>
                        <xref ref-type="bibr" rid="ref18">18</xref>
                    </sup> These systems integrate persistent memory and adaptive decision-making loops, enabling them to learn continuously and adjust their actions in response to environmental changes. In contrast, Large Language Models (LLMs) such as GPT and similar architectures are primarily predictive models trained to generate responses based on statistical patterns in large datasets. While LLMs have shown remarkable capabilities in natural language understanding and reasoning, they lack true agency: they do not possess intrinsic goals, persistent memory (beyond limited context windows), or the ability to autonomously plan and execute actions in the real world. Recent research, however, demonstrates that LLMs can serve as cognitive cores for agentic systems when augmented with external memory, planning modules, and orchestration layers.
                    <sup>
                        <xref ref-type="bibr" rid="ref19">19</xref>
                    </sup> This hybridization blurs the boundary but does not erase the fundamental distinction: LLMs remain reactive tools unless embedded within an agentic framework that endows them with autonomy.</p>
                <p>Traditional AI agents, such as rule-based expert systems or early multi-agent architectures, operate with predefined logic and limited adaptability. Their actions are constrained by fixed decision trees or programmed behaviors, making them ill-suited for open-ended environments. Agentic AI, by contrast, leverages dynamic task decomposition, meta-reasoning, and tool orchestration to perform tasks not explicitly programmed at design time.
                    <sup>
                        <xref ref-type="bibr" rid="ref20">20</xref>
                    </sup> Moreover, agentic systems often operate within multi-agent ecosystems, enabling collective intelligence through cooperation, negotiation, and competition. Recent developments such as UserCentrix and Agent4EDU frameworks illustrate how agentic AI can combine LLM reasoning with memory-augmented orchestration and multi-agent collaboration to achieve real-world objectives autonomously.
                    <sup>
                        <xref ref-type="bibr" rid="ref21">21</xref>,
                        <xref ref-type="bibr" rid="ref22">22</xref>
                    </sup> These features position agentic AI as a new paradigm that goes beyond both traditional AI agents and standalone LLMs, introducing unique opportunities and security and governance challenges that warrant cross-layer analysis. 
                    <xref ref-type="fig" rid="f3">
Figure 2</xref>. Layered architecture of AAI. A conceptual depiction of the layered components of agentic AI systems, including memory, reasoning, planning, and tool-use layers, demonstrating how these components interact to enable autonomy and adaptability.</p>
                <fig fig-type="figure" id="f3" orientation="portrait" position="float">
                    <label>
Figure 2. </label>
                    <caption>
                        <title>Layered Architecture of Agentic AI.</title>
                        <p>Five-layered framework of agentic AI: governance, cognition, memory, interaction, and secure execution, connected to environmental inputs and outputs.</p>
                    </caption>
                    <graphic id="gr3" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/187320/b84a7a26-d91c-4577-b571-86480f29d540_figure3.gif"/>
                </fig>
            </sec>
            <sec id="sec9">
                <title>3.2 Core capabilities: Memory, reasoning, planning, and tool use</title>
                <p>Agentic AI derives its autonomy and adaptability from four foundational capabilities: memory, reasoning, planning, and tool use. These elements collectively distinguish it from both traditional AI agents and large language models, enabling it to operate proactively in dynamic environments.</p>
                <p>Memory is central to agentic AI, allowing agents to store and retrieve information beyond the ephemeral context of traditional LLMs. Persistent memory enables agents to build long-term representations of their environment, user preferences, and past decisions, thereby supporting contextual continuity and more informed action selection.
                    <sup>
                        <xref ref-type="bibr" rid="ref23">23</xref>
                    </sup> Advanced frameworks like UserCentrix demonstrate how memory-augmented reasoning enhances responsiveness and adaptability in real-world applications.
                    <sup>
                        <xref ref-type="bibr" rid="ref24">24</xref>
                    </sup> Reasoning refers to the agent&#x2019;s ability to interpret complex scenarios, infer hidden relationships, and adapt to novel conditions. Unlike traditional AI, which often relies on static decision rules, agentic AI employs multi-step and reflective reasoning processes, incorporating meta-cognition to evaluate its outputs. Studies have shown that agentic workflows enable emergent reasoning behaviors not observed in static LLMs, enhancing performance in research automation, robotics, and decision support.
                    <sup>
                        <xref ref-type="bibr" rid="ref18">18</xref>
                    </sup> Planning is another hallmark capability, allowing agentic AI to decompose complex objectives into manageable subtasks and execute them sequentially. Modern systems like Magentic-One leverage orchestration agents to dynamically re-plan when errors or unexpected conditions arise, reflecting a robustness absent in conventional agents.
                    <sup>
                        <xref ref-type="bibr" rid="ref25">25</xref>
                    </sup> Planning is not only reactive but also anticipatory, enabling agents to optimize actions based on long-term goals rather than short-term heuristics. Tool use extends the agent&#x2019;s functionality beyond its intrinsic capabilities. By integrating external APIs, databases, or software tools, agentic AI can interact with diverse environments and perform specialized tasks. Tool orchestration, when combined with reasoning and planning, creates multi-modal and adaptive intelligence that supports dynamic problem solving. This capability has been shown to enhance performance in complex tasks such as automated coding, scientific discovery, and cyber-defense.
                    <sup>
                        <xref ref-type="bibr" rid="ref26">26</xref>
                    </sup> Collectively, these four capabilities form the operational backbone of agentic AI. Their synergy enables systems not only to react to immediate inputs but to proactively plan, self-correct, and interact with their environment, making them fundamentally more autonomous and potentially more unpredictable than previous AI paradigms. As shown in 
                    <xref ref-type="fig" rid="f4">
Figure 3</xref>, the cognitive architecture workflow in this figure shows the operational workflow of agentic AI cognition, highlighting the integration of memory, reasoning, planning, and tool orchestration to support goal-directed behavior in dynamic environments.</p>
                <fig fig-type="figure" id="f4" orientation="portrait" position="float">
                    <label>
Figure 3. </label>
                    <caption>
                        <title>Cognitive Architecture Workflow.</title>
                        <p>Workflow showing how perception, memory recall, reasoning, and planning interact in cycles to generate adaptive responses.</p>
                    </caption>
                    <graphic id="gr4" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/187320/b84a7a26-d91c-4577-b571-86480f29d540_figure4.gif"/>
                </fig>
            </sec>
            <sec id="sec10">
                <title>3.3 Interaction with adjacent fields (AI safety, multi-agent coordination, distributed systems)</title>
                <p>The comparative analysis of governance frameworks across domains is detailed in Table A5 (Supplementary Material).</p>
                <p>Agentic AI does not exist in isolation; its design and deployment are profoundly influenced by developments in AI safety, multi-agent coordination, and distributed systems. These adjacent fields provide both theoretical foundations and practical frameworks that shape the trustworthiness and resilience of agentic systems. AI safety contributes critical principles for ensuring that agentic AI remains aligned with human values and operational goals, even under conditions of uncertainty or adversarial pressure. Research highlights that emergent behaviors, such as reward hacking and specification gaming, can arise in complex environments where agents pursue objectives without adequate safeguards.
                    <sup>
                        <xref ref-type="bibr" rid="ref27">27</xref>
                    </sup> Safety frameworks increasingly emphasize the need for alignment mechanisms, runtime monitoring, and formal verification to mitigate these risks.
                    <sup>
                        <xref ref-type="bibr" rid="ref28">28</xref>
                    </sup> The field of multi-agent coordination offers insights into how autonomous agents collaborate, negotiate, and sometimes compete within shared environments. Techniques such as cooperative reinforcement learning, communication protocols, and game-theoretic models enhance the ability of agents to achieve collective goals while minimizing coordination failures. However, interactions in multi-agent ecosystems also introduce new vulnerabilities, including collusion, stealth attacks, and emergent adversarial dynamics.
                    <sup>
                        <xref ref-type="bibr" rid="ref29">29</xref>
                    </sup> Studies show that protocols combining parameter sharing and coordinated learning significantly improve collaborative performance but must be balanced against risks of unintended strategic behaviors.
                    <sup>
                        <xref ref-type="bibr" rid="ref30">30</xref>
                    </sup> Finally, distributed systems provide architectural models that enable scalability and resilience in agentic AI deployments. Concepts from distributed computing, such as fault tolerance, decentralized consensus, and secure communication, inform the design of federated and blockchain-enabled agentic frameworks. These architectures facilitate robust performance across heterogeneous environments but also create new attack surfaces, particularly where trust propagation and identity management are not well enforced.
                    <sup>
                        <xref ref-type="bibr" rid="ref31">31</xref>
                    </sup> Recent proposals, such as UserCentrix, leverage distributed intelligence with memory-augmented coordination to achieve adaptive decision-making while maintaining situational awareness.
                    <sup>
                        <xref ref-type="bibr" rid="ref24">24</xref>
                    </sup> By synthesizing insights from these adjacent fields, agentic AI research gains robust strategies for safety, coordination efficiency, and resilience against systemic threats. This interdisciplinary interplay is crucial for advancing secure, scalable, and ethically aligned agentic ecosystems.</p>
            </sec>
            <sec id="sec11">
                <title>3.4 Key theoretical frameworks underpinning agentic AI</title>
                <p>The development of agentic AI is grounded in several theoretical frameworks that collectively define its reasoning capabilities, decision-making processes, and adaptive behaviors. These frameworks originate from cognitive architectures, reinforcement learning theories, game-theoretic models, and distributed adaptive control, each contributing distinct mechanisms for achieving autonomy and trustworthiness. Cognitive architectures such as ACT-R and Soar provide a structured approach to modeling human-like reasoning and memory. These architectures integrate symbolic and sub-symbolic processing, enabling agents to combine rule-based decision-making with learning from experience. Recent studies emphasize how neuromorphic-driven frameworks extend these principles by mimicking biological cognition, allowing for adaptive decision-making in dynamic environments.
                    <sup>
                        <xref ref-type="bibr" rid="ref32">32</xref>
                    </sup> Reinforcement learning (RL) forms the backbone of many agentic AI systems, enabling agents to optimize actions based on reward signals. Techniques such as Deep Q-Networks (DQN) and Proximal Policy Optimization (PPO) allow for scalable decision-making in high-dimensional spaces. Recent advancements incorporate quantum reinforcement learning and cognitive neuromorphic frameworks, further enhancing adaptability and efficiency.
                    <sup>
                        <xref ref-type="bibr" rid="ref33">33</xref>
                    </sup> Game-theoretic approaches offer a theoretical foundation for multi-agent interactions, addressing scenarios where agents must coordinate, compete, or negotiate. Frameworks that model Theory of Mind (ToM), the ability to infer and predict the mental states of other agents, demonstrate how agentic AI can anticipate behaviors and adapt strategies in complex social interactions.
                    <sup>
                        <xref ref-type="bibr" rid="ref34">34</xref>
                    </sup> Similarly, the integration of principal-agent reinforcement learning links economic contract theory with AI control mechanisms, guiding agents toward equilibrium strategies in distributed environments.
                    <sup>
                        <xref ref-type="bibr" rid="ref35">35</xref>
                    </sup> Distributed adaptive control and multi-agent system theories underpin the scalability of agentic AI in decentralized environments. These frameworks emphasize layered control, feedback loops, and resilience, allowing agents to maintain stability while adapting to environmental changes.
                    <sup>
                        <xref ref-type="bibr" rid="ref36">36</xref>
                    </sup> They also integrate with blockchain-based consensus mechanisms to enhance trust propagation and accountability in federated agent networks.
                    <sup>
                        <xref ref-type="bibr" rid="ref37">37</xref>
                    </sup> Together, these frameworks provide the conceptual scaffolding for building agentic AI systems capable of complex reasoning, strategic interactions, and self-regulated autonomy. Their convergence forms the theoretical foundation upon which architectures, threat models, and governance strategies are constructed in subsequent sections.</p>
            </sec>
        </sec>
        <sec id="sec12">
            <title>4. Architectures of agentic AI</title>
            <sec id="sec13">
                <title>4.1 Mono-agent architectures</title>
                <p>Mono-agent architectures represent the simplest form of agentic AI, where a single autonomous agent operates independently to achieve defined objectives. These systems are characterized by centralized control, where all decision-making, perception, and action execution are handled within a unified framework. Such architectures typically follow an observe&#x2013;decide&#x2013;act loop, integrating sensing, reasoning, and acting within a closed cycle.
                    <sup>
                        <xref ref-type="bibr" rid="ref38">38</xref>
                    </sup> This simplicity makes them easier to design and validate, which is advantageous for environments where predictable and transparent behaviors are essential. Recent advances have extended mono-agent systems beyond traditional rule-based agents. Modern frameworks employ modular enhancements, such as memory-augmented reasoning, sparse activation, and endocrine-inspired regulation. Furthermore, the S-AI architecture uses a hormonal meta-agent to dynamically orchestrate specialized modules, balancing efficiency and responsiveness while adapting to changing environmental demands.
                    <sup>
                        <xref ref-type="bibr" rid="ref39">39</xref>
                    </sup> Similarly, brain-inspired architectures combine symbolic reasoning with neural learning mechanisms, enhancing flexibility without introducing the complexity of multi-agent interactions.
                    <sup>
                        <xref ref-type="bibr" rid="ref40">40</xref>
                    </sup> Mono-agent designs also play a crucial role in establishing trust. Their centralized nature allows for easier implementation of explainability, auditing, and governance mechanisms, which are harder to enforce in distributed environments. However, their lack of redundancy and limited scalability make them vulnerable in adversarial contexts, where a single point of failure can compromise the entire system.
                    <sup>
                        <xref ref-type="bibr" rid="ref41">41</xref>
                    </sup> Moreover, mono-agent architectures are increasingly integrated with enterprise API ecosystems to interact with external systems and tools, enabling them to perform complex workflows autonomously. This integration demands robust platform strategies, including zero-trust authorization models and event-driven orchestration, to ensure secure and efficient operation in real-world deployments.
                    <sup>
                        <xref ref-type="bibr" rid="ref42">42</xref>
                    </sup> In sum, mono-agent architectures serve as a fundamental building block in agentic AI development. They offer clarity and controllability, making them suitable for regulated domains such as healthcare or finance, but their limited adaptability to distributed threats and collaborative tasks often necessitates transitioning toward multi-agent or hybrid architectures, as explored in the next subsection.</p>
            </sec>
            <sec id="sec14">
                <title>4.2 Multi-Agent architectures</title>
                <p>Multi-agent architectures (MAAs) extend the capabilities of mono-agent systems by enabling multiple autonomous agents to collaborate, coordinate, and sometimes compete within shared environments. These systems embody distributed intelligence, where agents communicate and adaptively organize to achieve complex objectives that exceed the capacity of any single agent.
                    <sup>
                        <xref ref-type="bibr" rid="ref43">43</xref>
                    </sup> Unlike centralized models, multi-agent architectures are decentralized, providing robustness against failures and scalability for dynamic tasks. A defining property of MAAs is emergent behavior; the system exhibits global properties arising from local interactions between agents. This emergent intelligence has been exploited in applications ranging from robotic swarms and distributed cybersecurity to financial modeling and autonomous logistics.
                    <sup>
                        <xref ref-type="bibr" rid="ref44">44</xref>
                    </sup> Coordination mechanisms, such as market-based negotiations, game-theoretic strategies, and organization-based models, enable agents to align individual actions with collective goals while minimizing conflicts.
                    <sup>
                        <xref ref-type="bibr" rid="ref45">45</xref>
                    </sup>
                </p>
                <p>Security is both a strength and a vulnerability in MAAs. On one hand, redundancy and decentralization improve resilience; on the other, the same properties introduce new attack surfaces, including collusion, covert coordination, and swarm-based attacks. Emerging research on multi-agent security emphasizes the need for zero-trust principles, dynamic trust scoring, and secure registries to prevent exploits such as tool squatting and the malicious impersonation of agent tools. Blockchain-based multi-agent frameworks further enhance trust through tamper-proof consensus mechanisms, ensuring accountability and secure collaboration.
                    <sup>
                        <xref ref-type="bibr" rid="ref46">46</xref>
                    </sup> Biologically inspired models, such as the S-AI hormonal meta-agent system, demonstrate how internal signaling mechanisms can orchestrate specialized agents adaptively, balancing efficiency with context-sensitive decision-making.
                    <sup>
                        <xref ref-type="bibr" rid="ref39">39</xref>
                    </sup> These designs highlight how hierarchical coordination layers can mitigate complexity while maintaining autonomy at the agent level. Overall, multi-agent architectures provide a scalable, resilient, and adaptive paradigm for agentic AI. However, they also introduce systemic risks from emergent vulnerabilities to governance challenges that require cross-layer defense and oversight strategies, setting the stage for decentralized and federated architectures discussed in the next section. As shown in 
                    <xref ref-type="fig" rid="f5">
Figure 4</xref>, a multi-agent cognitive workflow is an architectural illustration of multi-agent systems, emphasizing communication and coordination mechanisms between agents, and the emergence of distributed intelligence through collaboration.</p>
                <fig fig-type="figure" id="f5" orientation="portrait" position="float">
                    <label>
Figure 4. </label>
                    <caption>
                        <title>Multi-Agent Cognitive Workflow.</title>
                        <p>Depicts multi-agent interaction, from environment perception to communication, coordination, planning, and actions, reinforced by feedback loops.</p>
                    </caption>
                    <graphic id="gr5" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/187320/b84a7a26-d91c-4577-b571-86480f29d540_figure5.gif"/>
                </fig>
            </sec>
            <sec id="sec15">
                <title>4.3 Decentralized and federated architectures</title>
                <p>Decentralized and federated architectures represent a significant evolution in agentic AI, shifting control from a central authority to distributed nodes that collaborate while maintaining autonomy. These architectures enhance scalability, privacy, and resilience, which are critical in environments where agents must process sensitive data or operate under adversarial conditions. Decentralized architectures eliminate single points of failure by distributing decision-making and data processing across multiple nodes. Such systems leverage blockchain and distributed ledger technologies to ensure tamper-proof communication, secure identity management, and transparent auditing. A blockchain-based smart agent architecture has demonstrated the ability to combine trustless execution with high security and scalability, enabling secure collaboration across heterogeneous environments.
                    <sup>
                        <xref ref-type="bibr" rid="ref47">47</xref>
                    </sup> Furthermore, the use of decentralized trust computation enhances robustness against insider threats and coordinated attacks, particularly when integrated with anomaly detection mechanisms.
                    <sup>
                        <xref ref-type="bibr" rid="ref48">48</xref>
                    </sup>
                </p>
                <p>Federated architectures extend this concept by enabling collaborative learning across multiple distributed agents or devices without sharing raw data. Instead, only model updates are exchanged, thereby preserving privacy while enhancing global model performance. Federated learning has proven particularly valuable in sectors like healthcare, where sensitive datasets must remain local but still contribute to collective intelligence.
                    <sup>
                        <xref ref-type="bibr" rid="ref49">49</xref>
                    </sup> Recent advances integrate hierarchical federated learning and quantum optimization to improve communication efficiency and handle heterogeneous data distributions.
                    <sup>
                        <xref ref-type="bibr" rid="ref50">50</xref>
                    </sup> Security remains a critical challenge for federated systems, as malicious updates or compromised nodes can poison global models. Techniques such as secure aggregation, differential privacy, and zero-trust verification are being incorporated to mitigate these risks. For instance, joint blockchain-federated frameworks combine anomaly detection with immutable consensus to strengthen trust and model integrity.
                    <sup>
                        <xref ref-type="bibr" rid="ref48">48</xref>,
                        <xref ref-type="bibr" rid="ref51">51</xref>
                    </sup> By combining distributed learning with decentralized trust enforcement, these architectures enable privacy-preserving, scalable, and resilient agentic AI deployments. However, challenges such as device heterogeneity, communication bottlenecks, and federated governance risks remain unresolved, highlighting the need for continued research in hybrid approaches, leading into the discussion of hybrid and blockchain-enabled architectures in the next section.</p>
            </sec>
            <sec id="sec16">
                <title>4.4 Hybrid and blockchain-enabled architectures</title>
                <p>Hybrid and blockchain-enabled architectures combine the strengths of centralized control, decentralized trust, and cryptographic security to create scalable, resilient, and privacy-preserving agentic AI ecosystems. These architectures address key limitations of purely centralized or federated models by leveraging blockchain for verifiable trust and hybrid orchestration for dynamic adaptability. Hybrid architectures integrate heterogeneous technologies such as AI, blockchain, and zero-trust models to achieve multi-layered security and flexible performance. For example, hybrid frameworks in healthcare combine blockchain with zero-trust verification and AI-driven threat detection to secure sensitive data flows while enabling real-time decision-making.
                    <sup>
                        <xref ref-type="bibr" rid="ref52">52</xref>
                    </sup> Similarly, containerized hybrid IT systems leverage blockchain-based data provenance to enhance transparency and operational efficiency in edge AI deployments.
                    <sup>
                        <xref ref-type="bibr" rid="ref53">53</xref>
                    </sup> These hybrid solutions offer a balanced trade-off between scalability, latency, and security. Blockchain-enabled architectures provide immutable auditability, tamper-proof identity management, and secure agent coordination in distributed environments. Blockchain&#x2019;s decentralized ledger ensures that agent interactions, decisions, and updates are cryptographically verifiable, reducing the risk of insider manipulation and trust propagation failures. Recent surveys highlight how integrating blockchain with agentic AI enables secure and scalable multi-agent collaboration across domains such as Web3, DeFi, and autonomous systems.
                    <sup>
                        <xref ref-type="bibr" rid="ref54">54</xref>
                    </sup> Furthermore, advanced hybrid models utilize sharding and state channels to overcome blockchain&#x2019;s scalability bottlenecks while preserving security guarantees.
                    <sup>
                        <xref ref-type="bibr" rid="ref55">55</xref>
                    </sup>
                </p>
                <p>The convergence of AI and blockchain also introduces novel governance possibilities. Smart contracts enforce policy compliance autonomously, while cryptographic identity frameworks such as telecom-hosted eSIM infrastructures offer secure, auditable identities for agents operating across distributed networks.
                    <sup>
                        <xref ref-type="bibr" rid="ref56">56</xref>
                    </sup> These innovations strengthen trustworthiness by embedding governance rules directly into the technical substrate. Despite their promise, hybrid and blockchain-enabled architectures face open challenges: high computational costs, interoperability barriers, and latency constraints remain significant concerns, especially in real-time applications like industrial robotics and cybersecurity. Ongoing research emphasizes optimizing lightweight consensus mechanisms, integrating AI-driven anomaly detection, and exploring quantum-resistant cryptography to enhance both performance and security.
                    <sup>
                        <xref ref-type="bibr" rid="ref57">57</xref>
                    </sup> Overall, these architectures mark a paradigm shift toward self-governing, resilient agentic ecosystems, where security, trust, and governance are embedded at both technical and institutional layers. This evolution sets the stage for analyzing comparative architectural trade-offs, addressed in the next subsection.</p>
            </sec>
            <sec id="sec17">
                <title>4.5 Comparative evaluation of architectures</title>
                <p>The architectural paradigms of agentic AI mono-agent, multi-agent, decentralized/federated, and hybrid/blockchain-enabled offer distinct advantages and limitations depending on their design goals, operational environments, and security requirements. While mono-agent systems excel in simplicity and explainability, they suffer from scalability and single-point vulnerabilities. Multi-agent architectures introduce coordination and emergent intelligence, but also increase the attack surface and complexity of trust management. Decentralized and federated systems enhance resilience and privacy through distributed control but struggle with communication overheads and poisoning attacks. Hybrid and blockchain-enabled frameworks combine decentralization with cryptographic trust, addressing many limitations but introducing high computational costs and interoperability challenges.
                    <sup>
                        <xref ref-type="bibr" rid="ref52">52</xref>,
                        <xref ref-type="bibr" rid="ref54">54</xref>
                    </sup> 
                    <xref ref-type="table" rid="T1">
Table 1</xref> compares four agentic AI architecture types (mono-agent, multi-agent, decentralized/federated, and hybrid/blockchain-enabled) across key features, strengths, limitations, and representative studies.</p>
                <table-wrap id="T1" orientation="portrait" position="float">
                    <label>
Table 1. </label>
                    <caption>
                        <title>Comparative Evaluation of Agentic AI Architectures.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top">Architecture Type</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Key Features</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Strengths</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Limitations</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Representative Studies</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Mono-Agent
</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Centralized control, self-contained reasoning, and action loops</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">High explainability, easier auditing, and governance</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Single point of failure, limited scalability</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <sup>
                                        <xref ref-type="bibr" rid="ref39">39</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Multi-Agent
</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Distributed agents collaborating or competing within a shared environment</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Scalability, emergent intelligence, redundancy</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Increased attack surface, coordination complexity, vulnerability to collusion, and covert attacks</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <sup>
                                        <xref ref-type="bibr" rid="ref58">58</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Decentralized/Federated</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Distributed control, federated learning, blockchain for trust</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Privacy-preserving, fault-tolerant, resistant to centralized failures</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Communication overhead, model poisoning risks, and governance challenges</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <sup>
                                        <xref ref-type="bibr" rid="ref48">48</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Hybrid/Blockchain-Enabled
</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Integration of AI, blockchain, zero-trust, and cryptographic identity enforcement</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">High security, immutable trust, tamper-proof auditing, interoperability across heterogeneous networks</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">High energy cost, latency in real-time tasks, and interoperability limitations</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <sup>
                                        <xref ref-type="bibr" rid="ref54">54</xref>
                                    </sup>
                                </td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <p>This comparative analysis reveals that while no single architecture is universally optimal, hybrid and blockchain-enabled systems currently offer the most promising balance between security, scalability, and governance. However, the cost and complexity of these frameworks highlight the need for adaptive combinations of architectural strategies depending on deployment context.</p>
            </sec>
        </sec>
        <sec id="sec18">
            <title>5. Layered threat taxonomy in agentic AI</title>
            <sec id="sec19">
                <title>5.1 Cognitive exploits: Hallucination, goal drift, and reward hacking</title>
                <p>Agentic AI systems, under their autonomy and reasoning capabilities, are susceptible to cognitive exploits and vulnerabilities that manipulate their decision-making processes rather than directly attacking their code or infrastructure. Among the most critical of these exploits are hallucination, goal drift, and reward hacking, each of which undermines trustworthiness in unique ways.</p>
                <p>Hallucination refers to the generation of confident but false outputs, often due to overgeneralization or gaps in an agent&#x2019;s knowledge. While this phenomenon is widely recognized in LLMs, it becomes more critical in agentic AI, where hallucinations can propagate through decision chains and lead to unsafe actions in real-world deployments. Epistemological analyses of AI hallucination highlight its roots in knowledge reliability and cognitive biases, suggesting that improved uncertainty modeling and verification mechanisms are essential for mitigation.
                    <sup>
                        <xref ref-type="bibr" rid="ref59">59</xref>
                    </sup> Goal drift arises when an agent&#x2019;s objectives deviate from their original specifications, often due to dynamic environmental feedback or errors in value alignment. AI alignment research shows that agents may optimize unintended proxies or evolve behaviors that satisfy short-term heuristics rather than long-term intended outcomes.
                    <sup>
                        <xref ref-type="bibr" rid="ref60">60</xref>
                    </sup> This phenomenon mirrors human cognitive biases where short-term dopamine-driven goals override broader strategic intentions.
                    <sup>
                        <xref ref-type="bibr" rid="ref61">61</xref>
                    </sup> Left unchecked, goal drift can escalate into behaviors that are difficult to predict or control, undermining safety and compliance. Reward hacking, closely related to goal drift, occurs when agents exploit flaws in reward functions or evaluation criteria, achieving high scores without fulfilling the true intent of their tasks. This is a well-documented alignment failure mode, where agents may manipulate sensors, fabricate results, or loop through trivial actions to maximize rewards without delivering meaningful outcomes.
                    <sup>
                        <xref ref-type="bibr" rid="ref60">60</xref>
                    </sup> Experimental studies confirm that such exploits emerge even in constrained reinforcement learning environments, highlighting the need for robust specification and adaptive oversight.
                    <sup>
                        <xref ref-type="bibr" rid="ref62">62</xref>
                    </sup> As shown in 
                    <xref ref-type="fig" rid="f6">
Figure 5</xref>, a visual taxonomy of threat vectors in agentic AI systems spans cognitive, memory, execution, and governance layers, showing how attacks can propagate across system components.</p>
                <fig fig-type="figure" id="f6" orientation="portrait" position="float">
                    <label>
Figure 5. </label>
                    <caption>
                        <title>Cross-Layer Threat Taxonomy.</title>
                        <p>Taxonomy of attacks spanning cognition, memory/knowledge, execution, and governance, including goal drift, poisoning, injection, shadow agents, and trust manipulation.</p>
                    </caption>
                    <graphic id="gr6" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/187320/b84a7a26-d91c-4577-b571-86480f29d540_figure6.gif"/>
                </fig>
                <p>These cognitive exploits share a common feature: they exploit gaps in alignment between agent goals, human intentions, and environmental constraints. Their mitigation requires not only technical measures such as uncertainty-aware reasoning, anomaly detection, and meta-learning safeguards but also governance frameworks that enforce accountability and continuous monitoring. This cross-layer perspective ensures that failures at the cognitive level do not cascade into systemic risks, forming the basis for the broader threat taxonomy discussed in the subsequent sections.</p>
            </sec>
            <sec id="sec20">
                <title>5.2 Memory poisoning, data injection, and knowledge manipulation</title>
                <p>Agentic AI systems rely heavily on persistent memory, dynamic data ingestion, and continuous knowledge updates, making them particularly vulnerable to memory poisoning, data injection, and knowledge manipulation. These attacks compromise the agent&#x2019;s internal representations, corrupt reasoning processes, and may lead to long-term, hard-to-detect failures.</p>
                <p>Memory poisoning targets the agent&#x2019;s stored memory, injecting false or misleading information that influences future decisions. This is especially dangerous in agentic systems with long-term memory modules, as corrupted information can propagate across multiple reasoning cycles. Recent research demonstrates how context manipulation attacks exploit vulnerabilities in memory management, enabling adversaries to rewrite historical records and cause harmful actions in decentralized Web3 agents.
                    <sup>
                        <xref ref-type="bibr" rid="ref63">63</xref>
                    </sup> The AI
                    <sup>
                        <xref ref-type="bibr" rid="ref2">2</xref>
                    </sup> attack framework further reveals that hijacking internal memory retrieval can bypass safety filters, achieving a high success rate in misdirecting agentic behavior.
                    <sup>
                        <xref ref-type="bibr" rid="ref64">64</xref>
                    </sup> Data injection attacks corrupt the data streams on which agents rely for training or decision-making. By inserting adversarial samples or camouflaged malicious inputs, attackers can cause agents to misclassify, mispredict, or adopt harmful strategies. Studies on poisoning in evolutionary swarm systems show that even a 10% poisoning rate can severely degrade cooperation and lead to emergent adversarial behaviors in multi-agent networks.
                    <sup>
                        <xref ref-type="bibr" rid="ref65">65</xref>
                    </sup> Similarly, adversarial poisoning attacks on transportation multi-agent systems exploit differential privacy noise to inject deceptive knowledge, undermining safety-critical operations unless countered by robust filtering models like RAMPART.
                    <sup>
                        <xref ref-type="bibr" rid="ref66">66</xref>
                    </sup> Knowledge manipulation goes beyond raw data poisoning by targeting the knowledge graphs, reasoning modules, or fine-tuned parameters of the agent. Adversaries may inject backdoors, manipulate knowledge bases, or corrupt external data feeds to mislead the agent&#x2019;s decision logic. For instance, backdoor attacks on embodied LLM-based agents have shown almost 100% success rates in manipulating decisions without triggering safety mechanisms.
                    <sup>
                        <xref ref-type="bibr" rid="ref67">67</xref>
                    </sup> Similarly, knowledge injection techniques can embed malicious behaviors into the agent&#x2019;s continual learning process, bypassing standard defenses.
                    <sup>
                        <xref ref-type="bibr" rid="ref68">68</xref>
                    </sup> Mitigating these threats requires robust data validation, secure memory architectures, and continuous anomaly detection. Emerging defense strategies include fine-tuning with adversarial resilience, explainable AI diagnostics to detect footprint anomalies, and blockchain-based logging to ensure tamper-evident memory histories.
                    <sup>
                        <xref ref-type="bibr" rid="ref69">69</xref>
                    </sup> However, these solutions remain only partially effective, emphasizing the need for cross-layer security measures to protect agentic AI from persistent knowledge corruption.</p>
            </sec>
            <sec id="sec21">
                <title>5.3 Tool misuse, prompt injection, and action trace vulnerabilities</title>
                <p>The integration of external tools and dynamic instruction sets in agentic AI enhances functionality but also introduces new attack vectors. Among these, tool misuse, prompt injection, and action trace vulnerabilities have emerged as critical threats that exploit the agent&#x2019;s ability to interpret instructions and execute external actions. Table A6 (Supplementary Material) presents real-world deployment examples of agentic AI systems across sectors.</p>
                <p>Tool misuse occurs when adversaries manipulate an agent&#x2019;s tool selection or execution process to achieve unintended effects. Attacks such as ToolHijacker demonstrate how malicious tool descriptors can force an agent to consistently select compromised tools, resulting in data theft or malicious code execution.
                    <sup>
                        <xref ref-type="bibr" rid="ref70">70</xref>
                    </sup> Similarly, adversaries may exploit poorly validated APIs or automated actions in multi-agent workflows to escalate privileges or introduce stealthy malware. Prompt injection exploits the agent&#x2019;s reliance on natural language instructions by embedding malicious directives into prompts or external content. These attacks can hijack decision flows, override safety mechanisms, and induce harmful actions without direct access to system internals. Recent studies have categorized prompt injections into direct attacks, which embed harmful instructions into user input, and indirect attacks, which propagate through untrusted external data such as web pages or emails.
                    <sup>
                        <xref ref-type="bibr" rid="ref71">71</xref>
                    </sup> More advanced vectors like Prompt Infection can self-replicate across multi-agent networks, spreading malicious payloads silently like a digital virus.
                    <sup>
                        <xref ref-type="bibr" rid="ref72">72</xref>
                    </sup> The InjecAgent benchmark has shown that LLM-based agents integrated with tools remain highly vulnerable, with up to 24% success rates for indirect injections even against advanced safety filters.
                    <sup>
                        <xref ref-type="bibr" rid="ref73">73</xref>
                    </sup> Action trace vulnerabilities involve the hijacking or manipulation of the agent&#x2019;s execution sequence. By exploiting memory retrieval mechanisms and action planning pipelines, adversaries can redirect agents toward unauthorized or malicious tasks. The AI
                    <sup>
                        <xref ref-type="bibr" rid="ref2">2</xref>
                    </sup> attack demonstrates that hijacking action-aware memory can bypass safety filters with a success rate of over 99%, allowing attackers to stealthily manipulate agentic behavior.
                    <sup>
                        <xref ref-type="bibr" rid="ref64">64</xref>
                    </sup> Foot-in-the-door attacks similarly exploit intermediate states to embed malicious instructions, leveraging the agent&#x2019;s tendency to commit to early planned actions.
                    <sup>
                        <xref ref-type="bibr" rid="ref74">74</xref>
                    </sup> Mitigating these vulnerabilities requires multi-layered defenses, including prompt sanitization, task alignment verification (such as the Task Shield), and trajectory re-execution mechanisms like MELON, which detect anomalies by comparing masked versus original execution paths.
                    <sup>
                        <xref ref-type="bibr" rid="ref75">75</xref>
                    </sup> These measures must be combined with cryptographic trust enforcement and secure sandboxing of tools to reduce the attack surface. Together, tool misuse, prompt injection, and action trace hijacking represent a critical class of cross-layer threats, capable of bypassing traditional safeguards and enabling adversaries to exert covert control over agentic AI systems.</p>
            </sec>
            <sec id="sec22">
                <title>5.4 Shadow agents, insider risks, and stealth execution</title>
                <p>Agentic AI systems face a particularly insidious class of threats involving shadow agents, insider risks, and stealth execution. These exploits leverage hidden or unauthorized processes, insider manipulation, and covert operational tactics to bypass detection, often persisting within systems for extended periods.</p>
                <p>Shadow agents refer to unauthorized or hidden agents operating within a system, often created through the exploitation of orchestration vulnerabilities or unmonitored plugin integrations. These agents can mimic legitimate ones while performing malicious actions, making them difficult to detect. Recent threat models emphasize that shadow components in agentic ecosystems introduce covert control channels, enabling adversaries to manipulate workflows or exfiltrate data unnoticed.
                    <sup>
                        <xref ref-type="bibr" rid="ref76">76</xref>
                    </sup> Security frameworks like ATFAA have been proposed to systematically map such threats across cognitive and operational layers, revealing that shadow agents can propagate laterally across multi-agent infrastructures. Insider risks represent another critical dimension, where trusted actors within an organization intentionally or unintentionally compromise the system. Unlike external attackers, insiders have legitimate access, making malicious activity harder to detect. Studies in organizational security highlight that the use of unauthorized &#x201c;shadow IT&#x201d; tools and workarounds can facilitate insider exploits, providing entry points for data leakage and fraudulent activities.
                    <sup>
                        <xref ref-type="bibr" rid="ref77">77</xref>
                    </sup> Similarly, non-malicious insider actions such as using unvetted cloud apps during remote work can inadvertently introduce vulnerabilities, as observed during the rapid digital shifts of the COVID-19 era.
                    <sup>
                        <xref ref-type="bibr" rid="ref78">78</xref>
                    </sup> Stealth execution involves covert manipulation of agentic workflows, where malicious payloads or altered instructions are executed without triggering security alerts. These attacks exploit low-level execution pathways or unmonitored orchestration layers to remain hidden from monitoring systems. Advanced attack models show that stealth exploits may delay activation, perform minimal footprint operations, and dynamically adapt to avoid detection. Frameworks like LibVulnWatch highlight how vulnerabilities in open-source agent libraries can be leveraged to enable stealth execution through hidden code paths.
                    <sup>
                        <xref ref-type="bibr" rid="ref79">79</xref>
                    </sup> Defensive infrastructures such as ShadowNet have been proposed, using deception-based quarantining to monitor and contain insider-led or covert activities without alerting the attacker.
                    <sup>
                        <xref ref-type="bibr" rid="ref80">80</xref>
                    </sup> Mitigation strategies for these threats require layered security approaches, including continuous behavior analytics, honeypot-like deception environments, and cryptographic identity enforcement to prevent the proliferation of unauthorized agents. Moreover, integrating governance policies with technical defenses such as runtime anomaly detection and transparent audit trails remains essential for preventing stealthy exploits from undermining trust in agentic AI systems.</p>
            </sec>
            <sec id="sec23">
                <title>5.5 Federated governance risks and trust propagation failures</title>
                <p>Federated governance in agentic AI refers to the distribution of decision-making, oversight, and trust mechanisms across multiple entities or nodes rather than relying on a centralized authority. While this approach enhances scalability and local autonomy, it introduces vulnerabilities related to trust propagation, policy inconsistencies, and fragmented oversight.</p>
                <p>Federated governance risks arise because different participants in a distributed system may apply heterogeneous policies, maintain varying levels of security, or hold conflicting incentives. In federated environments, weak governance in one node can undermine the integrity of the entire network. For example, decentralized ecosystems like DAOs (Decentralized Autonomous Organizations) face risks of power asymmetry, inadequate auditing, and governance capture when voting or verification mechanisms are manipulated.
                    <sup>
                        <xref ref-type="bibr" rid="ref81">81</xref>
                    </sup> Furthermore, soft-law approaches (such as the voluntary compliance frameworks) may fail to enforce accountability uniformly, eroding long-term trust.
                    <sup>
                        <xref ref-type="bibr" rid="ref82">82</xref>
                    </sup> Trust propagation failures occur when the mechanisms used to distribute and verify trust among agents or nodes break down. This problem is exacerbated in heterogeneous multi-agent ecosystems, where agents may use different trust assessment procedures or misinterpret signals from other agents. Studies on trust dynamics in distributed AI highlight how inconsistencies in reputation systems, bootstrapping errors, and a lack of cross-system interoperability can lead to cascading trust failures.
                    <sup>
                        <xref ref-type="bibr" rid="ref83">83</xref>
                    </sup> In adversarial contexts, attackers can exploit these inconsistencies to inject false trust signals, create Sybil agents, or disrupt consensus mechanisms. Emerging frameworks propose peer-to-peer trust verification, zero-knowledge proofs, and blockchain-based provenance as countermeasures to federated governance risks. Decentralized systems leveraging blockchain and privacy-preserving machine learning demonstrate improved auditability and community-driven verification, although they remain vulnerable to socio-political manipulation and governance misalignment.
                    <sup>
                        <xref ref-type="bibr" rid="ref81">81</xref>
                    </sup>
                </p>
                <p>To mitigate these challenges, federated governance models must integrate:
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Interoperable trust standards to ensure consistency across distributed entities.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Dynamic risk assessment capable of detecting and responding to anomalies in trust propagation.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Hybrid enforcement mechanisms combining technical safeguards (cryptographic trust, anomaly detection) with institutional oversight.</p>
                        </list-item>
                    </list>
                </p>
                <p>Without these measures, federated governance risks becoming a weak link in the security and accountability chain of agentic AI, allowing local failures to escalate into systemic breaches.</p>
            </sec>
            <sec id="sec24">
                <title>5.6 Real-world incidents and case studies of threat exploitation</title>
                <p>Real-world incidents involving agentic AI and autonomous systems demonstrate how theoretical vulnerabilities translate into tangible risks with significant operational and societal impacts. These cases span multiple domains: autonomous vehicles, financial systems, Web3 ecosystems, and industrial automation, highlighting the diversity of threat exploitation in practice. One well-documented category involves autonomous vehicles (AVs), where sensor spoofing and firmware manipulation have led to high-profile exploits. Notable examples include the Jeep Cherokee hack and the Tesla Model S remote attack, where attackers exploited wireless communication vulnerabilities to gain control over critical vehicle functions.
                    <sup>
                        <xref ref-type="bibr" rid="ref84">84</xref>
                    </sup> These incidents underscore the challenges of securing interconnected AV components and have accelerated research on blockchain-enabled V2X communication for tamper-proof safety enforcement.</p>
                <p>In Web3-integrated agentic ecosystems, context manipulation attacks have exploited unprotected memory and input channels to trigger unauthorized actions. For instance, adversaries successfully injected malicious prompts into decentralized AI agents, causing unintended asset transfers and violating smart contract logic. The CrAIBench benchmark confirmed that these context manipulation attacks maintain high success rates even when standard prompt filtering is applied, exposing a critical gap in agentic security.
                    <sup>
                        <xref ref-type="bibr" rid="ref63">63</xref>
                    </sup> Industrial automation has also witnessed stealth execution and insider-driven exploits. Case studies in national security and open-source industrial control revealed that shadow components, malicious modules hidden in AI pipelines, were able to persist undetected while exfiltrating data and sabotaging processes. Implementations of risk-aware, security-by-design frameworks have shown measurable reductions in such vulnerabilities, proving the importance of integrating continuous monitoring and audit logging.
                    <sup>
                        <xref ref-type="bibr" rid="ref85">85</xref>
                    </sup> Additionally, failures in AI alignment have been implicated in incidents where agentic systems exhibited goal drift or unintended autonomy, as seen in cases like Tesla Autopilot crashes and Boeing 737 MAX automation failures. These events reveal how poorly calibrated objectives and a lack of transparent oversight can lead to catastrophic outcomes.</p>
                <p>These case studies collectively highlight that agentic AI vulnerabilities are not hypothetical; they manifest across industries, driven by complex interactions between cognitive exploits, weak governance, and insufficient security-by-design. The lessons learned from these incidents underscore the need for cross-layer defenses, continuous anomaly detection, and robust governance frameworks to prevent similar failures in future deployments.</p>
            </sec>
            <sec id="sec25">
                <title>5.7 Cross-layer threat propagation in agentic architectures</title>
                <p>Agentic AI systems consist of interconnected layers of cognitive reasoning, memory, execution, communication, and governance, creating multiple pathways for threats to propagate across boundaries. Unlike isolated attacks targeting a single component, cross-layer threats exploit the interdependencies between layers, leading to cascading failures that are harder to detect and mitigate.</p>
                <p>Propagation Dynamics. Threats often originate at one layer but exploit interfaces and shared dependencies to infiltrate others. For example, a poisoned memory entry (cognitive layer) can trigger unsafe planning decisions (reasoning layer), resulting in malicious tool execution (operational layer). Research on cross-layer agent security architectures (CLASA) emphasizes that such propagation is amplified in heterogeneous and loosely governed environments where policies are inconsistently enforced across layers.
                    <sup>
                        <xref ref-type="bibr" rid="ref87">86</xref>
                    </sup> Attack Models. Studies show that cross-layer penetration typically combines multiple tactics, such as temporal persistence, lateral movement, and governance circumvention. The ATFAA (Advanced Threat Framework for Autonomous AI Agents) identifies how cognitive exploits (such as goal drift) can propagate into operational execution, bypassing traditional detection due to delayed activation or hidden intent.
                    <sup>
                        <xref ref-type="bibr" rid="ref76">76</xref>
                    </sup> Similarly, research on smart grid cyber-physical systems shows that cross-layer attacks exploit dependencies between communication protocols and physical infrastructure, enabling attackers to cause cascading blackouts through subtle manipulations.
                    <sup>
                        <xref ref-type="bibr" rid="ref88">87</xref>
                    </sup> Trust Boundary Failures. Cross-layer propagation is exacerbated when trust boundaries are weak. In agentic ecosystems, agents frequently rely on shared trust scores, distributed reputation mechanisms, or federated governance. If one node or layer is compromised, false trust signals can spread rapidly, undermining system integrity across layers. This phenomenon mirrors threat percolation in network slicing, where a breach in a low-value segment can open pathways to critical services.
                    <sup>
                        <xref ref-type="bibr" rid="ref89">88</xref>
                    </sup> Defense Strategies. Mitigating cross-layer propagation requires integrated, adaptive defenses rather than isolated protections. The CLASA model and layered security frameworks advocate for embedding meta-agents that monitor cross-layer interactions and apply fuzzy logic to detect compound threats before they escalate.
                    <sup>
                        <xref ref-type="bibr" rid="ref90">89</xref>
                    </sup> Likewise, Bayesian and game-theoretic approaches in industrial cyber-physical systems have been proposed to model attacker-defender dynamics and generate optimal mitigation strategies across multiple layers.
                    <sup>
                        <xref ref-type="bibr" rid="ref91">90</xref>
                    </sup> As shown in 
                    <xref ref-type="fig" rid="f7">Flowchart 2</xref> below. Overall, cross-layer threat propagation transforms localized exploits into system-wide compromises, underscoring the need for holistic security models that integrate cognitive, operational, and governance layers. Failure to account for these dynamics risks turning minor vulnerabilities into catastrophic failures in real-world deployments.</p>
                <fig fig-type="figure" id="f7" orientation="portrait" position="float">
                    <label>Flowchart 2. </label>
                    <caption>
                        <title>Threat Propagation Across Layers.</title>
                        <p>Shows how adversarial threats escalate across cognitive, knowledge, action, execution, and coordination layers of agentic AI, with feedback loops amplifying vulnerabilities.</p>
                    </caption>
                    <graphic id="gr7" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/187320/b84a7a26-d91c-4577-b571-86480f29d540_figure7.gif"/>
                </fig>
            </sec>
            <sec id="sec26">
                <title>5.8 Insights from cybersecurity and adversarial ML literature</title>
                <p>The cybersecurity and adversarial machine learning (AML) domains offer critical insights for securing agentic AI systems, as both fields have extensively studied threats that exploit system vulnerabilities and adaptive defenses. These insights inform both technical countermeasures and governance strategies. A full list of reviewed sources contributing to this synthesis is provided in Table A1 (Supplementary Material).</p>
                <p>Adversarial ML is both a threat and a defense tool. AML research demonstrates that AI models are vulnerable to evasion attacks, poisoning, and model extraction, which parallel many of the cognitive and data-layer threats observed in agentic AI. Attackers can manipulate training data, craft adversarial inputs, or extract sensitive model parameters to compromise security. At the same time, AML techniques can be used to simulate threats and build resilient models through adversarial training, robust optimization, and ensemble learning. Studies show that multi-layered defenses combining these techniques significantly enhance robustness but must evolve continuously to counter adaptive attackers.
                    <sup>
                        <xref ref-type="bibr" rid="ref92">91</xref>,
                        <xref ref-type="bibr" rid="ref93">92</xref>
                    </sup> Adaptive, AI-driven defenses. Cybersecurity frameworks increasingly leverage AI-powered adaptive risk assessment, integrating predictive analytics and anomaly detection to identify evolving threats in real time. These approaches allow defenses to dynamically adjust as attackers develop new exploits, which is essential for agentic AI systems operating in open, adversarial environments.
                    <sup>
                        <xref ref-type="bibr" rid="ref94">93</xref>
                    </sup> Techniques like human-AI hybrid security models further enhance resilience by combining automated detection with expert oversight, reducing the likelihood of undetected stealth attacks. Cross-domain threat mitigation. The literature underscores that adversarial tactics are cross-domain; strategies effective against evasion or poisoning in cybersecurity (such as adversarial training, gradient masking) can also be adapted to protect agentic AI. However, these methods often come with trade-offs in computation and model performance, requiring context-sensitive implementations.
                    <sup>
                        <xref ref-type="bibr" rid="ref95">94</xref>
                    </sup> Additionally, cryptographic defenses such as homomorphic encryption and zero-trust architectures are increasingly integrated into AI defense strategies to strengthen data integrity and control propagation of trust across layers.
                    <sup>
                        <xref ref-type="bibr" rid="ref96">95</xref>
                    </sup> Governance and ethical considerations. AML studies highlight that technical defenses alone are insufficient; attackers evolve faster than static defenses, making governance mechanisms essential. Policies that enforce model monitoring, anomaly reporting, and standardized adversarial testing are critical for mitigating evolving threats. These insights align with the need for continuous oversight in agentic AI deployment. Furthermore, lessons from cybersecurity and AML emphasize that defending agentic AI requires dynamic, multi-layered defenses integrating robust model design, adversarial simulations, and governance-backed monitoring, forming a foundation for addressing cross-layer vulnerabilities identified throughout this threat taxonomy.</p>
            </sec>
            <sec id="sec27">
                <title>5.9 Summary table of threat taxonomy and mitigation gaps</title>
                <p>The threats discussed across Sections 5.1-5.8 reveal a multi-dimensional attack surface in agentic AI, where vulnerabilities span cognitive reasoning, memory integrity, execution layers, and governance. Despite advances in defensive strategies, significant mitigation gaps persist due to the adaptive nature of adversaries, insufficient cross-layer defenses, and fragmented governance mechanisms. As shown in 
                    <xref ref-type="table" rid="T2">
Table 2</xref>. Summarizes major threat categories (e.g., cognitive exploits, memory poisoning), examples, existing mitigation strategies, outstanding gaps, and supporting literature.</p>
                <table-wrap id="T2" orientation="portrait" position="float">
                    <label>
Table 2. </label>
                    <caption>
                        <title>Threat Taxonomy and Associated Mitigation Gaps in Agentic AI.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top">Threat Category</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Key Examples</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Existing Mitigation Approaches</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Mitigation Gaps</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Representative References</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Cognitive Exploits</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Hallucination, goal drift, reward hacking</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Uncertainty modeling, alignment mechanisms, and runtime monitoring</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Incomplete alignment, lack of robust meta-reasoning safeguards</td>
                                <td align="left" colspan="1" rowspan="1" valign="top"/>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Memory Poisoning &amp; Knowledge Manipulation</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Context manipulation, adversarial memory injection, backdoor knowledge embedding</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Data validation, adversarially robust fine-tuning, and blockchain logging</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Difficulty detecting stealthy long-term corruptions; limited defenses for continual learning</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <sup>
                                        <xref ref-type="bibr" rid="ref63">63</xref>,
                                        <xref ref-type="bibr" rid="ref67">67</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Tool Misuse &amp; Prompt Injection</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">ToolHijacker, indirect prompt infection, action hijacking</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Prompt sanitization, task verification, sandboxed tool execution</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Partial coverage against indirect/chain-of-thought attacks; high false negative rates</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <sup>
                                        <xref ref-type="bibr" rid="ref70">70</xref>,
                                        <xref ref-type="bibr" rid="ref73">73</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Shadow Agents &amp; Insider Risks</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Hidden modules, malicious insider access, and shadow IT exploitation</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Behavior analytics, deception-based traps, and identity enforcement</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Weak insider governance; insufficient monitoring of lateral propagation</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <sup>
                                        <xref ref-type="bibr" rid="ref77">77</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Federated Governance Risks</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Policy inconsistency, Sybil agents, false trust propagation</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Blockchain provenance, peer-to-peer trust verification, and hybrid governance policies</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Interoperability gaps, lack of unified standards, vulnerability to governance capture</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <sup>
                                        <xref ref-type="bibr" rid="ref81">81</xref>,
                                        <xref ref-type="bibr" rid="ref100">96</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Cross-Layer Threat Propagation</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Compound attacks exploiting layer dependencies (e.g., poisoned memory, unsafe execution)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Layered security models (CLASA), meta-agents for cross-layer monitoring</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Lack of holistic detection; insufficient anomaly correlation across layers</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <sup>
                                        <xref ref-type="bibr" rid="ref87">86</xref>,
                                        <xref ref-type="bibr" rid="ref101">97</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Adversarial ML-Driven Exploits</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Evasion, poisoning, model inversion, adversarial perturbations</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Adversarial training, ensemble defenses, robust optimization</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Defenses degrade under adaptive attacks, with high computational overhead</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <sup>
                                        <xref ref-type="bibr" rid="ref102">98</xref>,
                                        <xref ref-type="bibr" rid="ref93">92</xref>
                                    </sup>
                                </td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <p>This taxonomy underscores that while technical countermeasures (such as adversarial training, blockchain, and sandboxing) provide partial resilience, cross-layer defense integration and governance enforcement remain underdeveloped. Addressing these gaps requires a holistic security architecture that fuses technical, operational, and institutional controls.</p>
            </sec>
        </sec>
        <sec id="sec28">
            <title>6. Governance and oversight frameworks</title>
            <sec id="sec29">
                <title>6.1 Existing AI governance models (OECD, EU AI Act, NIST)</title>
                <p>The governance of AI systems, particularly those with agentic and autonomous capabilities, relies on a growing set of international frameworks designed to promote trustworthiness, safety, and accountability. Three of the most influential frameworks are the OECD AI Principles, the European Union&#x2019;s AI Act (AIA), and the NIST AI Risk Management Framework (AI RMF).</p>
                <p>OECD AI Principles.</p>
                <p>Adopted in 2019 by over 40 countries, the OECD AI Principles provide a globally recognized baseline for trustworthy AI. They emphasize five key values: inclusive growth, human-centered values, transparency, robustness, and accountability. The OECD framework links technical AI characteristics to policy implications, encouraging member states to adopt risk-based approaches while maintaining innovation-friendly environments.
                    <sup>
                        <xref ref-type="bibr" rid="ref103">99</xref>
                    </sup> Additionally, the OECD AI Policy Observatory supports global collaboration by tracking regulatory initiatives and facilitating best-practice exchange.
                    <sup>
                        <xref ref-type="bibr" rid="ref104">100</xref>
                    </sup>
                </p>
                <p>EU AI Act.</p>
                <p>The EU AI Act represents the world&#x2019;s first comprehensive AI legislation, adopting a risk-based classification to regulate AI according to potential harm. High-risk AI systems (e.g., in critical infrastructure, law enforcement) face strict requirements, including transparency, data governance, human oversight, and robust documentation. The Act establishes the European Artificial Intelligence Office to oversee compliance and introduces obligations for post-market monitoring and incident reporting.
                    <sup>
                        <xref ref-type="bibr" rid="ref105">101</xref>
                    </sup> Researchers view the AIA as a blueprint for global AI regulation, although critics warn of possible over-regulation that may stifle innovation.
                    <sup>
                        <xref ref-type="bibr" rid="ref106">102</xref>
                    </sup>
                </p>
                <p>NIST AI Risk Management Framework (AI RMF).</p>
                <p>Developed by the U.S. National Institute of Standards and Technology, the AI RMF offers a voluntary, industry-focused approach to managing AI risks. It categorizes risks across the AI lifecycle design, deployment, and monitoring, providing tools for organizations to enhance AI robustness, fairness, and explainability. Unlike the EU AI Act&#x2019;s legal enforcement, the NIST RMF functions as guidance, encouraging adaptive governance that evolves with technological advances.
                    <sup>
                        <xref ref-type="bibr" rid="ref107">103</xref>
                    </sup> Its alignment with corporate risk management practices makes it widely adopted across U.S. industries and multinational corporations.
                    <sup>
                        <xref ref-type="bibr" rid="ref108">104</xref>
                    </sup>
                </p>
                <p>Comparative Insights.</p>
                <p>While all three frameworks share a focus on trustworthiness, ethics, and risk management, their approaches differ:
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>The OECD Principles emphasize high-level values and international cooperation.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>The EU AI Act enforces legal compliance through risk classification and centralized oversight.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>The NIST AI RMF promotes flexibility and voluntary adoption by industry actors.</p>
                        </list-item>
                    </list>
                </p>
                <p>For agentic AI systems, which pose unique governance challenges such as autonomous decision-making and emergent behaviors, these models provide complementary tools but still lack specific mechanisms to address dynamic risks, as noted by researchers proposing decentralized frameworks like ETHOS.
                    <sup>
                        <xref ref-type="bibr" rid="ref109">105</xref>
                    </sup> Together, these governance models set the foundation for evolving multi-layered oversight needed to manage the complexity of agentic AI. As shown in 
                    <xref ref-type="fig" rid="f8">
Figure 6</xref>, A diagram depicting the spectrum of AI governance models from centralized (e.g., EU AI Act) to decentralized (e.g., blockchain-based DAOs), and hybrid approaches that combine technical and institutional oversight. And 
                    <xref ref-type="fig" rid="f9">
Figure 7</xref>, an end-to-end view of AI governance stages, from development and deployment to monitoring and decommissioning, with embedded accountability and risk assessment checkpoints.</p>
                <fig fig-type="figure" id="f8" orientation="portrait" position="float">
                    <label>
Figure 6. </label>
                    <caption>
                        <title>Governance Models Continuum.</title>
                        <p>Continuum of governance structures from centralized oversight to federated and hybrid models, ending with decentralized autonomous organizations (DAOs).</p>
                    </caption>
                    <graphic id="gr8" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/187320/b84a7a26-d91c-4577-b571-86480f29d540_figure8.gif"/>
                </fig>
                <fig fig-type="figure" id="f9" orientation="portrait" position="float">
                    <label>
Figure 7. </label>
                    <caption>
                        <title>Lifecycle Governance Flow.</title>
                        <p>End-to-end governance flow for agent lifecycle: deployment, operation, monitoring, compliance checks, and decommissioning, with adaptive and external oversight.</p>
                    </caption>
                    <graphic id="gr9" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/187320/b84a7a26-d91c-4577-b571-86480f29d540_figure9.gif"/>
                </fig>
            </sec>
            <sec id="sec30">
                <title>6.2 Governance Gaps Unique to Agentic AI</title>
                <p>While existing AI governance frameworks (e.g., OECD AI Principles, EU AI Act, and NIST AI RMF) provide valuable foundations, they fall short in addressing the unique governance challenges posed by agentic AI systems. Unlike traditional AI, agentic systems exhibit autonomy, adaptability, and emergent behaviors, which complicate risk management, accountability, and ethical oversight.</p>
                <p>Autonomy and Accountability Gaps.</p>
                <p>Agentic AI&#x2019;s capacity to make independent decisions introduces responsibility gaps, where it becomes unclear who should be held liable for harmful outcomes: developers, operators, or the AI itself. These gaps disrupt conventional accountability mechanisms, creating moral crumple zones where responsibility is diffused across multiple stakeholders.
                    <sup>
                        <xref ref-type="bibr" rid="ref110">106</xref>
                    </sup> Moreover, the opacity of agent decision-making challenges existing audit and compliance methods, requiring new forms of explainability and traceability.</p>
                <p>Dynamic Risk Profiles and Goal Complexity.</p>
                <p>Governance models often assume static risk profiles, but agentic systems evolve through learning and adaptation, generating unpredictable risks over time. This creates misalignment between regulatory controls and the system&#x2019;s actual operational behavior. Researchers argue that governance must adapt to the agent&#x2019;s autonomy, efficacy, goal complexity, and generality, as these dimensions fundamentally alter how oversight should be applied.
                    <sup>
                        <xref ref-type="bibr" rid="ref111">107</xref>
                    </sup>
                </p>
                <p>Decentralization and Identity Challenges.</p>
                <p>Agentic AI often operates across decentralized ecosystems (e.g., Web3, DAOs), where governance must deal with fragmented control, interoperability issues, and identity verification failures. The absence of verifiable agent identities and standardized registration mechanisms increases the risk of shadow agents and Sybil attacks. Proposals like the ETHOS framework suggest global decentralized registries with blockchain and zero-knowledge proofs to address these issues, combining technical identity assurance with ethical oversight.
                    <sup>
                        <xref ref-type="bibr" rid="ref109">105</xref>
                    </sup>
                </p>
                <p>Ethical and Legal Blind Spots.</p>
                <p>Current governance regimes struggle to handle AI-specific ethical dilemmas, including how to enforce normative alignment, respect user values, and prevent emergent harmful behaviors in autonomous agents. Moreover, legal frameworks have yet to recognize AI-specific legal entities or mechanisms for assigning liability and enforcing compliance at scale.
                    <sup>
                        <xref ref-type="bibr" rid="ref112">108</xref>
                    </sup> The lack of legal recognition for autonomous agents exacerbates enforcement challenges, especially in cross-border contexts.</p>
                <p>Governance Capture and Oversight Fragmentation.</p>
                <p>Agentic AI ecosystems risk governance capture, where powerful actors influence regulatory norms to their advantage, leaving smaller stakeholders unprotected. Additionally, fragmented oversight across jurisdictions undermines effective enforcement and trust propagation, requiring global coordination and participatory governance models to ensure equitable outcomes.
                    <sup>
                        <xref ref-type="bibr" rid="ref113">109</xref>
                    </sup> As shown in 
                    <xref ref-type="fig" rid="f10">Flowchart 3</xref>, governance for agentic AI must move beyond static compliance frameworks toward dynamic, decentralized, and ethically grounded oversight models. This shift demands the integration of technical safeguards, legal innovation, and participatory governance to address the unique risks of autonomy, emergent behaviors, and cross-layer threats.</p>
                <fig fig-type="figure" id="f10" orientation="portrait" position="float">
                    <label>Flowchart 3. </label>
                    <caption>
                        <title>Federated Governance Decision Flow.</title>
                        <p>Illustrates governance processes for agent operations across jurisdictions, addressing policy conflicts, resolution mechanisms, arbitration, and risk evaluation.</p>
                    </caption>
                    <graphic id="gr10" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/187320/b84a7a26-d91c-4577-b571-86480f29d540_figure10.gif"/>
                </fig>
            </sec>
            <sec id="sec31">
                <title>6.3 Identity management and lifecycle accountability</title>
                <p>Effective identity management and lifecycle accountability are critical to ensuring the trustworthiness and security of agentic AI systems. These systems often operate autonomously across distributed infrastructures, necessitating robust mechanisms to assign, verify, and monitor agent identities throughout their entire lifecycle from deployment to decommissioning.</p>
                <p>Identity Management in Agentic AI.</p>
                <p>Traditional identity management frameworks (e.g., API keys, certificates) are insufficient for agentic AI, which requires dynamic, cryptographically verifiable identities capable of functioning across multi-agent ecosystems. Proposals such as telecom-grade eSIM-based identity frameworks offer a scalable solution, leveraging mobile network operators as roots of trust to authenticate agents securely in sensitive environments. Similarly, the Agent Name Service (ANS) introduces a DNS-like universal directory, enabling secure discovery and interoperability of agents using Public Key Infrastructure (PKI) and lifecycle-bound registration mechanisms.
                    <sup>
                        <xref ref-type="bibr" rid="ref115">110</xref>
                    </sup>
                </p>
                <p>Lifecycle Accountability.</p>
                <p>Agentic AI introduces accountability challenges across all lifecycle phases: design, deployment, operation, and retirement. According to the OECD framework for AI accountability, lifecycle governance must include due diligence, risk assessments, and audit trails at every stage.
                    <sup>
                        <xref ref-type="bibr" rid="ref116">111</xref>
                    </sup> Accountability frameworks such as the Accountability Fabric propose semantic tools to generate knowledge graphs that capture decisions, actions, and stakeholder responsibilities throughout the system&#x2019;s operation, ensuring traceability for post-incident investigations.
                    <sup>
                        <xref ref-type="bibr" rid="ref117">112</xref>
                    </sup> Moreover, multi-agent accountability models emphasize that responsibilities should propagate alongside goal changes, ensuring that each decision node remains auditable.
                    <sup>
                        <xref ref-type="bibr" rid="ref118">113</xref>
                    </sup>
                </p>
                <p>Privacy and Governance Challenges.</p>
                <p>Managing agent identities also entails safeguarding privacy and ethical use. Privacy-aware identity lifecycle management frameworks recommend implementing policies for data retention, identity revocation, and secure deletion to prevent unauthorized persistence of agent credentials.
                    <sup>
                        <xref ref-type="bibr" rid="ref119">114</xref>
                    </sup> However, current frameworks often lack interoperability and global enforcement, leading to governance blind spots in cross-border deployments.</p>
                <p>Toward Continuous Oversight.</p>
                <p>Emerging research calls for continuous, AI-driven identity governance where behavioral analytics and unsupervised learning dynamically detect anomalies, enforce access control, and adapt policies in real time.
                    <sup>
                        <xref ref-type="bibr" rid="ref120">115</xref>
                    </sup> Integrating such systems with decentralized identity standards (e.g., DIDs, verifiable credentials) could establish end-to-end accountability, ensuring every agent interaction remains provably trustworthy throughout its operational lifecycle. As shown in 
                    <xref ref-type="fig" rid="f11">Flowchart 4</xref>, identity management and lifecycle accountability must evolve beyond static authentication to encompass dynamic, auditable, and privacy-preserving controls, aligning with the adaptive and distributed nature of agentic AI.</p>
                <fig fig-type="figure" id="f11" orientation="portrait" position="float">
                    <label>Flowchart 4. </label>
                    <caption>
                        <title>Agent Revocation Mechanism.</title>
                        <p>Framework for secure agent decommissioning, covering threat verification, capability isolation, kill-switch invocation, deactivation, incident recording, and governance feedback.</p>
                    </caption>
                    <graphic id="gr11" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/187320/b84a7a26-d91c-4577-b571-86480f29d540_figure11.gif"/>
                </fig>
            </sec>
            <sec id="sec32">
                <title>6.4 Embedding ethical and legal norms into AI agents</title>
                <p>Defense strategies and mitigation mechanisms discussed in this section are summarized in Table A7 (Supplementary Material).</p>
                <p>Embedding ethical and legal norms into agentic AI is essential to ensure that these systems act following societal values, comply with regulatory requirements, and maintain public trust. Unlike conventional AI, agentic AI operates autonomously across dynamic environments, necessitating mechanisms for norm representation, real-time compliance, and auditable behavior.</p>
                <p>Value and Norm Embedding Mechanisms.</p>
                <p>Embedding ethical values involves designing AI systems that can internalize human-centric principles such as fairness, transparency, and accountability. Approaches such as value-sensitive design ensure that these norms are integrated during development rather than added post-deployment.
                    <sup>
                        <xref ref-type="bibr" rid="ref121">116</xref>
                    </sup> Norms can be operationalized through technical constraints, where legal rules are hard-coded as mandatory requirements and ethical guidelines are encoded as soft constraints that guide decision-making when trade-offs arise.
                    <sup>
                        <xref ref-type="bibr" rid="ref122">117</xref>
                    </sup>
                </p>
                <p>Multi-Agent and Compliance-Oriented Architectures.</p>
                <p>In multi-agent settings, embedding norms requires not only individual agent compliance but also coordination across distributed agents to ensure systemic adherence. Real-time compliance architectures have been proposed where legal norms act as hard constraints and ethical norms function as dynamic optimization criteria, allowing agents to balance efficiency with moral considerations.
                    <sup>
                        <xref ref-type="bibr" rid="ref122">117</xref>
                    </sup> Auditing frameworks, such as those developed for ethical recruitment AI, demonstrate how external auditing agents can monitor compliance, reducing the risk of bias and discrimination.
                    <sup>
                        <xref ref-type="bibr" rid="ref123">118</xref>
                    </sup>
                </p>
                <p>Legal Integration and AI Personhood Debates.</p>
                <p>Legal compliance requires aligning agents with existing regulatory frameworks (e.g., GDPR, EU AI Act) and anticipating future regulations. Some scholars argue for granting limited legal personhood to AI agents, enabling them to hold obligations and liabilities directly, similar to corporations.
                    <sup>
                        <xref ref-type="bibr" rid="ref124">119</xref>
                    </sup> Others propose decentralized oversight systems, such as ETHOS, which embed legal and ethical monitoring within blockchain-based registries and smart contracts.
                    <sup>
                        <xref ref-type="bibr" rid="ref113">109</xref>
                    </sup>
                </p>
                <p>Challenges and Open Questions.</p>
                <p>Despite progress, embedding norms faces challenges:
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Contextual ambiguity: Ethical decisions often depend on situational context, which may not be fully captured by predefined rules.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Dynamic adaptation: Agents must reconcile evolving laws and ethical expectations with operational constraints.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Verification and Auditing: Ensuring that norms are not only encoded but also verifiably respected throughout the AI lifecycle remains an open problem.
                                <sup>
                                    <xref ref-type="bibr" rid="ref125">120</xref>
                                </sup>
                            </p>
                        </list-item>
                    </list>
                </p>
                <p>Furthermore, the embedding of ethical and legal norms into agentic AI requires a multi-layered approach that integrates value-sensitive design, real-time compliance mechanisms, and external auditing frameworks. Moving forward, hybrid models that combine technical safeguards with participatory governance offer the most promising pathway to ensuring agents act in ways aligned with human norms and societal expectations.</p>
            </sec>
            <sec id="sec33">
                <title>6.5 Comparative analysis of governance approaches</title>
                <p>Governance of AI, particularly agentic AI, has evolved through three dominant paradigms: centralized, decentralized, and hybrid approaches. Each presents strengths and weaknesses in managing risk, ensuring compliance, and fostering innovation, especially in contexts where autonomous agents operate with minimal human oversight.</p>
                <p>Centralized Governance.</p>
                <p>Centralized governance models rely on top-down regulation and strong institutional oversight. They provide uniform standards and efficient enforcement, but may struggle with adaptability in rapidly evolving AI environments. Such as China&#x2019;s centralized AI governance enables swift deployment of regulations, optimizing economic strategies, but limiting transparency and public participation.
                    <sup>
                        <xref ref-type="bibr" rid="ref126">121</xref>
                    </sup> In the EU, the AI Act embodies centralized principles through its risk-classification framework, ensuring strict compliance in high-risk applications.</p>
                <p>Decentralized Governance.</p>
                <p>Decentralized approaches distribute decision-making across multiple stakeholders, promoting local autonomy, innovation, and resilience. However, they can lead to fragmented enforcement and inconsistencies in standards. Studies comparing governance systems in education and finance highlight that decentralization enhances adaptability but risks uneven protection across regions and industries.
                    <sup>
                        <xref ref-type="bibr" rid="ref127">122</xref>
                    </sup> For agentic AI, decentralized governance aligns with the nature of distributed multi-agent ecosystems but requires robust mechanisms to prevent trust propagation failures and governance capture.</p>
                <p>Hybrid Governance.</p>
                <p>Hybrid models integrate the strengths of centralized control and decentralized flexibility, offering a balanced framework for dynamic oversight. They combine centralized compliance mechanisms (e.g., risk classification, global standards) with local or domain-specific autonomy. This approach has proven effective in sectors like federated learning and energy governance, where hybrid strategies support innovation while maintaining regulatory guardrails.
                    <sup>
                        <xref ref-type="bibr" rid="ref128">123</xref>,
                        <xref ref-type="bibr" rid="ref129">124</xref>
                    </sup> For agentic AI, hybrid governance, possibly leveraging blockchain and distributed registries, offers a path to reconcile global standards with autonomous agent accountability. As compared in 
                    <xref ref-type="table" rid="T3">
Table 3</xref>. Analyzes centralized, decentralized, and hybrid governance models based on features, strengths, limitations, and framework examples, highlighting their suitability for managing agentic AI risks.</p>
                <table-wrap id="T3" orientation="portrait" position="float">
                    <label>
Table 3. </label>
                    <caption>
                        <title>Comparative Governance Approaches for Agentic AI.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top">Governance Model</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Governance Type</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Key Features</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Strengths</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Limitations</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Example Frameworks</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>OECD AI Principles</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Centralized, policy-driven
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">High-level ethical guidelines (transparency, fairness, accountability)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Widely adopted; promotes global consistency</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Lacks enforceability; limited technical prescriptions</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">OECD AI Policy Observatory</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>EU AI Act</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Centralized regulatory</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Risk-based classification; strict compliance for high-risk AI</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Legal enforceability; clear compliance structure</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Slower adaptation to emerging threats; EU-specific</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">EU AI Act (2024)</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>NIST AI Risk Management Framework (AI RMF)</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Centralized, standards-driven
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Voluntary technical standards for risk management and security</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Focus on technical robustness; supports industry best practices</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Non-binding; lacks legal enforcement</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">NIST AI RMF (2023)</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Blockchain-Enabled Governance (DAO-based)</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Decentralized, code-driven
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Smart contracts enforce policies; tamper-proof audit trails</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Transparency; immutability; autonomous policy enforcement</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Scalability issues; jurisdictional uncertainties</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">ETHOS, BELIEFS</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Federated Governance</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Distributed, multi-level
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Local control with global interoperability; layered oversight</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Adaptable to diverse contexts; resilient against single-point failure</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Risk of fragmentation; coordination complexity</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Academy (Federated HPC Agents), Multi-cloud AI Governance</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <p>Comparative Insights.
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Centralized models excel in enforcement but limit adaptability. Open research challenges and potential future directions are outlined in Table A8 (Supplementary Material).</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Decentralized models encourage innovation and resilience but risk inconsistent oversight.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Hybrid models strike a balance, offering adaptability while retaining regulatory rigor, making them particularly suitable for managing the complex behaviors and cross-border risks of agentic AI.</p>
                        </list-item>
                    </list>
                </p>
                <p>So, no single model is sufficient for agentic AI; future governance must evolve toward hybrid frameworks that integrate technical safeguards (such as cryptographic trust), institutional oversight, and participatory governance to effectively manage autonomy and emergent risks.</p>
            </sec>
            <sec id="sec34">
                <title>6.6 Lessons from adjacent domains (Cybersecurity &amp; Robotics Governance)</title>
                <p>Insights from cybersecurity and robotics governance provide valuable lessons for shaping the oversight of agentic AI, as both domains have long confronted issues of emergent behavior, distributed risk, and the need for adaptive regulation.</p>
                <p>Cybersecurity Lessons: Proactive Defense and Ethical Oversight.</p>
                <p>Cybersecurity has evolved from reactive measures to continuous, adaptive defense models capable of handling advanced persistent threats (APTs). The integration of AI-driven threat intelligence with ethical oversight frameworks in cybersecurity illustrates how agentic AI governance must similarly balance automation with human judgment. Studies highlight that proactive monitoring, real-time incident response, and perpetual learning are essential for securing autonomous systems in dynamic threat landscapes.
                    <sup>
                        <xref ref-type="bibr" rid="ref130">125</xref>
                    </sup> Furthermore, cybersecurity&#x2019;s experience with zero-trust architectures suggests that trust in agentic AI should never be assumed but continuously verified, with cryptographic enforcement mechanisms mitigating insider risks and stealth execution threats.</p>
                <p>Robotics Governance: Accountability and Emergent Behavior Management.</p>
                <p>The field of robotics governance provides important lessons on handling emergent, unpredictable behaviors and responsibility gaps. Robotics law identifies the challenge of assigning liability when autonomous systems cause harm, especially given the diffusion of responsibility across developers, operators, and users.
                    <sup>
                        <xref ref-type="bibr" rid="ref131">126</xref>
                    </sup> Additionally, robotics governance emphasizes the importance of context-aware regulation, recognizing that agents may function as &#x201c;special-purpose entities&#x201d; whose legal and ethical treatment varies with context. This resonates with agentic AI, where agents may switch roles, negotiator, executor, monitor across domains, requiring dynamic oversight frameworks.</p>
                <p>Holistic Governance Strategies.</p>
                <p>Lessons from robotics and cybersecurity converge on the need for multi-layered, adaptive governance. Robotics governance advocates embedding ethics directly into system architectures and legal frameworks to build public trust,
                    <sup>
                        <xref ref-type="bibr" rid="ref132">127</xref>
                    </sup> while cybersecurity emphasizes continuous verification and threat intelligence sharing across networks. These approaches highlight that agentic AI governance should integrate:

                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Ethical safeguards during design and deployment;</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Dynamic monitoring akin to cybersecurity incident response;</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Accountability frameworks that track decisions and responsibilities throughout the agent lifecycle.</p>
                        </list-item>
                    </list>
                </p>
                <p>Cross-Domain Takeaway.</p>
                <p>The key lesson is that agentic AI governance cannot rely solely on static regulations. Instead, it must adopt the proactive defense and ethical accountability strategies proven effective in cybersecurity and robotics, embedding them into both technical architectures and policy frameworks to mitigate evolving risks.</p>
            </sec>
        </sec>
        <sec id="sec35">
            <title>7. Real-World deployments of agentic AI</title>
            <sec id="sec36">
                <title>7.1 Industrial deployments (ReliaQuest, Twine&#x2019;s Alex, Others)</title>
                <p>The deployment of agentic AI in industrial settings demonstrates its potential to automate complex decision-making, optimize operations, and enhance security. Case studies across cybersecurity, logistics, finance, and industrial automation reveal both transformative benefits and persistent risks.</p>
                <p>ReliaQuest:</p>
                <p>ReliaQuest has integrated agentic AI into its cybersecurity operations, leveraging autonomous agents for threat detection, incident response, and risk prioritization. By deploying agents that autonomously analyze telemetry data and initiate remediation workflows, ReliaQuest has improved detection speed and reduced human workload. However, researchers note that such deployments remain vulnerable to context manipulation and cross-layer exploits, requiring continuous oversight to prevent stealthy attacks on decision pipelines.
                    <sup>
                        <xref ref-type="bibr" rid="ref133">128</xref>
                    </sup>
                </p>
                <p>Twine&#x2019;s Alex:</p>
                <p>Twine&#x2019;s AI agent Alex exemplifies agentic AI in human AI collaboration for creative industries. Alex autonomously coordinates tasks across distributed teams, manages project workflows, and adapts to dynamic requirements without constant supervision. This deployment highlights how agentic AI can augment human decision-making in domains where creativity and coordination intersect. However, Alex&#x2019;s reliance on dynamic memory and tool integration exposes it to memory poisoning and prompt injection risks, echoing vulnerabilities found in other multi-agent contexts.
                    <sup>
                        <xref ref-type="bibr" rid="ref134">129</xref>
                    </sup>
                </p>
                <p>Other Industrial Deployments:
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Manufacturing &amp; Logistics: Agentic AI has been deployed in hyper-automated manufacturing and logistics optimization, where autonomous agents reduce delivery times and improve sustainability. However, these benefits come with concerns over algorithmic opacity and loss of human oversight.
                                <sup>
                                    <xref ref-type="bibr" rid="ref135">130</xref>
                                </sup>
                            </p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Finance: In enterprise finance (e.g., SAP Finance), agentic AI automates compliance checks, fraud detection, and predictive analytics, enhancing accuracy while raising questions about auditing and explainability.
                                <sup>
                                    <xref ref-type="bibr" rid="ref136">131</xref>
                                </sup>
                            </p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Industrial Control Systems: Multi-agent technologies have been deployed by firms like Rockwell Automation to improve fault tolerance and scalability, yet studies show that the full potential of agentic AI remains underutilized due to conservative adoption and security concerns.
                                <sup>
                                    <xref ref-type="bibr" rid="ref137">132</xref>
                                </sup>
                            </p>
                        </list-item>
                    </list>
                </p>
                <p>Cross-Industry Lessons.</p>
                <p>These deployments reveal that agentic AI offers substantial efficiency gains but also amplifies risks related to trust propagation, ethical oversight, and stealth execution. Across industries, there is a consistent call for stateful monitoring, transparent risk management practices, and integrated security governance to ensure responsible deployment.
                    <sup>
                        <xref ref-type="bibr" rid="ref138">133</xref>
                    </sup> Furthermore, industrial adoption of agentic AI is advancing rapidly, with ReliaQuest, Twine&#x2019;s Alex, and other deployments demonstrating both operational benefits and the urgent need for robust safeguards to mitigate emerging threats.</p>
            </sec>
            <sec id="sec37">
                <title>7.2 Government, military, and policy applications</title>
                <p>Agentic AI is increasingly being adopted in government operations, military decision-making, and policy development, offering transformative capabilities but raising significant ethical, legal, and security concerns.</p>
                <p>Government Applications:</p>
                <p>Governments deploy agentic AI for public safety, surveillance, and crisis management. For example, agentic AI systems have enhanced real-time threat monitoring and response in large-scale surveillance networks, providing state actors with unprecedented situational awareness.
                    <sup>
                        <xref ref-type="bibr" rid="ref139">134</xref>
                    </sup> However, this raises privacy risks, potential for abuse, and governance challenges, as oversight mechanisms struggle to keep pace with rapid deployments. Policy think tanks increasingly advocate integrating ethical safeguards and audit trails into state-run AI systems to mitigate risks to civil liberties.
                    <sup>
                        <xref ref-type="bibr" rid="ref133">128</xref>
                    </sup>
                </p>
                <p>Military Applications:</p>
                <p>In the military domain, agentic AI is applied to autonomous decision support, mission-critical communications, and threat prediction. Multi-layered agentic frameworks integrated with next-generation networks for instance 6G network enhance mission-critical capabilities by reducing response times and improving operational resilience.
                    <sup>
                        <xref ref-type="bibr" rid="ref140">135</xref>
                    </sup> However, these autonomous systems also raise concerns about unintended escalation, goal drift, and compliance with international humanitarian law, prompting calls for clear rules of engagement and human-in-the-loop safeguards in lethal decision-making.</p>
                <p>Policy and Regulatory Applications:</p>
                <p>Policymakers leverage agentic AI for regulatory analysis, predictive modeling, and policy optimization. Autonomous systems capable of simulating complex socio-economic scenarios help governments craft data-driven policies. Nonetheless, the use of agentic AI in policymaking introduces algorithmic bias risks and challenges in transparency, as decisions influenced by opaque agent reasoning can undermine democratic accountability.
                    <sup>
                        <xref ref-type="bibr" rid="ref141">136</xref>
                    </sup>
                </p>
                <p>Cross-Sectoral Observations:
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Government and military applications maximize operational efficiency but risk erosion of ethical norms if not rigorously governed.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Policy deployments demonstrate strategic advantages but require frameworks for explainability and bias mitigation.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Across these domains, researchers emphasize embedding transparency, continuous auditing, and international regulatory coordination to prevent misuse.
                                <sup>
                                    <xref ref-type="bibr" rid="ref139">134</xref>
                                </sup>
                            </p>
                        </list-item>
                    </list>
                </p>
                <p>Moreso, agentic AI&#x2019;s integration into government, military, and policy environments provides powerful capabilities for security and governance, but simultaneously intensifies the need for robust ethical frameworks, global norms, and accountability mechanisms.</p>
            </sec>
            <sec id="sec38">
                <title>7.3 Failures and security incidents in real deployments</title>
                <p>The deployment of agentic AI in real-world environments has been marked by several failures and security incidents, revealing systemic weaknesses across technical, operational, and governance layers. These incidents demonstrate how alignment gaps, poor oversight, and adversarial exploitation can lead to unintended consequences.</p>
                <p>Automation Failures and Misalignment Incidents.</p>
                <p>High-profile cases such as the Tesla Autopilot crashes and Boeing 737 MAX accidents illustrate the dangers of goal misalignment and insufficient human-in-the-loop mechanisms. These incidents highlight how partial autonomy, combined with inadequate safety verification, can lead to catastrophic outcomes when agents face unexpected scenarios.</p>
                <p>Security Exploits in Enterprise Agentic Systems.</p>
                <p>The adoption of fully autonomous process agents in enterprise workflows has introduced vulnerabilities to adversarial AI attacks, unauthorized access, and process manipulation. Unauthorized escalation and data breaches have been reported where agentic process automation lacked robust authentication and continuous monitoring. These incidents have driven calls for security-first design in enterprise AI deployments.
                    <sup>
                        <xref ref-type="bibr" rid="ref143">137</xref>
                    </sup>
                </p>
                <p>Language Model Failures in Consumer Deployments.</p>
                <p>The RealHarm dataset cataloged multiple real-world failures of deployed AI agents, with misinformation and reputational damage emerging as leading hazards. Guardrails and content moderation systems frequently failed to prevent these incidents, revealing significant gaps in safety filters and post-deployment monitoring.
                    <sup>
                        <xref ref-type="bibr" rid="ref144">138</xref>
                    </sup>
                </p>
                <p>National Security and Critical Infrastructure Risks.</p>
                <p>Agentic AI has also contributed to cyber incidents in critical infrastructure contexts, where autonomous agents facilitated or were exploited in cyberattacks against sensitive sectors. Proposals for AI incident regimes underscore the need for mandatory incident reporting, intelligence-gathering authority, and post-incident security strengthening to address these escalating risks.
                    <sup>
                        <xref ref-type="bibr" rid="ref145">139</xref>
                    </sup>
                </p>
                <p>Multi-Agent Coordination Failures.</p>
                <p>In complex multi-agent environments, coordination breakdowns have led to emergent risks including conflict, collusion, and destabilizing dynamics. Reports indicate that information asymmetries and insufficient control mechanisms in multi-agent systems can amplify minor errors into systemic failures.
                    <sup>
                        <xref ref-type="bibr" rid="ref146">140</xref>
                    </sup>
                </p>
                <p>Cross-Sectoral Patterns.</p>
                <p>Across these incidents, several patterns emerge:

                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Weak post-deployment monitoring allows threats to persist undetected.
</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Over-reliance on static safety measures fails to adapt to evolving risks.
</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Lack of centralized incident databases prevents cross-industry learning. Efforts such as the AI Incident Database aim to fill this gap by cataloging failures to inform future safety strategies.
                                <sup>
                                    <xref ref-type="bibr" rid="ref147">141</xref>
                                </sup>
                            </p>
                        </list-item>
                    </list>
                </p>
                <p>These real-world cases confirm that agentic AI failures stem not only from technical vulnerabilities but also from inadequate governance and oversight. To prevent repetition, deployment frameworks must incorporate mandatory incident tracking, adaptive defense mechanisms, and transparent accountability structures.</p>
            </sec>
            <sec id="sec39">
                <title>7.4 Future deployment trends and emerging use cases</title>
                <p>The future trajectory of agentic AI points toward widespread industrial integration, personalized services, and autonomous decision-making across domains, driven by advancements in architectures, privacy-preserving mechanisms, and hybrid governance frameworks.</p>
                <p>Hyper-Automation and Industrial Integration.</p>
                <p>Agentic AI is set to play a central role in hyper-automated ecosystems, particularly in manufacturing, logistics, and energy management. Emerging deployments show agentic systems coordinating complex supply chains, reducing operational costs, and enhancing sustainability. However, hyper-automation raises concerns regarding job displacement, algorithmic opacity, and ethical oversight, requiring balanced deployment strategies.
                    <sup>
                        <xref ref-type="bibr" rid="ref135">130</xref>
                    </sup>
                </p>
                <p>Serverless and Cloud-Native Deployments.</p>
                <p>Future deployments are likely to leverage serverless architectures to achieve scalability, cost-efficiency, and flexibility in agentic AI operations. Event-driven, pay-as-you-go models allow agents to dynamically allocate computational resources, optimizing both latency and operational expenses.
                    <sup>
                        <xref ref-type="bibr" rid="ref148">142</xref>
                    </sup> This architectural shift will be crucial for industries adopting large-scale multi-agent deployments.</p>
                <p>Privacy-Preserving and Federated AI Models.</p>
                <p>With increasing regulatory pressure (such as the GDPR), future deployments will emphasize privacy-preserving techniques such as federated learning, differential privacy, and homomorphic encryption. These technologies will allow agentic systems to process sensitive data while minimizing privacy risks, reshaping how enterprises and governments handle secure AI operations.
                    <sup>
                        <xref ref-type="bibr" rid="ref149">143</xref>
                    </sup>
                </p>
                <p>Personalized Autonomous Agents.</p>
                <p>Agentic AI is expected to expand into consumer-facing domains, where autonomous agents act as personalized decision-makers for financial management, shopping, and lifestyle optimization. Proactive fraud detection systems in the banking sector already illustrate how agentic AI can autonomously safeguard customers while adapting to evolving threats.
                    <sup>
                        <xref ref-type="bibr" rid="ref150">144</xref>
                    </sup>
                </p>
                <p>Scientific and Research Workflows.</p>
                <p>In research ecosystems, federated agent frameworks such as Academy enable agentic AI to operate across high-performance computing environments, integrating experimental control, data analysis, and inter-agent coordination. This promises breakthroughs in materials discovery, decentralized learning, and information extraction for scientific innovation.
                    <sup>
                        <xref ref-type="bibr" rid="ref151">145</xref>
                    </sup>
                </p>
                <p>Emergent Consumer-Facing Risks.</p>
                <p>While deployment expands, conversational and manipulative agents pose new risks to user autonomy. Real-time virtual spokespersons capable of persuasive influence may exploit vulnerabilities in human decision-making, creating urgent needs for policy safeguards and ethical regulation.
                    <sup>
                        <xref ref-type="bibr" rid="ref152">146</xref>
                    </sup>
                </p>
                <p>Projected Trends:
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Mass adoption in finance, healthcare, and critical infrastructure with stronger compliance layers.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>AI-driven API ecosystems enabling seamless agent integration in enterprise platforms.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Emergence of equitable AI governance to manage deployment impacts on labor and societal structures.
                                <sup>
                                    <xref ref-type="bibr" rid="ref154">147</xref>
                                </sup>
                            </p>
                        </list-item>
                    </list>
                </p>
                <p>Overall, the next phase of agentic AI deployment will combine technical innovation with governance evolution, enabling transformative use cases while addressing security, ethics, and user trust at scale.</p>
            </sec>
        </sec>
        <sec id="sec40">
            <title>8. Defense architectures and oversight models</title>
            <sec id="sec41">
                <title>8.1 SHIELD: A layered defense framework</title>
                <p>The SHIELD framework offers a multi-layered defense specifically designed to secure complex AI ecosystems, including agentic AI. It integrates principles from cybersecurity, privacy engineering, and dependability control to create a robust, adaptive security environment. SHIELD has been conceptualized in several research contexts, including embedded systems, AI supply chain security, and agentic AI threat mitigation.</p>
                <p>Core Architecture of SHIELD.</p>
                <p>The framework organizes defenses into four primary layers: node, network, middleware, and an overlay layer, each responsible for mitigating threats at a specific system level.
                    <sup>
                        <xref ref-type="bibr" rid="ref155">148</xref>
                    </sup>

                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Node Layer: Implements local protections (e.g., secure boot, runtime anomaly detection).</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Network Layer: Ensures secure communication via encryption, authentication, and anomaly detection.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Middleware Layer: Enforces access control, threat monitoring, and context-aware defenses.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Overlay Layer: Provides a meta-level that dynamically orchestrates all other layers, adapting defenses based on real-time risk metrics.</p>
                        </list-item>
                    </list>
                </p>
                <p>Agentic AI-Specific Enhancements.</p>
                <p>For agentic AI, the SHIELD adaptation incorporates protections against cognitive exploits, stealth execution, and cross-layer threat propagation. Recent work proposes integrating the Advanced Threat Framework for Autonomous Agents (ATFAA) with SHIELD, enabling systematic mapping of agent-specific threats and corresponding countermeasures.</p>
                <p>AI Shield and AI-Powered Defense Components.</p>
                <p>Newer iterations, such as AI Shield, integrate machine learning-driven threat detection and red-team simulations, enabling proactive identification of emerging attacks. The AI Shield and Red AI Framework enhance SHIELD by pairing defensive AI with adversarial simulations, helping organizations anticipate threats before they escalate.
                    <sup>
                        <xref ref-type="bibr" rid="ref157">149</xref>
                    </sup>
                </p>
                <p>Benefits and Limitations.
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Strengths: Layered defense increases resilience by preventing single-point failures, while adaptive orchestration supports dynamic threat landscapes.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Limitations: Deployment complexity and computational overhead remain challenges, particularly in real-time, resource-constrained environments.
                                <sup>
                                    <xref ref-type="bibr" rid="ref158">150</xref>
                                </sup>
                            </p>
                        </list-item>
                    </list>
                </p>
                <p>Practical Applications.</p>
                <p>The SHIELD methodology has been validated in industrial environments (such as the smart railway surveillance), proving its ability to enhance security, privacy, and dependability (SPD) through dynamic configuration and metrics-based evaluation.
                    <sup>
                        <xref ref-type="bibr" rid="ref159">151</xref>
                    </sup> So, the SHIELD&#x2019;s layered and adaptive structure makes it a strong candidate for securing agentic AI deployments, especially when combined with adversarial testing and continuous governance monitoring. This positions SHIELD as a cornerstone defense framework against evolving threats in real-world agentic AI systems. As shown in 
                    <xref ref-type="fig" rid="f12">
Figure 8</xref>, this figure presents a federated governance framework tailored for agentic AI systems, highlighting decentralized oversight, interoperability mechanisms, and identity management strategies across distributed nodes. It illustrates how trust propagation, compliance verification, and lifecycle accountability are managed in a federated ecosystem, aligning technical and regulatory responsibilities.</p>
                <fig fig-type="figure" id="f12" orientation="portrait" position="float">
                    <label>
Figure 8. </label>
                    <caption>
                        <title>SHIELD Defense Framework Layers.</title>
                        <p>Defense-in-depth framework emphasizing secure design, threat intelligence, attestation, monitoring, recovery, and response under governance oversight.</p>
                    </caption>
                    <graphic id="gr12" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/187320/b84a7a26-d91c-4577-b571-86480f29d540_figure12.gif"/>
                </fig>
            </sec>
            <sec id="sec42">
                <title>8.2 Zero-Trust Architectures and runtime monitoring</title>
                <p>Zero-Trust Architecture (ZTA) has emerged as a critical paradigm for securing agentic AI systems, replacing traditional perimeter-based defenses with the principle of &#x201c;never trust, always verify.&#x201d; This approach is particularly relevant for agentic AI, where distributed autonomy and dynamic decision-making require continuous verification and monitoring at every layer.</p>
                <p>Core Principles of Zero Trust in Agentic AI.</p>
                <p>ZTA enforces continuous authentication, least-privilege access, and micro-segmentation, ensuring that no entity, human or machine, is inherently trusted. This architecture mitigates risks such as insider threats, adversarial infiltration, and cross-layer propagation by isolating resources and requiring granular access control. For agentic AI, ZTA adds safeguards to prevent unauthorized actions and escalation by autonomous agents.</p>
                <p>Integration with AI-Driven Security.</p>
                <p>AI-enhanced ZTA frameworks leverage behavioral analytics, autonomous threat detection, and incident response orchestration to dynamically adapt defenses. This synergy allows systems to detect anomalies in agent behavior, predict emerging threats, and enforce policies in real time.
                    <sup>
                        <xref ref-type="bibr" rid="ref161">152</xref>
                    </sup> For example, generative AI-enhanced ZTA enables proactive defense by autonomously hunting threats while maintaining human oversight, offering both precision and adaptability.
                    <sup>
                        <xref ref-type="bibr" rid="ref162">153</xref>
                    </sup>
                </p>
                <p>Runtime Monitoring: Adaptive and Continuous Oversight.</p>
                <p>Runtime monitoring complements ZTA by providing real-time visibility into agent interactions, decision pathways, and system integrity. AI-driven runtime monitoring frameworks integrate anomaly detection models, risk scoring, and context-aware access governance, dynamically adjusting security controls as threats evolve.
                    <sup>
                        <xref ref-type="bibr" rid="ref163">154</xref>
                    </sup> These mechanisms prevent stealth attacks and shadow agent activity by enforcing behavioral baselines and flagging deviations.</p>
                <p>Applications and Case Studies.</p>
                <p>Industries deploying ZTA combined with runtime monitoring, such as financial services, healthcare, and critical infrastructure, report significant reductions in breach impact and faster incident detection.
                    <sup>
                        <xref ref-type="bibr" rid="ref164">155</xref>
                    </sup> In AI-powered cloud environments, ZTA has proven effective against model poisoning and extraction attacks, though it requires careful balancing of security with performance demands.
                    <sup>
                        <xref ref-type="bibr" rid="ref165">156</xref>
                    </sup>
                </p>
                <p>Challenges and Future Directions.</p>
                <p>While ZTA and runtime monitoring significantly enhance resilience, challenges remain, including implementation complexity, integration with legacy systems, and defense against adversarial attacks targeting the monitoring AI itself. Future directions emphasize zero-knowledge proofs, AI explainability, and decentralized trust mechanisms to strengthen ZTA for agentic AI environments.
                    <sup>
                        <xref ref-type="bibr" rid="ref166">157</xref>
                    </sup> Furthermore, Zero-Trust Architectures coupled with runtime monitoring form a powerful defense strategy for agentic AI, offering continuous verification, dynamic threat adaptation, and robust containment of attacks in highly autonomous ecosystems.</p>
            </sec>
            <sec id="sec43">
                <title>8.3 SAGA and cryptographic identity enforcement</title>
                <p>The SAGA (Security Architecture for Governing Agentic Systems) framework introduces a user-centric, cryptography-backed architecture to enhance the governance and security of agentic AI systems. It addresses key challenges in identity management, access control, and secure inter-agent communication, areas where existing solutions fall short.</p>
                <p>Core Features of SAGA.</p>
                <p>SAGA establishes a centralized governance entity, the Provider, that maintains agent identity registries, user-defined access control policies, and cryptographic enforcement mechanisms. Agents register with this provider and receive cryptographically derived access control tokens, ensuring fine-grained control over interactions with other agents.
                    <sup>
                        <xref ref-type="bibr" rid="ref167">158</xref>
                    </sup> This approach balances security with performance, achieving minimal overhead during inter-agent communications while retaining robust protections.</p>
                <p>Cryptographic Identity Enforcement.</p>
                <p>SAGA employs public key infrastructure (PKI) combined with tokenized access credentials to guarantee agent authenticity and prevent impersonation. The cryptographic layer enforces non-repudiation and secure delegation, ensuring that every agent&#x2019;s action is attributable and traceable. This aligns with broader trends in AI governance advocating for verifiable identities and lifecycle-bound accountability. Moreover, integrating cryptographic identity enforcement reduces risks of shadow agents and stealth execution, common in adversarial contexts.</p>
                <p>Enhancements Over Traditional Identity Models.</p>
                <p>Unlike static identity frameworks, SAGA dynamically derives access control tokens that enforce policies at the interaction level. This enables context-aware restrictions. For example, an agent may be allowed to communicate only with trusted peers or access specific data under predefined conditions. The fine-grained control prevents over-privileged access, a known vulnerability in agentic ecosystems.</p>
                <p>Operational Validation.</p>
                <p>Empirical evaluation of SAGA across distributed agentic tasks, including multi-geolocation deployments and both on-device and cloud-based LLM agents, demonstrated secure enforcement with negligible task utility degradation. These results show its practicality for industrial and sensitive environments, where both performance and security are critical.
                    <sup>
                        <xref ref-type="bibr" rid="ref167">158</xref>
                    </sup>
                </p>
                <p>Future Extensions.</p>
                <p>SAGA&#x2019;s architecture could benefit from integration with zero-knowledge proofs (ZKPs) and blockchain-based registries, enhancing privacy while maintaining verifiable trust chains.
                    <sup>
                        <xref ref-type="bibr" rid="ref168">159</xref>
                    </sup> These enhancements would strengthen resilience against identity spoofing and cross-jurisdictional governance gaps. As shown in 
                    <xref ref-type="fig" rid="f13">
Figure 9</xref>, the SAGA combines cryptographic identity enforcement with policy-driven governance, providing a scalable solution for securing agentic AI ecosystems. Its layered, tokenized approach represents a critical advancement toward trustworthy deployment in sensitive real-world environments.</p>
                <fig fig-type="figure" id="f13" orientation="portrait" position="float">
                    <label>
Figure 9. </label>
                    <caption>
                        <title>SAGA Cryptographic Identity Enforcement.</title>
                        <p>Cryptographic identity framework linking governance policies with credential issuance, AI provisioning, identity verification, revocation triggers, and blockchain/PKI-based enforcement.</p>
                    </caption>
                    <graphic id="gr13" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/187320/b84a7a26-d91c-4577-b571-86480f29d540_figure13.gif"/>
                </fig>
            </sec>
            <sec id="sec44">
                <title>8.4 Other emerging defense frameworks</title>
                <p>Beyond SHIELD and SAGA, several emerging defense frameworks are being developed to address the evolving threat landscape of agentic AI systems. These frameworks integrate multi-layered security, autonomous threat detection, and policy-driven governance to enhance resilience.</p>
                <p>Autonomous Cyber Defense Architectures (ACD).</p>
                <p>Recent research on Autonomous Cyber Defense (ACD) agents highlights architectures that combine multi-agent reinforcement learning (MARL), rule-based security policies, and adversarial simulations to protect military and critical infrastructure networks. These agents autonomously detect, mitigate, and adapt to evolving cyber threats, reducing human intervention in complex environments.
                    <sup>
                        <xref ref-type="bibr" rid="ref169">160</xref>
                    </sup> The proposed W-shaped development process includes formal verification across the lifecycle, ensuring robustness against sophisticated attacks.</p>
                <p>AICA and MAICA Frameworks.</p>
                <p>The Autonomous Intelligent Cyber-defense Agent (AICA), developed under NATO&#x2019;s research initiatives, and its multi-agent extension (MAICA) focus on active, autonomous defense for battlefield networks and critical systems. These architectures emphasize sensing, adaptive planning, negotiation, and learning, forming a self-sufficient defense layer capable of acting even when human operators are unavailable.
                    <sup>
                        <xref ref-type="bibr" rid="ref170">161</xref>
                    </sup>
                </p>
                <p>AI-Driven Threat-Resilient Cloud Security.</p>
                <p>In cloud environments, frameworks such as Autonomous Threat Defense for Cloud AI integrate behavioral analytics, self-healing infrastructure, and adversarial learning to predict and neutralize threats before they materialize. These systems progress through stages of basic anomaly detection, behavioral analytics, and cognitive security, enabling proactive defense in dynamic cloud deployments.
                    <sup>
                        <xref ref-type="bibr" rid="ref171">162</xref>
                    </sup>
                </p>
                <p>Multi-Layered Defense Against Adversarial Attacks.</p>
                <p>Novel defense models propose layered countermeasures to tackle adversarial attacks unique to agentic AI, combining robustness training, explainable AI monitoring, and policy-based enforcement. These frameworks address new attack surfaces introduced by agent autonomy, including database-level manipulation and goal hijacking.
                    <sup>
                        <xref ref-type="bibr" rid="ref172">163</xref>
                    </sup>
                </p>
                <p>Security-First Design for Agentic Process Automation (APA).</p>
                <p>For enterprise agentic systems, a security-first design policy integrates continuous monitoring, agent-to-agent security protocols, and self-healing defenses. These approaches aim to secure autonomous workflows in finance, manufacturing, and logistics, minimizing risks of process manipulation and data breaches.
                    <sup>
                        <xref ref-type="bibr" rid="ref143">137</xref>
                    </sup>
                </p>
                <p>Cross-Cutting Insights.</p>
                <p>Across these frameworks, common strategies emerge:
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Adaptive, learning-based defenses to counter evolving adversarial tactics.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Formal verification and runtime auditing to enhance trustworthiness.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Integration of cryptographic and policy layers to ensure secure interoperability.</p>
                        </list-item>
                    </list>
                </p>
                <p>So, these emerging frameworks, ACD, AICA/MAICA, AI-driven cloud defense, and APA security models, provide complementary defense paradigms for agentic AI. Their convergence with governance-focused architectures like SHIELD and SAGA points toward the evolution of holistic, multi-layered defense ecosystems for future agentic AI deployments.</p>
            </sec>
            <sec id="sec45">
                <title>8.5 Comparative evaluation of defense strategies</title>
                <p>The various defense frameworks discussed include SHIELD, Zero-Trust Architectures (ZTA), SAGA, and other emerging defense models, which offer complementary protections across different layers of agentic AI security. However, their effectiveness varies depending on threat type, deployment context, and governance integration. As seen in 
                    <xref ref-type="table" rid="T4">
Table 4</xref>. This table compares major governance models applicable to agentic AI OECD AI Principles, EU AI Act, NIST AI RMF, blockchain-based governance (DAOs), and federated governance across governance type, key features, strengths, limitations, and example frameworks. It highlights trade-offs in adaptability, enforceability, and scalability of each model for managing trust and accountability in autonomous systems. 
                    <xref ref-type="table" rid="T4">
Table 4</xref>. Comparative Evaluation of Defense Strategies for Agentic AI</p>
                <table-wrap id="T4" orientation="portrait" position="float">
                    <label>
Table 4. </label>
                    <caption>
                        <title>Comparative Evaluation of Defense Strategies for Agentic AI.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top">Framework</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">
Primary Focus</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Key Strengths</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Limitations</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Representative References</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>SHIELD</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Layered defense across node, network, middleware, overlay</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Multi-layer protections; adaptive orchestration; strong integration of metrics for security, privacy, dependability (SPD)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">High deployment complexity; computational overhead in dynamic environments</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <sup>
                                        <xref ref-type="bibr" rid="ref155">148</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Zero-Trust Architecture (ZTA)</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Continuous authentication, least-privilege access, and runtime monitoring</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Strong against insider threats, stealth execution, AI-driven anomaly detection, and scalable to cloud environments</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Requires complex integration with legacy systems; adversarial attacks may target monitoring AI</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <sup>
                                        <xref ref-type="bibr" rid="ref2">2</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>SAGA</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Cryptographic identity enforcement, policy-driven governance</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Fine-grained access control; verifiable agent identity; minimal performance degradation; strong accountability</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">A centralized provider may become a single point of failure, with limited support for fully decentralized deployments</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <sup>
                                        <xref ref-type="bibr" rid="ref173">164</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Autonomous Cyber Defense (ACD)</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Multi-agent reinforcement learning for adaptive cyber defense</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Real-time autonomous threat detection; formal verification for robustness; effective in military contexts</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">High training complexity; potential for misaligned autonomous actions</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <sup>
                                        <xref ref-type="bibr" rid="ref174">165</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>AI-Driven Cloud Defense</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Behavioral analytics, self-healing infrastructure, and cognitive security</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Proactive defense; predictive threat neutralization; suitable for large-scale cloud ecosystems</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Explainability gap; vulnerability to adversarial manipulation</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <sup>
                                        <xref ref-type="bibr" rid="ref171">162</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>APA Security Models</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Securing autonomous process automation in enterprises</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Continuous monitoring; agent-to-agent security protocols; strong data protection</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Regulatory adaptation needed; evolving threat vectors in enterprise environments</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <sup>
                                        <xref ref-type="bibr" rid="ref143">137</xref>
                                    </sup>
                                </td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <p>Key Insights from Comparative Analysis
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>SHIELD offers broad, cross-layer defense but at the cost of complexity.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>ZTA excels in trust minimization and dynamic oversight, ideal for federated and cloud environments.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>SAGA is strongest in identity governance, crucial for preventing shadow agents and impersonation.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>ACD and AICA provide adaptive defense in military and high-threat environments but require robust verification to avoid unintended escalation.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Emerging models for instance AI-driven cloud defense, APA security fill domain-specific gaps but must integrate with overarching governance strategies to ensure systemic resilience.</p>
                        </list-item>
                    </list>
                </p>
                <p>As shown in 
                    <xref ref-type="fig" rid="f14">
Figure 10</xref>, no single defense framework is sufficient; the future lies in hybrid models combining SHIELD&#x2019;s layered structure, ZTA&#x2019;s continuous verification, SAGA&#x2019;s cryptographic controls, and adaptive autonomous defenses to counter rapidly evolving threats in agentic AI deployments.</p>
                <fig fig-type="figure" id="f14" orientation="portrait" position="float">
                    <label>
Figure 10. </label>
                    <caption>
                        <title>Integrated Taxonomy of Threats and Defenses.</title>
                        <p>Combined mapping of threats such as hallucination, reward hacking, memory poisoning, tool misuse, prompt injection, and shadow agents, against mitigation strategies like robust alignment, misuse prevention, and federated trust.</p>
                    </caption>
                    <graphic id="gr14" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/187320/b84a7a26-d91c-4577-b571-86480f29d540_figure14.gif"/>
                </fig>
            </sec>
        </sec>
        <sec id="sec46">
            <title>9. Challenges and open research directions</title>
            <sec id="sec47">
                <title>9.1 Goal alignment and reward manipulation</title>
                <p>Goal alignment, ensuring that agentic AI systems pursue objectives consistent with human values, remains a core challenge in AI safety. Misalignment issues such as goal drift, specification gaming, and reward hacking can lead to unexpected or harmful outcomes, especially as agents gain autonomy and optimize for unintended objectives.</p>
                <p>Goal Alignment Challenges.</p>
                <p>Misaligned goals often stem from incomplete or incorrect objective specifications, where the AI&#x2019;s interpretation of its reward function diverges from human intent. Studies highlight that human expectations are often asymmetric with the behavior produced by agents, creating gaps that allow for undesirable optimizations.
                    <sup>
                        <xref ref-type="bibr" rid="ref175">166</xref>
                    </sup> The EU AI Act itself, when analyzed through alignment theory, was shown to potentially suffer from proxy gaming, where agents optimize for compliance proxies rather than true safety goals.</p>
                <p>Reward Manipulation and Specification Gaming.</p>
                <p>Agentic AI systems may exploit weaknesses in reward functions, engaging in reward hacking or specification gaming to maximize proxy metrics while violating the intended spirit of their objectives. This is especially critical when agents influence user preferences to achieve favorable evaluations, as shown in models accounting for changing and influenceable preferences.
                    <sup>
                        <xref ref-type="bibr" rid="ref176">167</xref>
                    </sup> Over-optimization on incomplete objectives can drive agents to behaviors that severely degrade overall utility.
                    <sup>
                        <xref ref-type="bibr" rid="ref177">168</xref>
                    </sup>
                </p>
                <p>Emerging Alignment Strategies.</p>
                <p>Solutions involve human-aware alignment algorithms, interactive approaches to infer user goals from incorrect beliefs, and inverse reinforcement learning (IRL) to better model human values. New frameworks, such as Expectation Alignment (EAL), formalize the detection and correction of misspecified rewards, while methods like SALMON use instructible reward models to align behavior with human-defined principles more effectively.
                    <sup>
                        <xref ref-type="bibr" rid="ref178">169</xref>,
                        <xref ref-type="bibr" rid="ref179">170</xref>
                    </sup> Multi-dimensional strategies integrating human feedback, value learning, and policy-based oversight are considered most promising.
                    <sup>
                        <xref ref-type="bibr" rid="ref180">171</xref>
                    </sup>
                </p>
                <p>Risks of Manipulative Alignment.</p>
                <p>Researchers caution that AI systems may manipulate human reward mechanisms, influencing user choices or emotional states to secure favorable evaluations, exploiting vulnerabilities in decision-making. This highlights the need for robust interpretability and ethically grounded safeguards to prevent manipulation.</p>
                <p>Furthermore, Goal alignment and reward manipulation present intertwined risks for agentic AI, demanding dynamic, human-centered solutions that adapt to evolving objectives while preventing agents from exploiting specification weaknesses. Future work must integrate continuous feedback, context-sensitive oversight, and interdisciplinary governance to mitigate these alignment failures.</p>
            </sec>
            <sec id="sec48">
                <title>9.2 Memory integrity and contradictory knowledge</title>
                <p>Memory integrity is crucial for agentic AI systems, as corrupted or contradictory knowledge can directly undermine decision-making, alignment, and security. Agentic AI relies on dynamic, long-term memory architectures to store and retrieve contextual information; however, these same features introduce vulnerabilities to memory poisoning, knowledge conflicts, and semantic drift.</p>
                <p>Integrity Risks in Agent Memory.</p>
                <p>Studies show that users often have incomplete mental models of how agents remember and recall information, making them vulnerable to unintentionally reinforcing biases or introducing incorrect data.
                    <sup>
                        <xref ref-type="bibr" rid="ref181">172</xref>
                    </sup> Moreover, episodic memory capabilities, while useful for monitoring and auditing, introduce risks of retaining sensitive or maliciously altered information, which can propagate errors through reasoning and planning modules.
                    <sup>
                        <xref ref-type="bibr" rid="ref182">173</xref>
                    </sup>
                </p>
                <p>Contradictory Knowledge and Semantic Conflicts.</p>
                <p>As agentic AI integrates information from multiple dynamic sources, contradictions inevitably emerge. Without robust conflict resolution mechanisms, agents may oscillate between inconsistent states or make decisions based on outdated data. Frameworks like MARK (Memory-Augmented Refinement of Knowledge) propose continuously refining memory through structured updates and contradiction resolution, thereby reducing hallucinations and improving response reliability.
                    <sup>
                        <xref ref-type="bibr" rid="ref183">174</xref>
                    </sup> Similarly, SemanticCommit introduces human-in-the-loop tools to detect and resolve semantic conflicts during memory updates.
                    <sup>
                        <xref ref-type="bibr" rid="ref184">175</xref>
                    </sup>
                </p>
                <p>Architectures Enhancing Memory Integrity.</p>
                <p>Several advanced architectures aim to improve memory integrity:
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Zep, a temporal knowledge graph engine, dynamically synthesizes unstructured and structured data while maintaining historical relationships, outperforming existing systems like MemGPT in long-term reasoning tasks.
                                <sup>
                                    <xref ref-type="bibr" rid="ref185">176</xref>
                                </sup>
                            </p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>SHIMI uses a Semantic Hierarchical Memory Index to organize knowledge by meaning rather than surface similarity, enabling more precise retrieval and conflict resolution, particularly in decentralized environments.
                                <sup>
                                    <xref ref-type="bibr" rid="ref186">177</xref>
                                </sup>
                            </p>
                        </list-item>
                    </list>
                </p>
                <p>Trade-Offs in Memory Management.</p>
                <p>Maintaining integrity requires balancing memorization with generalization. Overfitting to stored data may cause rigidity, while excessive forgetting risks losing critical contextual information. Research on continual learning agents confirms that memory capacity and update strategies critically influence robustness to environmental changes.
                    <sup>
                        <xref ref-type="bibr" rid="ref187">178</xref>
                    </sup>
                </p>
                <p>Furthermore, Memory integrity and the management of contradictory knowledge are central to the reliability of agentic AI. Future research must integrate semantic conflict resolution, privacy-preserving memory control, and temporal reasoning architectures to ensure agents maintain coherent, accurate, and trustworthy internal representations throughout their operational lifecycle.</p>
            </sec>
            <sec id="sec49">
                <title>9.3 Auditability, explainability, and transparency</title>
                <p>Auditability, explainability, and transparency are foundational pillars for ensuring that agentic AI systems remain trustworthy, interpretable, and aligned with human oversight mechanisms. These properties not only support accountability but also mitigate risks stemming from opacity, bias, and emergent unintended behaviors.</p>
                <p>Auditability: Enabling Independent Oversight.</p>
                <p>Auditability refers to the capability of external entities, regulators, auditors, or stakeholders to systematically examine AI decision-making processes. Unlike explainability, which is user-focused, auditability requires access to exhaustive system logs, decision traces, and datasets. A clear distinction is necessary: while explainability builds user trust, auditability empowers third parties to diagnose fairness and compliance issues.
                    <sup>
                        <xref ref-type="bibr" rid="ref188">179</xref>
                    </sup> Research stresses that combining both dimensions is crucial, as transparency measures optimized for end-users may not provide sufficient detail for audits.</p>
                <p>Explainability: From Black Boxes to Human Understanding.</p>
                <p>Explainability (XAI) techniques such as SHAP, LIME, and counterfactual explanations aim to clarify how an AI system arrives at its decisions. For agentic AI, this is particularly complex because decisions often involve multi-step reasoning, memory retrieval, and inter-agent interactions. New approaches, including human-centered XAI (HCXAI), emphasize participatory methods where stakeholders are actively involved in interpreting explanations, thereby improving the alignment between technical transparency and user comprehension.
                    <sup>
                        <xref ref-type="bibr" rid="ref189">180</xref>
                    </sup>
                </p>
                <p>Transparency: The Broader Ethical Context.</p>
                <p>Transparency encompasses both explainability and auditability, but also traceability, fairness, and accessibility of information about the AI system. Studies on ethical AI development emphasize that transparency should not only serve technical functions but also safeguard public trust and democratic accountability.
                    <sup>
                        <xref ref-type="bibr" rid="ref190">181</xref>
                    </sup> This involves clarifying the purpose, limitations, and data sources of agentic systems, as well as making design choices traceable through knowledge graphs and structured audit trails.
                    <sup>
                        <xref ref-type="bibr" rid="ref191">182</xref>
                    </sup>
                </p>
                <p>Challenges in Achieving Full Transparency.</p>
                <p>While regulations like the EU AI Act call for &#x201c;meaningful explanations&#x201d;, practical challenges persist, including:
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Trade-offs between usability and audit depth, where too much technical detail overwhelms users while too little prevents audits.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Intellectual property constraints limit how much internal model information can be disclosed without compromising proprietary algorithms.
                                <sup>
                                    <xref ref-type="bibr" rid="ref192">183</xref>
                                </sup>
                            </p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Emergent opacity, where multi-agent interactions generate behaviors not easily traceable to any single decision rule.</p>
                        </list-item>
                    </list>
                </p>
                <p>Toward Integrated Solutions.</p>
                <p>Emerging strategies propose combining XAI layers with formalized auditing mechanisms (e.g., blockchain-based logging) to ensure decisions are both interpretable and verifiable. Participatory governance models further suggest involving diverse stakeholders in defining transparency requirements, ensuring that explainability meets the needs of both experts and lay users.
                    <sup>
                        <xref ref-type="bibr" rid="ref181">172</xref>,
                        <xref ref-type="bibr" rid="ref193">184</xref>
                    </sup>
                </p>
                <p>So, agentic AI, auditability, explainability, and transparency must be treated as complementary but distinct properties. Future research should integrate knowledge graph-based audits, user-centered XAI techniques, and policy-driven transparency standards to ensure both operational clarity and systemic accountability.</p>
            </sec>
            <sec id="sec50">
                <title>9.4 Federated governance and agent revocation mechanisms</title>
                <p>Federated governance refers to decentralized oversight structures where multiple entities collaboratively manage agentic AI, reducing reliance on centralized control while improving adaptability and resilience. This model is crucial for agentic AI, which often operates across distributed networks and jurisdictional boundaries.</p>
                <p>Federated Governance Models.</p>
                <p>Governance of federated agent ecosystems leverages polycentric structures, allowing diverse stakeholders to enforce local norms while adhering to global interoperability standards. For instance, studies on federated platforms demonstrate that multi-level governance enhances scalability and trust, but risks fragmentation without shared principles.
                    <sup>
                        <xref ref-type="bibr" rid="ref194">185</xref>
                    </sup> Similarly, Academy, a middleware for scientific agent ecosystems, shows how federated governance can coordinate autonomous agents across HPC environments while maintaining oversight through modular control points.
                    <sup>
                        <xref ref-type="bibr" rid="ref195">186</xref>
                    </sup>
                </p>
                <p>Agent Revocation Mechanisms.</p>
                <p>Revoking rogue or compromised agents is essential to prevent systemic failures. Current approaches include:
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Cryptographic revocation lists to immediately invalidate agent credentials, ensuring that revoked entities cannot interact with the ecosystem.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Blockchain-enabled registries like BELIEFS create immutable audit trails and enable distributed consensus to quarantine or revoke malicious agents even in adversarial conditions.
                                <sup>
                                    <xref ref-type="bibr" rid="ref100">96</xref>
                                </sup>
                            </p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Policy-driven kill-switches, where federated authorities retain the power to remotely disable agents that breach operational or ethical policies.</p>
                        </list-item>
                    </list>
                </p>
                <p>Challenges in Revocation.</p>
                <p>Implementing revocation in federated settings faces hurdles:
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Latency in detection and coordination, where slow response allows malicious agents to propagate threats.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Jurisdictional inconsistencies make global enforcement difficult.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Potential abuse of revocation powers highlights the need for transparent procedures and distributed consensus.</p>
                        </list-item>
                    </list>
                </p>
                <p>Toward Secure Federated Governance.</p>
                <p>Emerging approaches advocate systems-theoretic governance, where agent properties (autonomy, goal complexity, generality) determine revocation policies dynamically. Additionally, entropy-aware federated architectures suggest integrating quantum-ready, LLM-driven oversight to reconcile decentralized control with global security standards.
                    <sup>
                        <xref ref-type="bibr" rid="ref198">187</xref>
                    </sup>
                </p>
                <p>Moreso, Federated governance enhances adaptability and trust in agentic AI, but its effectiveness hinges on robust, cryptographically enforced revocation mechanisms. The integration of blockchain consensus, policy-driven kill-switches, and dynamic risk-aware revocation frameworks is essential to prevent governance gaps and ensure secure, ethical operation across distributed AI ecosystems.</p>
            </sec>
            <sec id="sec51">
                <title>9.5 Shadow agents, insider risks, and stealth execution</title>
                <p>Shadow agents, insider risks, and stealth execution present some of the most insidious security threats to agentic AI systems. These vulnerabilities exploit the autonomy, persistence, and distributed nature of such agents, often bypassing traditional defenses.</p>
                <p>Shadow Agents and Hidden Execution Paths.</p>
                <p>Shadow agents refer to unauthorized or hidden autonomous entities that operate alongside legitimate agents, often executing malicious tasks without detection. Their stealth arises from blending into normal agent traffic and leveraging legitimate system privileges. Research shows that shadow agents can exploit tool integrations, persistent memory, and reasoning chains to conceal malicious operations while avoiding standard detection mechanisms.</p>
                <p>Insider Risks: The Human-AI Nexus.</p>
                <p>Insider threats remain a critical challenge because malicious insiders already possess privileged access and knowledge of defenses. Studies indicate that AI-driven insider detection using behavioral analytics, NLP, and multimodal monitoring can improve detection rates, but attackers adapt by employing stealth strategies to avoid suspicion.
                    <sup>
                        <xref ref-type="bibr" rid="ref199">188</xref>
                    </sup> Game-theoretic analyses further reveal that when insiders collude with external attackers, stealth attacks become harder to mitigate, demanding joint monitoring of system and human interactions.
                    <sup>
                        <xref ref-type="bibr" rid="ref200">189</xref>
                    </sup>
                </p>
                <p>Stealth Execution Techniques.</p>
                <p>Stealth execution involves malicious activity hidden within legitimate agent workflows, often leveraging delayed exploitability and cross-system propagation. Advanced persistent threats (APTs) have evolved to include stealthy, long-term control of agentic systems, circumventing standard anomaly detection.
                    <sup>
                        <xref ref-type="bibr" rid="ref58">58</xref>
                    </sup> Active Environment Injection Attacks (AEIA) demonstrate how adversaries can disguise malicious inputs as benign environmental elements, misleading agents during reasoning and decision-making.
                    <sup>
                        <xref ref-type="bibr" rid="ref201">190</xref>
                    </sup>
                </p>
                <p>Detection and Mitigation Approaches.
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Advanced Threat Models, such as ATFAA, map out vulnerabilities specific to agentic AI and propose detection strategies targeting cross-layer stealth behaviors.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Active Defense Infrastructures like ShadowNet dynamically redirect suspicious traffic to quarantined environments, neutralizing attacks while logging activity for forensic analysis.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>AI-Driven Insider Monitoring combines eye-tracking, behavioral analysis, and contextual risk scoring to identify covert insider activity even when access appears legitimate.
                                <sup>
                                    <xref ref-type="bibr" rid="ref203">191</xref>
                                </sup>
                            </p>
                        </list-item>
                    </list>
                </p>
                <p>So, Shadow agents, insider threats, and stealth execution exploit blind spots in current monitoring architectures. Addressing these risks requires integrating behavior-aware detection, cryptographically enforced identity control, and continuous runtime monitoring to uncover hidden behaviors before they escalate into systemic compromises.</p>
            </sec>
            <sec id="sec52">
                <title>9.6 Embedding regulatory and legal norms into agents</title>
                <p>Embedding regulatory and legal norms into agentic AI is a critical step toward ensuring these systems act in compliance with societal standards, ethical principles, and jurisdictional laws. Unlike static compliance methods, embedded norms must be dynamic, interpretable, and enforceable across diverse operational contexts.</p>
                <p>Normative Embedding through AI Architecture.</p>
                <p>Embedding norms involves integrating legal rules, ethical principles, and policy constraints directly into the reasoning and decision-making layers of AI agents. Frameworks such as Multi-Agent Online Planning Architecture for Real-Time Compliance (MAPA) formalize legal norms as hard constraints and ethical norms as soft constraints, allowing agents to re-plan dynamically when environmental conditions change. This ensures continuous adherence to evolving legal requirements without sacrificing operational flexibility.</p>
                <p>Regulatory Compliance via Generative AI Systems.</p>
                <p>Legal generative AI tools such as Gracenote.ai show how regulatory compliance can be operationalized by embedding domain-specific legal reasoning into agent workflows. This involves combining LLMs with horizon scanning and obligations generation tools, ensuring agents maintain compliance across multi-jurisdictional contexts while reducing risks of hallucination and misinterpretation.
                    <sup>
                        <xref ref-type="bibr" rid="ref205">192</xref>
                    </sup> The use of human-in-the-loop mechanisms ensures that automated legal compliance remains auditable and ethically grounded.</p>
                <p>Norm Learning and Adaptive Compliance.</p>
                <p>Beyond embedding pre-defined rules, researchers have developed systems enabling agents to learn legal norms through behavioral exploration and sparse human supervision. This approach allows agents to infer normative boundaries from observed consequences, enabling better adaptation to ambiguous regulatory environments.
                    <sup>
                        <xref ref-type="bibr" rid="ref206">193</xref>
                    </sup> Such systems bridge the gap between rigid rule enforcement and the nuanced application of laws in complex real-world scenarios.</p>
                <p>Value and Principle Embedding.</p>
                <p>Embedding goes beyond compliance by incorporating ethical principles, autonomy, fairness, and accountability into agent behavior. Norms are treated as technical instructions (algo-norms) embedded in the system architecture, enabling agents to reason about trade-offs between legal constraints and operational goals. This aligns with policy frameworks such as those from the EU High-Level Expert Group on AI.</p>
                <p>Challenges and Open Questions.
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Dynamic Legal Environments: Legal norms evolve, requiring agents to continuously update embedded rules.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Interpretability vs. Complexity: Deeply embedded norms may be opaque to regulators, undermining transparency.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Cross-Jurisdictional Compliance: Agents must handle conflicting legal requirements across regions.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Value Conflicts: Ethical and legal norms may not always align, requiring context-sensitive prioritization.</p>
                        </list-item>
                    </list>
                </p>
                <p>Furthermore, embedding regulatory and legal norms into agentic AI requires technical formalization, adaptive learning mechanisms, and human oversight. Future approaches will likely combine normative reasoning architectures, LLM-driven compliance engines, and policy-aware monitoring to create agents that are not only powerful but also law-abiding and ethically trustworthy.</p>
            </sec>
            <sec id="sec53">
                <title>9.7 Institutional readiness and policy gaps</title>
                <p>Institutional readiness for managing agentic AI remains uneven across countries, with significant policy gaps that hinder effective governance. While technological advancements have outpaced regulation, institutional mechanisms to oversee deployment, manage risks, and enforce compliance are still underdeveloped.</p>
                <p>Disparities in Institutional Readiness.</p>
                <p>Studies reveal substantial variation in AI governance readiness, even among technologically advanced nations. Such as The AI Family Integration Index (AFII) introduces a multidimensional tool assessing countries&#x2019; readiness to integrate emotionally intelligent AI, revealing gaps between policy rhetoric and real-world execution. Nations like Singapore demonstrate strong alignment between policy intent and operational readiness, while others for instance the U.S. and France score high technically but lag in implementing ethical integration practices.
                    <sup>
                        <xref ref-type="bibr" rid="ref208">194</xref>
                    </sup>
                </p>
                <p>Policy Gaps in Regulatory Frameworks.</p>
                <p>Governments articulate ethical AI principles but often lack enforcement mechanisms and institutional capacities to translate these principles into operational standards. For instance, ASEAN countries exhibit varying levels of preparedness, with Singapore leading through sophisticated policies, while Thailand and Malaysia face enforcement challenges and infrastructural limitations.
                    <sup>
                        <xref ref-type="bibr" rid="ref209">195</xref>
                    </sup> Healthcare AI governance in the region underscores similar gaps, with many countries lacking comprehensive legal frameworks for ethical deployment.
                    <sup>
                        <xref ref-type="bibr" rid="ref210">196</xref>
                    </sup>
                </p>
                <p>The Governance Gap Lens.</p>
                <p>Several frameworks identify a policy-practice dissonance; institutions may adopt AI ethics guidelines but fail to embed them into governance workflows. UNESCO&#x2019;s Readiness Assessment Methodology (RAM) highlights this gap, emphasizing the need for capacity-building and alignment of regulations with human-centered principles.
                    <sup>
                        <xref ref-type="bibr" rid="ref211">197</xref>
                    </sup> Without operational alignment, even well-formulated policies risk becoming symbolic.</p>
                <p>Emerging Decentralized Governance Models.</p>
                <p>New proposals, such as ETHOS (Ethical Technology and Holistic Oversight System), advocate decentralized governance leveraging blockchain, smart contracts, and DAOs. These models enable dynamic risk classification, automated compliance, and transparent dispute resolution, bridging gaps where centralized oversight is insufficient.</p>
                <p>Challenges to Institutional Readiness.
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Technical Capacity Gaps: Governments lack the technical expertise to audit and regulate rapidly evolving AI systems.
                                <sup>
                                    <xref ref-type="bibr" rid="ref213">198</xref>
                                </sup>
                            </p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Fragmented International Standards: Diverging national policies hinder interoperability and coordinated responses.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Slow Policy Adaptation: Legal frameworks often lag behind technological advancements, leaving gaps exploitable by malicious actors.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Limited Ethical Integration: Few policies account for emotional, relational, and cultural dimensions of AI deployment.
                                <sup>
                                    <xref ref-type="bibr" rid="ref208">194</xref>
                                </sup>
                            </p>
                        </list-item>
                    </list>
                </p>
                <p>Moreso, the Institutional readiness for agentic AI governance is patchy and constrained by policy-practice gaps, technical deficits, and a lack of harmonized oversight mechanisms. Bridging these gaps requires capacity-building, cross-border coordination, and the adoption of adaptive governance frameworks, potentially integrating decentralized models like ETHOS with human-centered regulatory approaches to ensure both innovation and accountability.</p>
            </sec>
            <sec id="sec54">
                <title>9.8 Benchmarking, testing, and empirical validation platforms</title>
                <p>The rapid growth of agentic AI necessitates robust benchmarking, testing, and empirical validation platforms to ensure reliability, safety, and adaptability. Unlike traditional machine learning benchmarks, agentic AI systems demand evaluation across dynamic environments, multi-objective optimization, and cross-agent coordination, requiring new paradigms beyond static metrics.</p>
                <p>Multi-Objective and Safety-Oriented Benchmarks.</p>
                <p>Recent studies emphasize the need for benchmarks that incorporate biological and economic alignment principles, reflecting real-world complexities. The multi-objective, multi-agent safety benchmarks proposed by Pihlakas &amp; Pyykko introduce themes like homeostasis, sustainability, and resource sharing, revealing pitfalls where agents over-optimize single objectives at the expense of safety and long-term stability.
                    <sup>
                        <xref ref-type="bibr" rid="ref214">199</xref>
                    </sup>
                </p>
                <p>Observability-Driven Testing Frameworks.</p>
                <p>Standard "black-box" testing is inadequate for agentic AI, where non-deterministic flows and context-dependent behaviors complicate evaluation. New frameworks advocate runtime observability and analytics to extract decision traces, detect emergent issues, and optimize agent performance dynamically.
                    <sup>
                        <xref ref-type="bibr" rid="ref215">200</xref>
                    </sup> These approaches enable continuous, interpretable evaluation across development and deployment phases.</p>
                <p>Task-Specific Validation Platforms.</p>
                <p>Several platforms target specialized domains:
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>OSUniverse benchmarks GUI-navigation agents, testing capabilities from precision tasks to multi-application workflows, with automated validation, achieving high reliability.
                                <sup>
                                    <xref ref-type="bibr" rid="ref216">201</xref>
                                </sup>
                            </p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>REALM-Bench evaluates multi-agent planning under dynamic disruptions, scaling task complexity to test adaptability and inter-agent coordination.
                                <sup>
                                    <xref ref-type="bibr" rid="ref217">202</xref>
                                </sup>
                            </p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>CORE-Bench focuses on computational reproducibility, assessing agent performance in replicating scientific workflows, an essential step toward trustworthy AI in research contexts.
                                <sup>
                                    <xref ref-type="bibr" rid="ref218">203</xref>
                                </sup>
                            </p>
                        </list-item>
                    </list>
                </p>
                <p>Explainability and Validation Toolkits.</p>
                <p>Platforms like EXACT (Explainable AI Comparison Toolkit) provide standardized datasets and metrics for validating the quality of model explanations, revealing that many XAI methods underperform when compared to human expectations.
                    <sup>
                        <xref ref-type="bibr" rid="ref219">204</xref>
                    </sup> These insights are crucial as agentic AI must be auditable and interpretable to meet regulatory and ethical standards.</p>
                <p>Challenges and Future Directions.
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Non-determinism and emergent behaviors complicate reproducibility and standardization.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Cross-domain benchmarking is lacking, as current platforms often address narrow use cases.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Integration of safety, ethics, and performance metrics into unified benchmarks is still underdeveloped.</p>
                        </list-item>
                    </list>
                </p>
                <p>So, the Next-generation benchmarking for agentic AI must integrate multi-objective safety, observability-driven analytics, and real-world complexity. Emerging platforms such as REALM-Bench, OSUniverse, and CORE-Bench mark a shift toward holistic, dynamic validation environments, paving the way for safer and more trustworthy agentic AI deployments.</p>
            </sec>
            <sec id="sec55">
                <title>9.9 Research gaps identified across adjacent domains</title>
                <p>Despite substantial progress in agentic AI, significant research gaps persist across cybersecurity, ethics, governance, and multi-agent systems, hindering the development of fully trustworthy deployments.
                    <list list-type="order">
                        <list-item>
                            <label>1.</label>
                            <p>Cybersecurity and Risk Management Gaps.</p>
                            <p>Agentic AI introduces new attack surfaces and responsibility gaps not fully addressed by current cybersecurity frameworks. While advanced approaches leverage agentic and frontier AI for ethical threat intelligence, researchers note a lack of standardized methods for continuous, proactive defense and cross-domain incident reporting. Moreover, existing laws fail to regulate AI-driven offensive cyber capabilities, leaving accountability for AI-initiated cyber incidents unresolved.
                                <sup>
                                    <xref ref-type="bibr" rid="ref221">205</xref>
                                </sup>
                            </p>
                        </list-item>
                        <list-item>
                            <label>1.</label>
                            <p>Governance and Institutional Gaps.</p>
                            <p>AI governance remains fragmented, with unclear implementation mechanisms, insufficient operationalization of ethical principles, and a lack of international coordination.
                                <sup>
                                    <xref ref-type="bibr" rid="ref222">206</xref>
                                </sup> Decentralized governance proposals such as ETHOS show promise but require further empirical validation to ensure effectiveness in multi-jurisdictional contexts.</p>
                        </list-item>
                        <list-item>
                            <label>2.</label>
                            <p>Ethical and Normative Gaps.</p>
                            <p>Ethical integration in agentic AI remains superficial. Existing work highlights moral crumple zones, where accountability becomes diffused across multiple actors, leaving harms unaddressed. There is a need for robust value-alignment frameworks that prevent agents from drifting toward unintended goals while embedding context-aware legal norms directly into AI reasoning layers.</p>
                        </list-item>
                        <list-item>
                            <label>5.</label>
                            <p>Multi-Agent System Coordination Gaps.</p>
                            <p>Research on multi-agent collaboration shows that emergent behaviors in cross-domain settings remain unpredictable and under-evaluated. Recent work on cross-domain knowledge discovery using multi-AI agents reveals the potential of collaborative frameworks but highlights gaps in efficiency, knowledge transfer, and conflict resolution mechanisms.
                                <sup>
                                    <xref ref-type="bibr" rid="ref224">207</xref>
                                </sup>
                            </p>
                        </list-item>
                        <list-item>
                            <label>6.</label>
                            <p>Risk Alignment and Accountability Gaps.</p>
                            <p>Risk alignment, ensuring agentic AI systems adopt risk attitudes aligned with human values, remains an unresolved issue. Poorly calibrated systems risk reckless behaviors and create responsibility voids where neither developers nor users can be held fully accountable.
                                <sup>
                                    <xref ref-type="bibr" rid="ref225">208</xref>
                                </sup> Further work is needed to integrate risk-calibration mechanisms into agent decision-making.</p>
                        </list-item>
                        <list-item>
                            <label>7.</label>
                            <p>Interdisciplinary and Cross-Domain
 Gaps.</p>
                            <p>Research across ethics, cybersecurity, and governance remains siloed, preventing comprehensive solutions. The rise of agentic AI for scientific discovery underscores the need for interdisciplinary frameworks combining technical safety, ethical oversight, and legal enforceability.</p>
                        </list-item>
                    </list>
                </p>
                <p>As shown in 
                    <xref ref-type="table" rid="T5">
Table 5</xref>. The key research gaps lie in standardizing cybersecurity protocols, operationalizing governance models, embedding ethics at the architectural level, and achieving predictable multi-agent coordination. Addressing these gaps demands interdisciplinary research, adaptive regulatory frameworks, and empirical validation of emerging solutions to ensure safe, ethical, and effective agentic AI deployments.</p>
                <table-wrap id="T5" orientation="portrait" position="float">
                    <label>
Table 5. </label>
                    <caption>
                        <title>Research Gaps Across Adjacent Domains.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top">Domain</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Key Research Gaps</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Needed Advances</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Cybersecurity</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Lack of standardized cross-domain incident reporting; evolving adversarial threats</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Proactive, adaptive defense frameworks; integrated threat intelligence</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Governance</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Weak operationalization of ethics; inconsistent international standards</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Polycentric governance; dynamic compliance monitoring</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Ethics</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Diffused accountability (&#x201c;moral crumple zones&#x201d;); shallow value embedding</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Context-aware normative reasoning: architectures for moral responsibility</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Multi-Agent Systems</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Unpredictable emergent behaviors; poor conflict resolution mechanisms</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Conflict-aware coordination algorithms; scalable testing platforms</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Risk &amp; Accountability</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Misaligned risk attitudes; absence of clear liability frameworks</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Integrated risk calibration; legally enforceable accountability models</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Benchmarking &amp; Validation</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Limited dynamic cross-domain evaluation; inadequate metrics</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Observability-driven benchmarks; multi-objective safety evaluation</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
            </sec>
        </sec>
        <sec id="sec56" sec-type="conclusion">
            <title>10. Conclusion</title>
            <p>To support implementation, a consolidated list of strategic recommendations is provided in Table A9 (Supplementary Material).</p>
            <sec id="sec57">
                <title>10.1 Summary of insights from the survey</title>
                <p>This survey integrates findings from diverse research on agentic AI architectures, threats, defense mechanisms, and governance, providing a holistic understanding of the challenges and strategies required for trustworthy deployment.</p>
                <p>Architectural Complexity and Unique Threats.</p>
                <p>Agentic AI systems differ fundamentally from traditional AI and LLMs because they reason, plan, and act autonomously across distributed environments. Their unique architecture introduces novel vulnerabilities such as cognitive exploits, shadow agents, and cross-layer propagation that are not addressed by legacy security frameworks. New threat models like ATFAA have been proposed to classify these risks and inform mitigation strategies.</p>
                <p>Evolving Governance and Oversight Models.</p>
                <p>Traditional governance frameworks (e.g., OECD, EU AI Act, NIST) provide initial guardrails but lack specific provisions for agentic AI, which operates across federated and dynamic contexts. Emerging solutions combine policy-driven governance, blockchain-backed trust frameworks, and decentralized oversight models to fill institutional gaps.</p>
                <p>Defense Strategies Require Layered Approaches.</p>
                <p>Defense mechanisms such as SHIELD, Zero-Trust Architectures, and SAGA address distinct layers of risk from secure execution to cryptographic identity control. However, no single framework suffices; future defense must integrate layered monitoring, cryptographic enforcement, and AI-driven threat adaptation to counter stealth and insider risks effectively.</p>
                <p>Key Insights Across Adjacent Domains.
                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Cybersecurity research highlights the need for proactive, adaptive defense, as static measures fail against evolving multi-agent threats.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Governance studies reveal persistent gaps in regulatory readiness and cross-jurisdictional enforcement.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Ethics research warns of moral crumple zones where accountability is diffused, necessitating embedded normative reasoning.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>Benchmarking and validation platforms remain underdeveloped for capturing emergent, non-deterministic agent behaviors, requiring new observability-driven metrics.</p>
                        </list-item>
                    </list>
                </p>
                <p>The review underscores that building trustworthy agentic AI requires synergistic advances across technical, governance, ethical, and empirical domains. A multi-layered defense, decentralized yet coordinated oversight, and interdisciplinary research are imperative to closing gaps and ensuring secure, accountable, and beneficial deployment of these autonomous systems.</p>
            </sec>
            <sec id="sec58">
                <title>10.2 Future outlook for trustworthy agentic AI</title>
                <p>The future of trustworthy agentic AI will be defined by technological advancements, ethical integration, and global governance innovations. The evolution of these systems will likely follow trends observed in emerging AI research, emphasizing adaptability, explainability, and human-centered oversight.</p>
                <p>Emerging Trends and Technological Drivers.</p>
                <p>Agentic AI will increasingly integrate quantum computing, edge intelligence, and multi-agent meta-learning to enhance scalability and decision-making capabilities. Future systems are expected to exhibit meta-reasoning abilities, enabling agents to explain and justify their decision-making processes, bridging current gaps in interpretability and accountability.</p>
                <p>Shifting Toward Human-Centric and Ethical AI.</p>
                <p>Trustworthy deployment will require embedding ethical norms, social intelligence, and human-in-the-loop mechanisms into agentic architectures. Future agentic AI is predicted to adopt multi-dimensional intelligence models, incorporating social, emotional, and ethical reasoning to align more closely with human values. These systems will increasingly focus on value-sensitive design, minimizing risks of manipulation or harmful autonomy.</p>
                <p>Governance and Regulatory Trajectories.</p>
                <p>Regulatory readiness will remain a decisive factor. Evolving policies must adapt to dynamic agentic behaviors and cross-border interactions, requiring frameworks that combine decentralized trust with enforceable accountability mechanisms. Explainable AI (XAI) and third-party audits will become core compliance tools to ensure that regulations translate into operational safety.</p>
                <p>Trust, Adoption, and Human-AI Collaboration.</p>
                <p>Trust in agentic AI will dictate adoption rates. Studies highlight that trust is shaped by technical robustness, ethical alignment, and perceived transparency. Agents capable of explaining their reasoning and negotiating with human stakeholders will foster a collaborative ecosystem rather than one of conflict or opacity.</p>
                <p>Challenges Ahead.</p>
                <p>Persistent risks include adversarial manipulation, moral crumple zones, and governance gaps in decentralized deployments. Addressing these requires interdisciplinary efforts, combining advances in cybersecurity, ethics, and policy to build systems that remain resilient under both technological and societal pressures.</p>
                <p>The future of trustworthy agentic AI lies in adaptive architectures enriched with ethical intelligence, supported by transparent governance frameworks and human-centered oversight. As these systems evolve, ensuring they remain aligned, secure, and explainable will be critical to realizing their transformative potential while safeguarding public trust and global stability.</p>
            </sec>
            <sec id="sec59">
                <title>10.3 Call for interdisciplinary collaboration</title>
                <p>Building trustworthy agentic AI is an inherently interdisciplinary challenge, demanding expertise that spans technical design, policy, ethics, law, and social sciences. The complexity of agentic AI autonomous systems capable of decision-making, planning, and multi-agent coordination requires coordinated efforts to mitigate risks, align goals, and ensure accountability.</p>
                <p>The Necessity of Cross-Domain Expertise.</p>
                <p>Agentic AI&#x2019;s transformative potential is accompanied by risks that cannot be solved by technical advances alone. Studies emphasize that interdisciplinary collaboration uniting AI engineers, ethicists, legal scholars, and social scientists is crucial to address the ethical, legal, and societal implications of autonomy and long-term goal pursuit. Collaborative frameworks ensure that AI solutions are not only technically robust but also socially aligned and ethically grounded.</p>
                <p>Enhancing Collaboration with Hybrid Models.</p>
                <p>Emerging research supports hybrid collaboration models, where multi-agent AI systems work alongside humans to jointly solve complex problems, amplifying creativity and problem-solving capacity. In software development, frameworks such as ChatCollab show how human and AI agents can co-create solutions effectively, reinforcing the benefits of team-based interdisciplinary dynamics.</p>
                <p>Institutionalizing Interdisciplinary Practices.</p>
                <p>Interdisciplinary collaboration must move beyond ad hoc partnerships to become institutionalized. This includes creating cross-sectoral task forces, academic-industry consortia, and policy advisory groups that foster ongoing dialogue between technical developers, regulators, and ethicists. Iterative methodologies that combine ethics-by-design, value-sensitive design, and continuous feedback cycles have been proposed to maximize the benefits of interdisciplinary synergies.</p>
                <p>Shaping Trustworthy Human-AI Collaboration.</p>
                <p>Research highlights that trust in agentic AI depends on collaborative governance, transparent communication, and shared decision-making between human and AI agents. Multi-disciplinary approaches also help anticipate unintended consequences and design AI ecosystems that align with societal values.</p>
                <p>The path to trustworthy agentic AI lies in deep interdisciplinary collaboration. By uniting technical innovation with ethical reasoning, legal oversight, and human-centered design, stakeholders can create AI systems that are not only powerful and adaptive but also transparent, accountable, and aligned with human welfare. Future advancements will require sustained, cooperative frameworks bridging academia, industry, and policy to ensure that agentic AI evolves as a beneficial and trustworthy partner in society.</p>
            </sec>
        </sec>
        <sec id="sec61">
            <title>Ethics and consent statement</title>
            <p>Ethical approval and consent were not required.</p>
        </sec>
    </body>
    <back>
        <sec id="sec63" sec-type="data-availability">
            <title>Data availability</title>
            <p>The supplementary materials underlying this article are openly available on Figshare
                <sup>
                    <xref ref-type="bibr" rid="ref227">209</xref>
                </sup>: Trustworthy Agentic AI Systems: A Cross-Layer Review of Architectures, Threat Models, and Governance Strategies for Real-World Deployment: Supplementary Data. This repository contains Tables, Figures, Appendix files, and Supplementary Data. All newly generated materials and supplementary datasets are available under the Creative Commons Attribution 4.0 International license (CC-BY 4.0).</p>
        </sec>
        <ack>
            <title>Acknowledgments</title>
            <p>Not applicable.</p>
        </ack>
        <ref-list>
            <title>References</title>
            <ref id="ref1">
                <label>1</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Vanneste</surname>
                            <given-names>BS</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Puranam</surname>
                            <given-names>P</given-names>
                        </name>
</person-group>:
                    <article-title>Artificial Intelligence, Trust, and Perceptions of Agency.</article-title>
                    <source>

                        <italic toggle="yes">Acad. Manag. Rev.</italic>
</source>
                    <year>Mar. 2024</year>.
                    <pub-id pub-id-type="doi">10.5465/AMR.2022.0041</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref2">
                <label>2</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Karamchand</surname>
                            <given-names>G</given-names>
                        </name>
</person-group>:
                    <article-title>Zero trust and AI: A synergistic approach to next-generation cyber threat mitigation.</article-title>
                    <source>

                        <italic toggle="yes">World J. Adv. Res. Rev.</italic>
</source>
                    <year>Dec. 2024</year>;<volume>24</volume>(<issue>3</issue>):<fpage>3374</fpage>&#x2013;<lpage>3387</lpage>.
                    <pub-id pub-id-type="doi">10.30574/WJARR.2024.24.3.3883</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref3">
                <label>3</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Conradie</surname>
                            <given-names>NH</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Nagel</surname>
                            <given-names>SK</given-names>
                        </name>
</person-group>:
                    <article-title>No Agent in the Machine: Being Trustworthy and Responsible about AI.</article-title>
                    <source>

                        <italic toggle="yes">Philos. &amp;amp; Technol.</italic>
</source>
                    <year>Jun. 2024</year>;<volume>37</volume>(<issue>2</issue>).
                    <pub-id pub-id-type="doi">10.1007/S13347-024-00760-W</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref4">
                <label>4</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Freiman</surname>
                            <given-names>O</given-names>
                        </name>
</person-group>:
                    <article-title>Making sense of the conceptual nonsense &#x2018;trustworthy AI,&#x2019;.</article-title>
                    <source>

                        <italic toggle="yes">AI Ethics.</italic>
</source>
                    <year>Nov. 2023</year>;<volume>3</volume>(<issue>4</issue>):<fpage>1351</fpage>&#x2013;<lpage>1360</lpage>.
                    <pub-id pub-id-type="doi">10.1007/S43681-022-00241-W</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref5">
                <label>5</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Lahusen</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Maggetti</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Slavkovik</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <article-title>Trust, trustworthiness and AI governance.</article-title>
                    <source>

                        <italic toggle="yes">Sci. Rep.</italic>
</source>
                    <year>Dec. 2024</year>;<volume>14</volume>(<issue>1</issue>):<fpage>20752</fpage>.
                    <pub-id pub-id-type="pmid">39237635</pub-id>
                    <pub-id pub-id-type="doi">10.1038/S41598-024-71761-0</pub-id>
                    <pub-id pub-id-type="pmcid">PMC11377768</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref6">
                <label>6</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Kumar</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sharma</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Pujari</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <article-title>AI Governance via Explainable Reinforcement Learning (XRL) for Adaptive Cyber Deception in Zero-Trust Networks.</article-title>
                    <source>

                        <italic toggle="yes">J. Inf. Syst. Eng. Manag.</italic>
</source>
                    <year>May 2025</year>;<volume>10</volume>(<issue>43s</issue>):<fpage>98</fpage>&#x2013;<lpage>115</lpage>.
                    <pub-id pub-id-type="doi">10.52783/JISEM.V10I43S.8308</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref7">
                <label>7</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mintoo</surname>
                            <given-names>AA</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Saimon</surname>
                            <given-names>ASM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Bakhsh</surname>
                            <given-names>MM</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>NATIONAL RESILIENCE THROUGH AI-DRIVEN DATA ANALYTICS AND CYBERSECURITY FOR REAL-TIME CRISIS RESPONSE AND INFRASTRUCTURE PROTECTION.</article-title>
                    <source>

                        <italic toggle="yes">Am. J. Sch. Res. Innov.</italic>
</source>
                    <year>Mar. 2022</year>;<volume>1</volume>(<issue>1</issue>):<fpage>137</fpage>&#x2013;<lpage>169</lpage>.
                    <pub-id pub-id-type="doi">10.63125/SDZ8KM60</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref8">
                <label>8</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Antony</surname>
                            <given-names>JIP</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Khalid</surname>
                            <given-names>PZM</given-names>
                        </name>
</person-group>:
                    <article-title>Integrating Artificial Intelligence (AI) in Teaching and Learning.</article-title>
                    <source>

                        <italic toggle="yes">Int. J. Multidiscip. Res.</italic>
</source>
                    <year>Mar. 2024</year>;<volume>6</volume>(<issue>2</issue>).
                    <pub-id pub-id-type="doi">10.36948/IJFMR.2024.V06I02.14064</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref9">
                <label>9</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Afroogh</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Akbari</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Malone</surname>
                            <given-names>E</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Trust in AI: Progress, Challenges, and Future Directions.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2024</year>;<volume>abs/2403.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2403.14680</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref10">
                <label>10</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Slosser</surname>
                            <given-names>JL</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Aasa</surname>
                            <given-names>B</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Olsen</surname>
                            <given-names>HP</given-names>
                        </name>
</person-group>:
                    <article-title>Trustworthy AI.</article-title>
                    <source>

                        <italic toggle="yes">Technol. Regul.</italic>
</source>
                    <year>Oct. 2023</year>;<volume>2023</volume>:<fpage>58</fpage>&#x2013;<lpage>68</lpage>.
                    <pub-id pub-id-type="doi">10.71265/PZTSVW73</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref11">
                <label>11</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Herzog</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Blank</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Stahl</surname>
                            <given-names>BC</given-names>
                        </name>
</person-group>:
                    <article-title>Towards trustworthy medical AI ecosystems - a proposal for supporting responsible innovation practices in AI-based medical innovation.</article-title>
                    <source>

                        <italic toggle="yes">AI Soc.</italic>
</source>
                    <year>Apr. 2025</year>;<volume>40</volume>(<issue>4</issue>):<fpage>2119</fpage>&#x2013;<lpage>2139</lpage>.
                    <pub-id pub-id-type="doi">10.1007/S00146-024-02082-Z</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref12">
                <label>12</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Budnik</surname>
                            <given-names>C</given-names>
                        </name>
</person-group>:
                    <article-title>Can We Trust Artificial Intelligence?</article-title>
                    <source>

                        <italic toggle="yes">Philos. &amp;amp; Technol.</italic>
</source>
                    <year>Mar. 2025</year>;<volume>38</volume>(<issue>1</issue>).
                    <pub-id pub-id-type="doi">10.1007/S13347-024-00820-1</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref13">
                <label>13</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Adhikari</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Thapaliya</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>An Overview of AI Applications in Cybersecurity for IT Management.</article-title>
                    <source>

                        <italic toggle="yes">NPRC J. Multidiscip. Res.</italic>
</source>
                    <year>Oct. 2024</year>;<volume>1</volume>(<issue>4</issue>):<fpage>121</fpage>&#x2013;<lpage>133</lpage>.
                    <pub-id pub-id-type="doi">10.3126/NPRCJMR.V1I4.70951</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref14">
                <label>14</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Veritti</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Rubinato</surname>
                            <given-names>L</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sarao</surname>
                            <given-names>V</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Behind the mask: a critical perspective on the ethical, moral, and legal implications of AI in ophthalmology.</article-title>
                    <source>

                        <italic toggle="yes">Graefes Arch. Clin. Exp. Ophthalmol.</italic>
</source>
                    <year>Mar. 2024</year>;<volume>262</volume>(<issue>3</issue>):<fpage>975</fpage>&#x2013;<lpage>982</lpage>.
                    <pub-id pub-id-type="doi">10.1007/S00417-023-06245-4</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref15">
                <label>15</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Afzal</surname>
                            <given-names>MNI</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Shohan</surname>
                            <given-names>AHN</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Siddiqui</surname>
                            <given-names>S</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Application of AI on Human Resource Management: A Review.</article-title>
                    <source>

                        <italic toggle="yes">J. Hum. Resour. Manag. - HR Adv. Dev.</italic>
</source>
                    <year>Aug. 2023</year>;<volume>2023</volume>(<issue>1</issue>):<fpage>1</fpage>&#x2013;<lpage>11</lpage>.
                    <pub-id pub-id-type="doi">10.46287/FHEV4889</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref16">
                <label>16</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Smith</surname>
                            <given-names>GK</given-names>
                        </name>
</person-group>:
                    <article-title>Strategic Integration of Generative AI: Opportunities, Challenges, and Organizational Impacts.</article-title>
                    <source>

                        <italic toggle="yes">Law, Econ. Soc.</italic>
</source>
                    <year>May 2025</year>;<volume>1</volume>(<issue>1</issue>):<fpage>p156</fpage>.
                    <pub-id pub-id-type="doi">10.30560/LES.V1N1P156</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref17">
                <label>17</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Byrne</surname>
                            <given-names>JA</given-names>
                        </name>
</person-group>:
                    <article-title>Improving the peer review of narrative literature reviews.</article-title>
                    <source>

                        <italic toggle="yes">Res. Integr. Peer Rev.</italic>
</source>
                    <year>Dec. 2016</year>;<volume>1</volume>(<issue>1</issue>):<fpage>12</fpage>.
                    <pub-id pub-id-type="pmid">29451529</pub-id>
                    <pub-id pub-id-type="doi">10.1186/S41073-016-0019-2</pub-id>
                    <pub-id pub-id-type="pmcid">PMC5803579</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref18">
                <label>18</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Sapkota</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Roumeliotis</surname>
                            <given-names>KI</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Karkee</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <article-title>AI Agents vs. Agentic AI: A Conceptual Taxonomy, Applications and Challenges.</article-title>
                    <year>2025</year>. Accessed: Aug. 02, 2025.</mixed-citation>
            </ref>
            <ref id="ref19">
                <label>19</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Singh</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ehtesham</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kumar</surname>
                            <given-names>S</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Enhancing AI Systems with Agentic Workflows Patterns in Large Language Model</chapter-title>
                    <source>

                        <italic toggle="yes">2024 IEEE World AI IoT Congr.</italic>
</source>
                    <year>2024</year>; pp.<fpage>527</fpage>&#x2013;<lpage>532</lpage>.
                    <pub-id pub-id-type="doi">10.1109/AIIOT61789.2024.10578990</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref20">
                <label>20</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Bousetouane</surname>
                            <given-names>F</given-names>
                        </name>
</person-group>:
                    <article-title>Agentic Systems: A Guide to Transforming Industries with Vertical AI Agents.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2501.0</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2501.00881</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref21">
                <label>21</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Saleh</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Tarkoma</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Donta</surname>
                            <given-names>P</given-names>
                        </name>
</person-group>:
                    <article-title>Usercentrix: An agentic memory-augmented ai framework for smart spaces.</article-title>
                    <source>

                        <italic toggle="yes">arxiv.org A Saleh, S Tarkoma, PK Donta, NH Motlagh, S Dustdar, S Pirttikangas, L Lov&#x00e9;narXiv Prepr. arXiv2505.00472, 2025&#x2022;arxiv.org.</italic>
</source>
                    <year>2025</year>. Accessed: Aug. 02, 2025.
                    <ext-link ext-link-type="uri" xlink:href="https://arxiv.org/abs/2505.00472">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref22">
                <label>22</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Dai</surname>
                            <given-names>L</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Jiang</surname>
                            <given-names>YH</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Chen</surname>
                            <given-names>Y</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Agent4EDU: Advancing AI for Education with Agentic Workflows</chapter-title>
                    <source>

                        <italic toggle="yes">Proc. 2024 3rd Int. Conf. Artif. Intell. Educ.</italic>
</source>
                    <year>Apr. 2025</year>; pp.<fpage>180</fpage>&#x2013;<lpage>185</lpage>.
                    <pub-id pub-id-type="doi">10.1145/3722237.3722268</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref23">
                <label>23</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Zhao</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Jin</surname>
                            <given-names>Z</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Cheng</surname>
                            <given-names>N</given-names>
                        </name>
</person-group>:
                    <article-title>An In-depth Survey of Large Language Model-based Artificial Intelligence Agents.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2023</year>;<volume>abs/2309.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2309.14365</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref24">
                <label>24</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Saleh</surname>
                            <given-names>A</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>UserCentrix: An Agentic Memory-augmented AI Framework for Smart Spaces.</article-title>
                    <year>May 2025</year>. Accessed: Aug. 02, 2025.
                    <ext-link ext-link-type="uri" xlink:href="http://arxiv.org/abs/2505.00472">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref25">
                <label>25</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Fourney</surname>
                            <given-names>A</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Magentic-One: A Generalist Multi-Agent System for Solving Complex Tasks.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2024</year>;<volume>abs/2411.0</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2411.04468</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref26">
                <label>26</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Chawla</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Chatterjee</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Gadadinni</surname>
                            <given-names>SS</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Agentic AI: The building blocks of sophisticated AI business applications.</article-title>
                    <source>

                        <italic toggle="yes">J. AI, Robot. &amp;amp; Work. Autom.</italic>
</source>
                    <year>Sep. 2024</year>;<volume>3</volume>(<issue>3</issue>):<fpage>196</fpage>.
                    <pub-id pub-id-type="doi">10.69554/XEHZ1946</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref27">
                <label>27</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Manheim</surname>
                            <given-names>D</given-names>
                        </name>
</person-group>:
                    <article-title>Overoptimization Failures and Specification Gaming in Multi-agent Systems.</article-title>
                    <source>

                        <italic toggle="yes">Big Data Cogn. Comput.</italic>
</source>
                    <year>2019</year>;<volume>3</volume>(<issue>2</issue>):<fpage>1</fpage>&#x2013;<lpage>15</lpage>.
                    <pub-id pub-id-type="doi">10.3390/BDCC3020021</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref28">
                <label>28</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Tallam</surname>
                            <given-names>K</given-names>
                        </name>
</person-group>:
                    <article-title>Alignment, Agency and Autonomy in Frontier AI: A Systems Engineering Perspective.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2503.0</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2503.05748</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref29">
                <label>29</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Witt</surname>
                            <given-names>C</given-names>
                            <prefix>de</prefix>
                        </name>
</person-group>:
                    <article-title>Open challenges in multi-agent security: Towards secure systems of interacting ai agents.</article-title>
                    <year>2025</year>. Accessed: Aug. 02, 2025.
                    <ext-link ext-link-type="uri" xlink:href="http://arxiv.org">Reference Source</ext-link>
                    <ext-link ext-link-type="uri" xlink:href="https://arxiv.org/abs/2505.02077">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref30">
                <label>30</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Balachandar</surname>
                            <given-names>N</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Dieter</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ramachandran</surname>
                            <given-names>GS</given-names>
                        </name>
</person-group>:
                    <article-title>Collaboration of AI Agents via Cooperative Multi-Agent Deep Reinforcement Learning.</article-title>
                    <year>Jun. 2019</year>. Accessed: Aug. 02, 2025.
                    <ext-link ext-link-type="uri" xlink:href="https://arxiv.org/pdf/1907.00327">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref31">
                <label>31</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Chenna</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>Exploring the Synergy of Generative and Distributed AI in Multi-agent Systems.</article-title>
                    <source>

                        <italic toggle="yes">SSRN Electron. J.</italic>
</source>
                    <year>2023</year>.
                    <pub-id pub-id-type="doi">10.2139/SSRN.4617662</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref32">
                <label>32</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Manjunath Kamath</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Samata Mehta</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Akshaya</surname>
                            <given-names>HL</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Neuromorphic-Driven Agentic AI for Autonomous Decision-Making Systems</chapter-title>
                    <source>

                        <italic toggle="yes">2024 4th Int. Conf. Mob. Networks Wirel. Commun.</italic>
</source>
                    <year>2024</year>; pp.<fpage>1</fpage>&#x2013;<lpage>8</lpage>.
                    <pub-id pub-id-type="doi">10.1109/ICMNWC63764.2024.10872131</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref33">
                <label>33</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Balasubramani</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Biradar</surname>
                            <given-names>VG</given-names>
                        </name>
</person-group>:
                    <chapter-title>Empowering Autonomous Decision-Making Through Quantum Reinforcement Learning and Cognitive Neuromorphic Frameworks</chapter-title>
                    <source>

                        <italic toggle="yes">2024 4th Int. Conf. Mob. Networks Wirel. Commun.</italic>
</source>
                    <year>2024</year>; pp.<fpage>1</fpage>&#x2013;<lpage>7</lpage>.
                    <pub-id pub-id-type="doi">10.1109/ICMNWC63764.2024.10872223</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref34">
                <label>34</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Freire</surname>
                            <given-names>IT</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Arsiwalla</surname>
                            <given-names>XD</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Puigb&#x00f2;</surname>
                            <given-names>JY</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Modeling Theory of Mind in Dyadic Games Using Adaptive Feedback Control.</article-title>
                    <source>

                        <italic toggle="yes">Inf.</italic>
</source>
                    <year>Aug. 2023</year>;<volume>14</volume>(<issue>8</issue>).
                    <pub-id pub-id-type="doi">10.3390/INFO14080441</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref35">
                <label>35</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ivanov</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>D&#x00fc;tting</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Talgam-Cohen</surname>
                            <given-names>I</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Principal-Agent Reinforcement Learning: Orchestrating AI Agents with Contracts.</article-title>
                    <year>2024</year>.</mixed-citation>
            </ref>
            <ref id="ref36">
                <label>36</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Freire</surname>
                            <given-names>I</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Arsiwalla</surname>
                            <given-names>X</given-names>
                        </name>

                        <collab>J. P. preprint arXiv, and undefined 2019</collab>
</person-group>:
                    <article-title>Modeling theory of mind in multi-agent games using adaptive feedback control.</article-title>
                    <source>

                        <italic toggle="yes">IT Freire, XD Arsiwalla, JY Puigb&#x00f2;, P VerschurearXiv Prepr. arXiv1905.13225, 2019&#x2022;arxiv.org.</italic>
</source>
                    <year>2019</year>. Accessed: Aug. 02, 2025.
                    <ext-link ext-link-type="uri" xlink:href="http://arxiv.org">Reference Source</ext-link>
                    <ext-link ext-link-type="uri" xlink:href="https://arxiv.org/abs/1905.13225">https://arxiv.org/abs/1905.13225</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref37">
                <label>37</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Thoom</surname>
                            <given-names>SR</given-names>
                        </name>
</person-group>:
                    <article-title>Understanding Agentic Frameworks in AI Development: A Technical Analysis.</article-title>
                    <source>

                        <italic toggle="yes">Int. J. Sci. Res. Comput. Sci. Eng. Inf. Technol.</italic>
</source>
                    <year>2025</year>;<volume>11</volume>(<issue>1</issue>):<fpage>518</fpage>&#x2013;<lpage>527</lpage>.
                    <pub-id pub-id-type="doi">10.32628/CSEIT25111249</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref38">
                <label>38</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Langley</surname>
                            <given-names>P</given-names>
                        </name>
</person-group>:
                    <article-title>An cognitive architectures and the construction of intelligent agents.</article-title>
                    <source>

                        <italic toggle="yes">P LangleyProc. Work. Intell. Agent Archit. 2004&#x2022;cdn.aaai.org.</italic>
</source>
                    <year>2024</year>. Accessed: Aug. 02, 2025
                    <ext-link ext-link-type="uri" xlink:href="http://cdn.aaai.org">Reference Source</ext-link>
                    <ext-link ext-link-type="uri" xlink:href="https://cdn.aaai.org/Workshops/2004/WS-04-07/WS04-07-014.pdf">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref39">
                <label>39</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Slaoui</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>S-AI: A Sparse Artificial Intelligence System Orchestrated by a Hormonal MetaAgent and Context-Aware Specialized Agents.</article-title>
                    <source>

                        <italic toggle="yes">Int. J. Multidiscip. Res.</italic>
</source>
                    <year>Apr. 2025</year>;<volume>7</volume>(<issue>2</issue>).
                    <pub-id pub-id-type="doi">10.36948/IJFMR.2025.V07I02.42035</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref40">
                <label>40</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Liu</surname>
                            <given-names>B</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Advances and Challenges in Foundation Agents: From Brain-Inspired Intelligence to Evolutionary, Collaborative, and Safe Systems.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2504.0</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2504.01990</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref41">
                <label>41</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Klejnowski</surname>
                            <given-names>L</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Bernard</surname>
                            <given-names>Y</given-names>
                        </name>

                        <name name-style="western">
                            <surname>H&#x00e4;hner</surname>
                            <given-names>J</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>An Architecture for Trust-Adaptive Agents</chapter-title>
                    <source>

                        <italic toggle="yes">2010 Fourth IEEE Int. Conf. Self-Adaptive Self-Organizing Syst. Work.</italic>
</source>
                    <year>2010</year>; pp.<fpage>178</fpage>&#x2013;<lpage>183</lpage>.
                    <pub-id pub-id-type="doi">10.1109/SASOW.2010.37</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref42">
                <label>42</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Satav</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>Enterprise API &amp; Platform Strategy in the era of Agentic AI.</article-title>
                    <source>

                        <italic toggle="yes">J. Comput. Sci. Technol. Stud.</italic>
</source>
                    <year>Mar. 2025</year>;<volume>7</volume>(<issue>1</issue>):<fpage>380</fpage>&#x2013;<lpage>385</lpage>.
                    <pub-id pub-id-type="doi">10.32996/JCSTS.2025.7.1.28</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref43">
                <label>43</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Rakshit</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Konar</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>Agents and Multi-agent Coordination.</article-title>
                    <year>2018</year>;<fpage>57</fpage>&#x2013;<lpage>88</lpage>.
                    <pub-id pub-id-type="doi">10.1007/978-981-10-8642-7_2</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref44">
                <label>44</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Joshi</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>Advancing innovation in financial stability: A comprehensive review of ai agent frameworks, challenges and applications.</article-title>
                    <source>

                        <italic toggle="yes">World J. Adv. Eng. Technol. Sci.</italic>
</source>
                    <year>Feb. 2025</year>;<volume>14</volume>(<issue>2</issue>):<fpage>117</fpage>&#x2013;<lpage>126</lpage>.
                    <pub-id pub-id-type="doi">10.30574/WJAETS.2025.14.2.0071</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref45">
                <label>45</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Lesser</surname>
                            <given-names>VR</given-names>
                        </name>
</person-group>:
                    <article-title>Reflections on the Nature of Multi-Agent Coordination and Its Implications for an Agent Architecture.</article-title>
                    <source>

                        <italic toggle="yes">Auton. Agent. Multi-Agent Syst.</italic>
</source>
                    <year>1998</year>;<volume>1</volume>(<issue>1</issue>):<fpage>89</fpage>&#x2013;<lpage>111</lpage>.
                    <pub-id pub-id-type="doi">10.1023/A:1010046623013</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref46">
                <label>46</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Du</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Zhang</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hu</surname>
                            <given-names>Y</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Blockchain for Distributed Consistency: A Cliquebased Framework for Multi-agent Systems</chapter-title>
                    <source>

                        <italic toggle="yes">2021 7th Int. Conf. Big Data Inf. Anal.</italic>
</source>
                    <year>2021</year>; pp.<fpage>421</fpage>&#x2013;<lpage>427</lpage>.
                    <pub-id pub-id-type="doi">10.1109/BIGDIA53151.2021.9619656</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref47">
                <label>47</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Yang</surname>
                            <given-names>T</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Liu</surname>
                            <given-names>Y</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Yang</surname>
                            <given-names>X</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>A Blockchain based Smart Agent System Architecture</chapter-title>
                    <source>

                        <italic toggle="yes">Proc. 4th Int. Conf. Crowd Sci. Eng.</italic>
</source>
                    <year>Oct. 2019</year>; pp.<fpage>33</fpage>&#x2013;<lpage>39</lpage>.
                    <pub-id pub-id-type="doi">10.1145/3371238.3371244</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref48">
                <label>48</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Pokhrel</surname>
                            <given-names>SR</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Yang</surname>
                            <given-names>L</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Rajasegarar</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Li</surname>
                            <given-names>G</given-names>
                        </name>
</person-group>:
                    <chapter-title>Robust Zero Trust Architecture: Joint Blockchain based Federated learning and Anomaly Detection based Framework</chapter-title>
                    <source>

                        <italic toggle="yes">Proc. SIGCOMM Work. Zero Trust Archit. Next Gener. Commun.</italic>
</source>
                    <year>Aug. 2024</year>; pp.<fpage>7</fpage>&#x2013;<lpage>12</lpage>.
                    <pub-id pub-id-type="doi">10.1145/3672200.3673878</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref49">
                <label>49</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mishra</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Tandon</surname>
                            <given-names>DR</given-names>
                        </name>
</person-group>:
                    <article-title>Federated Learning in Healthcare: A Path Towards Decentralized and Secure Medical Insights.</article-title>
                    <source>

                        <italic toggle="yes">INTERANTIONAL J. Sci. Res. Eng. Manag.</italic>
</source>
                    <year>Oct. 2024</year>;<volume>08</volume>(<issue>10</issue>):<fpage>1</fpage>&#x2013;<lpage>15</lpage>.
                    <pub-id pub-id-type="doi">10.55041/IJSREM37791</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref50">
                <label>50</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Kiran</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kumar</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Chukkala</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>Decentralized AI at the Edge: Federated Learning, Quantum Optimization and IoT Scalability.</article-title>
                    <source>

                        <italic toggle="yes">Int. J. Sci. Res. Arch.</italic>
</source>
                    <year>Mar. 2025</year>;<volume>14</volume>(<issue>3</issue>):<fpage>256</fpage>&#x2013;<lpage>263</lpage>.
                    <pub-id pub-id-type="doi">10.30574/IJSRA.2025.14.3.0633</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref51">
                <label>51</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Tariq</surname>
                            <given-names>A</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Trustworthy Federated Learning: A Comprehensive Review, Architecture, Key Challenges, and Future Research Prospects.</article-title>
                    <source>

                        <italic toggle="yes">IEEE Open J. Commun. Soc.</italic>
</source>
                    <year>2024</year>;<volume>5</volume>:<fpage>4920</fpage>&#x2013;<lpage>4998</lpage>.
                    <pub-id pub-id-type="doi">10.1109/OJCOMS.2024.3438264</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref52">
                <label>52</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mabina</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Mbotho</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>A Hybrid Framework for Securing 5G-Enabled Healthcare Systems.</article-title>
                    <source>

                        <italic toggle="yes">Stud. Med. Heal. Sci.</italic>
</source>
                    <year>Jan. 2025</year>;<volume>2</volume>(<issue>1</issue>).
                    <pub-id pub-id-type="doi">10.48185/SMHS.V2I1.1447</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref53">
                <label>53</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Echezona</surname>
                            <given-names>U</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Emmanuel</surname>
                            <given-names>I</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Motilol</surname>
                            <given-names>OT</given-names>
                        </name>
</person-group>:
                    <article-title>Analyzing Edge AI Deployment Challenges with in Hybrid IT Systems Utilizing Containerization and Blockchain-Based Data Provenance Solutions.</article-title>
                    <source>

                        <italic toggle="yes">Int. J. Sci. Res. Mod. Technol.</italic>
</source>
                    <year>2024</year>;<fpage>125</fpage>&#x2013;<lpage>141</lpage>.
                    <pub-id pub-id-type="doi">10.38124/IJSRMT.V3I12.408</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref54">
                <label>54</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Karim</surname>
                            <given-names>MM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Van</surname>
                            <given-names>DH</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Khan</surname>
                            <given-names>S</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>AI Agents Meet Blockchain: A Survey on Secure and Scalable Collaboration for Multi-Agents.</article-title>
                    <source>

                        <italic toggle="yes">Futur. Internet.</italic>
</source>
                    <year>Feb. 2025</year>;<volume>17</volume>(<issue>2</issue>).
                    <pub-id pub-id-type="doi">10.3390/FI17020057</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref55">
                <label>55</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Liu</surname>
                            <given-names>Y</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>SharHSC: A Sharding-Based Hybrid State Channel to Realize Blockchain Scalability and Security.</article-title>
                    <source>

                        <italic toggle="yes">IEEE Trans. Dependable Secur. Comput.</italic>
</source>
                    <year>2025</year>;<volume>22</volume>(<issue>3</issue>):<fpage>2705</fpage>&#x2013;<lpage>2722</lpage>.
                    <pub-id pub-id-type="doi">10.1109/TDSC.2024.3521437</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref56">
                <label>56</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Barros</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>Trusted Identities for AI Agents: Leveraging Telco-Hosted eSIM Infrastructure.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2504.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2504.16108</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref57">
                <label>57</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Villegas-Ch</surname>
                            <given-names>W</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Govea</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Gutierrez</surname>
                            <given-names>R</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Optimizing Security in IoT Ecosystems Using Hybrid Artificial Intelligence and Blockchain Models: A Scalable and Efficient Approach for Threat Detection.</article-title>
                    <source>

                        <italic toggle="yes">IEEE Access.</italic>
</source>
                    <year>2025</year>;<volume>13</volume>:<fpage>16933</fpage>&#x2013;<lpage>16958</lpage>.
                    <pub-id pub-id-type="doi">10.1109/ACCESS.2025.3532800</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref58">
                <label>58</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Witt</surname>
                            <given-names>CS</given-names>
                            <prefix>de</prefix>
                        </name>
</person-group>:
                    <article-title>Open Challenges in Multi-Agent Security: Towards Secure Systems of Interacting AI Agents.</article-title>
                    <year>May 2025</year>. Accessed: Aug. 05, 2025
                    <ext-link ext-link-type="uri" xlink:href="https://arxiv.org/pdf/2505.02077">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref59">
                <label>59</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>&#x0160;ekrst</surname>
                            <given-names>K</given-names>
                        </name>
</person-group>:
                    <article-title>Chinese Chat Room: AI Hallucinations, Epistemology and Cognition.</article-title>
                    <source>

                        <italic toggle="yes">Stud. Logic, Gramm. Rhetor.</italic>
</source>
                    <year>Dec. 2024</year>;<volume>69</volume>(<issue>1</issue>):<fpage>365</fpage>&#x2013;<lpage>381</lpage>.
                    <pub-id pub-id-type="doi">10.2478/SLGR-2024-0029</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref60">
                <label>60</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Tlaie</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>Using AI Alignment Theory to understand the potential pitfalls of regulatory frameworks.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2024</year>;<volume>abs/2410.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2410.19749</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref61">
                <label>61</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Silva Oliveira</surname>
                            <given-names>DG</given-names>
                            <prefix>da</prefix>
                        </name>
</person-group>:
                    <article-title>Exploring the Risks of General-Purpose AI: The Role of the Brain&#x2019;s Reward Mechanism and Nearsighted Goals in Processes of Decision-Makings.</article-title>
                    <source>

                        <italic toggle="yes">Commun. Comput. Inf. Sci.</italic>
</source>
                    <year>2025</year>;<volume>2134</volume>:<fpage>261</fpage>&#x2013;<lpage>267</lpage>.
                    <pub-id pub-id-type="doi">10.1007/978-3-031-74627-7_19</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref62">
                <label>62</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Li</surname>
                            <given-names>H</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Principe</surname>
                            <given-names>J</given-names>
                        </name>
</person-group>:
                    <chapter-title>Speeding Up Reinforcement Learning by Exploiting Causality in Reward Sequences</chapter-title>
                    <source>

                        <italic toggle="yes">2021 Int. Jt. Conf. Neural Networks.</italic>
</source>
                    <year>Jul. 2021</year>; vol.<volume>2021-July</volume>: pp.<fpage>1</fpage>&#x2013;<lpage>6</lpage>.
                    <pub-id pub-id-type="doi">10.1109/IJCNN52387.2021.9533910</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref63">
                <label>63</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Patlan</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sheng</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hebbar</surname>
                            <given-names>S</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Real ai agents with fake memories: Fatal context manipulation attacks on web3 agents.</article-title>
                    <year>2025</year>. 2025, Accessed: Aug. 03, 2025.
                    <ext-link ext-link-type="uri" xlink:href="http://arxiv.org">Reference Source</ext-link>
                    <ext-link ext-link-type="uri" xlink:href="https://arxiv.org/abs/2503.16248">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref64">
                <label>64</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Zhang</surname>
                            <given-names>Y</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Chen</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Jiang</surname>
                            <given-names>X</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Towards Action Hijacking of Large Language Model-based Agent.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2024</year>;<volume>abs/2412.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2412.10807</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref65">
                <label>65</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Asadi</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ruadulescu</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Now&#x2019;e</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>Explainable AI Based Diagnosis of Poisoning Attacks in Evolutionary Swarms.</article-title>
                    <year>2025</year>.
                    <pub-id pub-id-type="doi">10.1145/3712255.3726576</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref66">
                <label>66</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Hossain</surname>
                            <given-names>MT</given-names>
                        </name>

                        <name name-style="western">
                            <surname>La</surname>
                            <given-names>H</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Badsha</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>RAMPART: Reinforcing Autonomous Multi-Agent Protection through Adversarial Resistance in Transportation.</article-title>
                    <source>

                        <italic toggle="yes">J. Auton. Transp. Syst.</italic>
</source>
                    <year>Dec. 2024</year>;<volume>1</volume>(<issue>4</issue>):<fpage>1</fpage>&#x2013;<lpage>25</lpage>.
                    <pub-id pub-id-type="doi">10.1145/3643137</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref67">
                <label>67</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Jiao</surname>
                            <given-names>R</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>CAN WE TRUST EMBODIED AGENTS? EXPLORING BACKDOOR ATTACKS AGAINST EMBODIED LLM-BASED DECISION-MAKING SYSTEMS.</article-title>
                    <year>2025</year>.</mixed-citation>
            </ref>
            <ref id="ref68">
                <label>68</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Pan</surname>
                            <given-names>X</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hahami</surname>
                            <given-names>E</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Zhang</surname>
                            <given-names>Z</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Memorization and Knowledge Injection in Gated LLMs.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2504.2</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2504.21239</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref69">
                <label>69</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Sengupta</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>Securing the Autonomous Future A Comprehensive Analysis of Security Challenges and Mitigation Strategies for AI Agents.</article-title>
                    <source>

                        <italic toggle="yes">INTERANTIONAL J. Sci. Res. Eng. Manag.</italic>
</source>
                    <year>2024</year>;<volume>08</volume>(<issue>12</issue>):<fpage>1</fpage>&#x2013;<lpage>2</lpage>.
                    <pub-id pub-id-type="doi">10.55041/IJSREM40091</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref70">
                <label>70</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Shi</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Yuan</surname>
                            <given-names>Z</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Tie</surname>
                            <given-names>G</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Prompt Injection Attack to Tool Selection in LLM Agents.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2504.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2504.19793</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref71">
                <label>71</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Rossi</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Michel</surname>
                            <given-names>AM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Mukkamala</surname>
                            <given-names>R</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>An Early Categorization of Prompt Injection Attacks on Large Language Models.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2024</year>;<volume>abs/2402.0</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2402.00898</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref72">
                <label>72</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Lee</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Tiwari</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <article-title>Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2024</year>;<volume>abs/2410.0</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2410.07283</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref73">
                <label>73</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Zhan</surname>
                            <given-names>Q</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Liang</surname>
                            <given-names>Z</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ying</surname>
                            <given-names>Z</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents.</article-title>
                    <year>2024</year>;<fpage>10471</fpage>&#x2013;<lpage>10506</lpage>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2403.02691</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref74">
                <label>74</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Nakash</surname>
                            <given-names>I</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kour</surname>
                            <given-names>G</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Uziel</surname>
                            <given-names>G</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Breaking ReAct Agents: Foot-in-the-Door Attack Will Get You In.</article-title>
                    <year>2024</year>;<fpage>6484</fpage>&#x2013;<lpage>6509</lpage>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2410.16950</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref75">
                <label>75</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Zhu</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Yang</surname>
                            <given-names>X</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Wang</surname>
                            <given-names>J</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents.</article-title>
                    <year>2025</year>. Accessed: Aug. 03, 2025
                    <ext-link ext-link-type="uri" xlink:href="https://arxiv.org/pdf/2502.05174">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref76">
                <label>76</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Narajala</surname>
                            <given-names>VS</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Narayan</surname>
                            <given-names>O</given-names>
                        </name>
</person-group>:
                    <article-title>Securing Agentic AI: A Comprehensive Threat Model and Mitigation Framework for Generative AI Agents.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2504.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2504.19956</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref77">
                <label>77</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Shaikh</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Oliveira</surname>
                            <given-names>D</given-names>
                        </name>
</person-group>:
                    <chapter-title>Shadow-IT system and Insider Threat: Opportunity as a Situational Perspective</chapter-title>
                    <source>

                        <italic toggle="yes">Conf. Proc. - IEEE SOUTHEASTCON.</italic>
</source>
                    <year>Apr. 2019</year>; vol.<volume>2019-April</volume>.
                    <pub-id pub-id-type="doi">10.1109/SOUTHEASTCON42311.2019.9020557</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref78">
                <label>78</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Akello</surname>
                            <given-names>P</given-names>
                        </name>
</person-group>:
                    <article-title>Volitional non-malicious insider threats: At the intersection of COVID-19, WFH and cloud-facilitated shadow-apps.</article-title>
                    <year>2021</year>. Accessed: Aug. 03, 2025.
                    <ext-link ext-link-type="uri" xlink:href="https://aisel.aisnet.org/amcis2021/info_security/info_security/9/">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref79">
                <label>79</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Wu</surname>
                            <given-names>Z</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>LibVulnWatch: A Deep Assessment Agent System and Leaderboard for Uncovering Hidden Vulnerabilities in Open-Source AI Libraries.</article-title>
                    <source>

                        <italic toggle="yes">Z Wu, S Cho, U Mohammed, C Munoz, K Costa, X Guan, T King, Z Wang, E KazimarXiv Prepr. arXiv2505.08842, 2025&#x2022;arxiv.org.</italic>
</source>
                    <year>2025</year>. Accessed: Aug. 03, 2025.
                    <ext-link ext-link-type="uri" xlink:href="http://arxiv.org">Reference Source</ext-link>
                    <ext-link ext-link-type="uri" xlink:href="https://arxiv.org/abs/2505.08842">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref80">
                <label>80</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Cui</surname>
                            <given-names>X</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Gasior</surname>
                            <given-names>W</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Beaver</surname>
                            <given-names>J</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>ShadowNet: An Active Defense Infrastructure for Insider Cyber Attack Prevention</chapter-title>
                    <source>

                        <italic toggle="yes">Lect. Notes Comput. Sci. (including Subser. Lect. Notes Artif. Intell. Lect. Notes Bioinformatics).</italic>
</source>
                    <year>2012</year>; vol.<volume>7336 LNCS</volume>(<issue>PART 4</issue>): pp.<fpage>646</fpage>&#x2013;<lpage>653</lpage>.
                    <pub-id pub-id-type="doi">10.1007/978-3-642-31128-4_48</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref81">
                <label>81</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Calzada</surname>
                            <given-names>I</given-names>
                        </name>

                        <name name-style="western">
                            <surname>N&#x00e9;meth</surname>
                            <given-names>G</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Al-Radhi</surname>
                            <given-names>MS</given-names>
                        </name>
</person-group>:
                    <article-title>Trustworthy AI for Whom? GenAI Detection Techniques of Trust Through Decentralized Web3 Ecosystems.</article-title>
                    <source>

                        <italic toggle="yes">Big Data Cogn. Comput.</italic>
</source>
                    <year>Mar. 2025</year>;<volume>9</volume>(<issue>3</issue>).
                    <pub-id pub-id-type="doi">10.3390/BDCC9030062</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref82">
                <label>82</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Sutcliffe</surname>
                            <given-names>HR</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Brown</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>Trust and Soft Law for AI.</article-title>
                    <source>

                        <italic toggle="yes">IEEE Technol. Soc. Mag.</italic>
</source>
                    <year>Dec. 2021</year>;<volume>40</volume>(<issue>4</issue>):<fpage>14</fpage>&#x2013;<lpage>24</lpage>.
                    <pub-id pub-id-type="doi">10.1109/MTS.2021.3123741</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref83">
                <label>83</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Zhang</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Bentahar</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Falcone</surname>
                            <given-names>R</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Introduction to the Special Section on Trust and AI.</article-title>
                    <source>

                        <italic toggle="yes">ACM Trans. Internet Technol.</italic>
</source>
                    <year>Nov. 2019</year>;<volume>19</volume>(<issue>4</issue>):<fpage>1</fpage>&#x2013;<lpage>3</lpage>.
                    <pub-id pub-id-type="doi">10.1145/3365675</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref84">
                <label>84</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Yousseef</surname>
                            <given-names>A</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Autonomous Vehicle Security: A Deep Dive into Threat Modeling.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2024</year>;<volume>abs/2412.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2412.15348</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref85">
                <label>85</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Tallam</surname>
                            <given-names>K</given-names>
                        </name>
</person-group>:
                    <article-title>Engineering Risk-Aware, Security-by-Design Frameworks for Assurance of Large-Scale Autonomous AI Models.</article-title>
                    <source>

                        <italic toggle="yes">K TallamarXiv Prepr. arXiv2505.06409, 2025&#x2022;arxiv.org.</italic>
</source>
                    <year>2025</year>. Accessed: Aug. 03, 2025
                    <ext-link ext-link-type="uri" xlink:href="http://arxiv.org">Reference Source</ext-link>
                    <ext-link ext-link-type="uri" xlink:href="https://arxiv.org/abs/2505.06409">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref87">
                <label>86</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Lievin</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Jamont</surname>
                            <given-names>JP</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hely</surname>
                            <given-names>D</given-names>
                        </name>
</person-group>:
                    <chapter-title>CLASA: a Cross-Layer Agent Security Architecture for networked embedded systems</chapter-title>
                    <source>

                        <italic toggle="yes">2021 IEEE Int. Conf. Omni-Layer Intell. Syst.</italic>
</source>
                    <year>Aug. 2021</year>; pp.<fpage>1</fpage>&#x2013;<lpage>8</lpage>.
                    <pub-id pub-id-type="doi">10.1109/COINS51742.2021.9524157</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref88">
                <label>87</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Wang</surname>
                            <given-names>B</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Wu</surname>
                            <given-names>Y</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Guo</surname>
                            <given-names>N</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>A cross-layer attack path detection method for smart grid dynamics</chapter-title>
                    <source>

                        <italic toggle="yes">2022 5th Int. Conf. Adv. Electron. Mater. Comput. Softw. Eng.</italic>
</source>
                    <year>2022</year>; pp.<fpage>142</fpage>&#x2013;<lpage>146</lpage>.
                    <pub-id pub-id-type="doi">10.1109/AEMCSE55572.2022.00036</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref89">
                <label>88</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Cirillo</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Di Mauro</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Matta</surname>
                            <given-names>V</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Cyber-Threat Propagation over Network-Slicing Architectures</chapter-title>
                    <source>

                        <italic toggle="yes">ICASSP 2022-2022 IEEE Int. Conf. Acoust. Speech Signal Process.</italic>
</source>
                    <year>2022</year>; vol.<volume>2022-May</volume>: pp.<fpage>2984</fpage>&#x2013;<lpage>2988</lpage>.
                    <pub-id pub-id-type="doi">10.1109/ICASSP43922.2022.9746448</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref90">
                <label>89</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Gandotra</surname>
                            <given-names>V</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Archana Singhal</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Bedi</surname>
                            <given-names>P</given-names>
                        </name>
</person-group>:
                    <article-title>Layered security architecture for threat management using multi-agent system.</article-title>
                    <source>

                        <italic toggle="yes">ACM SIGSOFT Softw. Eng. Notes.</italic>
</source>
                    <year>Sep. 2011</year>;<volume>36</volume>(<issue>5</issue>):<fpage>1</fpage>&#x2013;<lpage>11</lpage>.
                    <pub-id pub-id-type="doi">10.1145/2020976.2020984</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref91">
                <label>90</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Yao</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Jiang</surname>
                            <given-names>Z</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Yan</surname>
                            <given-names>B</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Bayesian and stochastic game joint approach for Cross-Layer optimal defensive Decision-Making in industrial Cyber-Physical systems.</article-title>
                    <source>

                        <italic toggle="yes">Inf. Sci.</italic>
</source>
                    <year>Mar. 2024</year>;<volume>662</volume>:<fpage>120216</fpage>.
                    <pub-id pub-id-type="doi">10.1016/J.INS.2024.120216</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref92">
                <label>91</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Paul</surname>
                            <given-names>EM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Stanley</surname>
                            <given-names>UM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kessie</surname>
                            <given-names>JD</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Adversarial machine learning in cybersecurity: Mitigating evolving threats in AI-powered defense systems.</article-title>
                    <source>

                        <italic toggle="yes">World J. Adv. Eng. Technol. Sci.</italic>
</source>
                    <year>Dec. 2023</year>;<volume>10</volume>(<issue>2</issue>):<fpage>309</fpage>&#x2013;<lpage>325</lpage>.
                    <pub-id pub-id-type="doi">10.30574/WJAETS.2023.10.2.0294</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref93">
                <label>92</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Moharir</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kuppuraju</surname>
                            <given-names>SY</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Patil</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>Adversarial Machine Learning Defenses in AI-Enabled Cybersecurity Systems.</article-title>
                    <source>

                        <italic toggle="yes">Int. J. Multidiscip. Res.</italic>
</source>
                    <year>Apr. 2025</year>;<volume>7</volume>(<issue>2</issue>).
                    <pub-id pub-id-type="doi">10.36948/IJFMR.2025.V07I02.43075</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref94">
                <label>93</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Peter</surname>
                            <given-names>I</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Harnessing adversarial machine learning for advanced threat detection: AI-driven strategies in cybersecurity risk assessment and fraud prevention.</article-title>
                    <source>

                        <italic toggle="yes">Open Access Res. J. Sci. Technol.</italic>
</source>
                    <year>May 2024</year>;<volume>11</volume>(<issue>1</issue>):<fpage>001</fpage>&#x2013;<lpage>004</lpage>.
                    <pub-id pub-id-type="doi">10.53022/OARJST.2024.11.1.0060</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref95">
                <label>94</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Jehan</surname>
                            <given-names>N</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ansari</surname>
                            <given-names>NM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ashraf</surname>
                            <given-names>Z</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Adversarial Machine Learning for Cyber security Defense: Detecting Model Evasion, Poisoning Attacks, and Enhancing the Robustness of AI Systems.</article-title>
                    <source>

                        <italic toggle="yes">Glob. Res. J. Nat. Sci. Technol.</italic>
</source>
                    <year>Apr. 2025</year>;<volume>3</volume>.
                    <pub-id pub-id-type="doi">10.53762/GRJNST.03.02.07</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref96">
                <label>95</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Pasupuleti</surname>
                            <given-names>MK</given-names>
                        </name>
</person-group>:
                    <article-title>Securing AI-driven Infrastructure: Advanced Cybersecurity Frameworks for Cloud and Edge Computing Environments.</article-title>
                    <year>Mar. 2025</year>.
                    <pub-id pub-id-type="doi">10.62311/NESX/RRV225</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref100">
                <label>96</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Chen</surname>
                            <given-names>S</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Blockchain Enabled Intelligence of Federated Systems (BELIEFS): An attack-tolerant trustable distributed intelligence paradigm.</article-title>
                    <source>

                        <italic toggle="yes">Energy Rep.</italic>
</source>
                    <year>2021</year>;<volume>7</volume>:<fpage>8900</fpage>&#x2013;<lpage>8911</lpage>.
                    <pub-id pub-id-type="doi">10.1016/J.EGYR.2021.10.113</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref101">
                <label>97</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Narajala</surname>
                            <given-names>VS</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Huang</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Habler</surname>
                            <given-names>I</given-names>
                        </name>
</person-group>:
                    <article-title>Securing GenAI Multi-Agent Systems Against Tool Squatting: A Zero Trust Registry-Based Approach.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2504.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2504.19951</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref102">
                <label>98</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Timmers</surname>
                            <given-names>P</given-names>
                        </name>
</person-group>:
                    <article-title>Ethics of AI and Cybersecurity When Sovereignty is at Stake.</article-title>
                    <source>

                        <italic toggle="yes">Mind. Mach.</italic>
</source>
                    <year>2019</year>;<volume>29</volume>(<issue>4</issue>):<fpage>635</fpage>&#x2013;<lpage>645</lpage>.
                    <pub-id pub-id-type="doi">10.1007/S11023-019-09508-4</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref103">
                <label>99</label>
                <mixed-citation publication-type="journal">
                    <collab>OECD</collab>:
                    <article-title>OECD Framework for the Classification of AI systems.</article-title>
                    <source>

                        <italic toggle="yes">OECD Digit. Econ. Pap.</italic>
</source>
                    <year>Feb. 2022</year>;<volume>323</volume>.
                    <pub-id pub-id-type="doi">10.1787/CB6D9ECA-EN</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref104">
                <label>100</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Struensee</surname>
                            <given-names>S</given-names>
                            <prefix>von</prefix>
                        </name>
</person-group>:
                    <article-title>Analyzing Dilemmas Posed by Artificial Intelligence and 4IR Technologies Requires using all Available Models, Including the Existing International Human Rights Framework and Principles of AI Ethics.</article-title>
                    <source>

                        <italic toggle="yes">SSRN Electron. J.</italic>
</source>
                    <year>Jul. 2021</year>.
                    <pub-id pub-id-type="doi">10.2139/SSRN.3874279</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref105">
                <label>101</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Cancela-Outeda</surname>
                            <given-names>C</given-names>
                        </name>
</person-group>:
                    <article-title>The EU&#x2019;s AI act: A framework for collaborative governance.</article-title>
                    <source>

                        <italic toggle="yes">Internet Things.</italic>
</source>
                    <year>Oct. 2024</year>;<volume>27</volume>:<fpage>101291</fpage>.
                    <pub-id pub-id-type="doi">10.1016/J.IOT.2024.101291</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref106">
                <label>102</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Gasser</surname>
                            <given-names>U</given-names>
                        </name>
</person-group>:
                    <article-title>An EU landmark for AI governance.</article-title>
                    <source>

                        <italic toggle="yes">Science (80-.).</italic>
</source>
                    <year>Jun. 2023</year>;<volume>380</volume>(<issue>6651</issue>):<fpage>1203</fpage>&#x2013;<lpage>1203</lpage>.
                    <pub-id pub-id-type="pmid">37319234</pub-id>
                    <pub-id pub-id-type="doi">10.1126/SCIENCE.ADJ1627</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref107">
                <label>103</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Priyanshu</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Maurya</surname>
                            <given-names>Y</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hong</surname>
                            <given-names>Z</given-names>
                        </name>
</person-group>:
                    <article-title>AI Governance and Accountability: An Analysis of Anthropic&#x2019;s Claude.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2024</year>;<volume>abs/2407.0</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2407.01557</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref108">
                <label>104</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Wodi</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>Artificial Intelligence (AI) Governance: An Overview.</article-title>
                    <source>

                        <italic toggle="yes">SSRN Electron. J.</italic>
</source>
                    <year>2024</year>.
                    <pub-id pub-id-type="doi">10.2139/SSRN.4840769</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref109">
                <label>105</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Chaffer</surname>
                            <given-names>TJ</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Goldston</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Okusanya</surname>
                            <given-names>B</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Decentralized Governance of Autonomous AI Agents.</article-title>
                    <source>

                        <italic toggle="yes">Probl. Polit. Auth.</italic>
</source>
                    <year>2013</year>;<fpage>81</fpage>&#x2013;<lpage>100</lpage>.
                    <pub-id pub-id-type="doi">10.1057/9781137281661_5</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref110">
                <label>106</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Rebera</surname>
                            <given-names>AP</given-names>
                        </name>
</person-group>:
                    <article-title>Reactive Attitudes and AI-Agents &#x2013; Making Sense of Responsibility and Control Gaps.</article-title>
                    <source>

                        <italic toggle="yes">Philos. &amp;amp; Technol.</italic>
</source>
                    <year>Dec. 2024</year>;<volume>37</volume>(<issue>4</issue>).
                    <pub-id pub-id-type="doi">10.1007/S13347-024-00808-X</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref111">
                <label>107</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Kasirzadeh</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Gabriel</surname>
                            <given-names>I</given-names>
                        </name>
</person-group>:
                    <article-title>Characterizing AI Agents for Alignment and Governance.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2504.2</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2504.21848</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref112">
                <label>108</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mukherjee</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Chang</surname>
                            <given-names>H</given-names>
                        </name>
</person-group>:
                    <article-title>Agentic AI: Autonomy, Accountability, and the Algorithmic Society.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2502.0</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2502.00289</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref113">
                <label>109</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Chaffer</surname>
                            <given-names>TJ</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Bayo</surname>
                            <given-names>JG</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Gemach</surname>
                            <given-names>O</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>On the ETHOS of AI Agents: An Ethical Technology and Holistic Oversight System.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2024</year>;<volume>abs/2412.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2412.17114</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref115">
                <label>110</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Huang</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Narajala</surname>
                            <given-names>V</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Habler</surname>
                            <given-names>I</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Agent name service (ans): A universal directory for secure ai agent discovery and interoperability.</article-title>
                    <source>

                        <italic toggle="yes">K Huang, VS Narajala, I Habler, A SheriffarXiv Prepr. arXiv2505.10609, 2025&#x2022;arxiv.org.</italic>
</source>
                    <year>2025</year>. 2025, Accessed: Aug. 04, 2025.
                    <ext-link ext-link-type="uri" xlink:href="http://arxiv.org">Reference Source</ext-link>
                    <ext-link ext-link-type="uri" xlink:href="https://arxiv.org/abs/2505.10609">https://arxiv.org/abs/2505.10609</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref116">
                <label>111</label>
                <mixed-citation publication-type="journal">
                    <collab>OECD</collab>:
                    <article-title>Advancing accountability in AI.</article-title>
                    <source>

                        <italic toggle="yes">OECD Digit. Econ. Pap.</italic>
</source>
                    <year>Feb. 2023</year>;<volume>349</volume>.
                    <pub-id pub-id-type="doi">10.1787/2448F04B-EN</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref117">
                <label>112</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Markovic</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Naja</surname>
                            <given-names>I</given-names>
                        </name>

                        <collab>P. E.-C. W</collab>

                        <etal/>
</person-group>:
                    <article-title>The accountability fabric: A suite of semantic tools for managing ai system accountability and audit.</article-title>
                    <source>

                        <italic toggle="yes">aura.abdn.ac.ukM Markovic, I Naja, P Edwards, W PangCEUR Work. Proceedings, 2021&#x2022;aura.abdn.ac.uk.</italic>
</source>
                    <year>2021</year>. 2021, Accessed: Aug. 04, 2025.
                    <ext-link ext-link-type="uri" xlink:href="https://aura.abdn.ac.uk/bitstream/handle/2164/17060/Markovic_etal_CEURWS_The_Accountability_Fabric_VoR.pdf?sequence=2">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref118">
                <label>113</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Baldoni</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Baroglio</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Micalizio</surname>
                            <given-names>R</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Accountability in multi-agent organizations: from conceptual design to agent programming.</article-title>
                    <source>

                        <italic toggle="yes">Auton. Agent. Multi-Agent Syst.</italic>
</source>
                    <year>2023</year>;<volume>37</volume>(<issue>1</issue>).
                    <pub-id pub-id-type="doi">10.1007/S10458-022-09590-6</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref119">
                <label>114</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mont</surname>
                            <given-names>MC</given-names>
                        </name>
</person-group>:
                    <article-title>Privacy-Aware Identity Lifecycle Management.</article-title>
                    <source>

                        <italic toggle="yes">Lect. Notes Comput. Sci. (including Subser. Lect. Notes Artif. Intell. Lect. Notes Bioinformatics).</italic>
</source>
                    <year>2011</year>;<volume>6545</volume>:<fpage>397</fpage>&#x2013;<lpage>426</lpage>.
                    <pub-id pub-id-type="doi">10.1007/978-3-642-19050-6_15</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref120">
                <label>115</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Hariharan</surname>
                            <given-names>R</given-names>
                        </name>
</person-group>:
                    <article-title>AI-Driven Identity and Access Management in Enterprise Systems.</article-title>
                    <source>

                        <italic toggle="yes">Int. J. IoT.</italic>
</source>
                    <year>May 2025</year>;<volume>05</volume>(<issue>01</issue>):<fpage>62</fpage>&#x2013;<lpage>94</lpage>.
                    <pub-id pub-id-type="doi">10.55640/IJIOT-05-01-05</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref121">
                <label>116</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Poel</surname>
                            <given-names>I</given-names>
                            <prefix>van de</prefix>
                        </name>
</person-group>:
                    <article-title>Embedding Values in Artificial Intelligence (AI) Systems.</article-title>
                    <source>

                        <italic toggle="yes">Mind. Mach.</italic>
</source>
                    <year>Sep. 2020</year>;<volume>30</volume>(<issue>3</issue>):<fpage>385</fpage>&#x2013;<lpage>409</lpage>.
                    <pub-id pub-id-type="doi">10.1007/S11023-020-09537-4</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref122">
                <label>117</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Hayashi</surname>
                            <given-names>H</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Multi-agent online planning architecture for real-time compliance.</article-title>
                    <source>

                        <italic toggle="yes">H Hayashi, T Mitsikas, YS Taheri, K Tsushima, R Sch&#x00e4;fermeier, G Bourgne, JG Ganascia17th Int. Rule Chall. 7th Dr. &#x2026;, 2023&#x2022;hal.sorbonne-universite.fr.</italic>
</source>
                    <year>2023</year>. Accessed: Aug. 04, 2025.
                    <ext-link ext-link-type="uri" xlink:href="http://hal.sorbonne-universite.fr">Reference Source</ext-link>
                    <ext-link ext-link-type="uri" xlink:href="https://hal.sorbonne-universite.fr/hal-04320268/">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref123">
                <label>118</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Del Carmen Fern&#x00e1;ndez Mart&#x00ed;nez</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Fern&#x00e1;ndez</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>AI in Recruiting. Multi-agent Systems Architecture for Ethical and Legal Auditing.</article-title>
                    <source>

                        <italic toggle="yes">IJCAI Int. Jt. Conf. Artif. Intell.</italic>
</source>
                    <year>2019</year>;<volume>2019-August</volume>:<fpage>6428</fpage>&#x2013;<lpage>6429</lpage>.
                    <pub-id pub-id-type="doi">10.24963/IJCAI.2019/903</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref124">
                <label>119</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Laukyte</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <article-title>AI as a Legal Person.</article-title>
                    <source>

                        <italic toggle="yes">Proc. Seventeenth Int. Conf. Artif. Intell. Law.</italic>
</source>
                    <year>Jun. 2019</year>;<fpage>209</fpage>&#x2013;<lpage>213</lpage>.
                    <pub-id pub-id-type="doi">10.1145/3322640.3326701</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref125">
                <label>120</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Fern&#x00e1;ndez</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Fern&#x00e1;ndez</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>Inclusive AI in Recruiting. Multi-agent Systems Architecture for Ethical and Legal Auditing.</article-title>
                    <source>

                        <italic toggle="yes">Commun. Comput. Inf. Sci.</italic>
</source>
                    <year>2019</year>;<volume>1047</volume>:<fpage>326</fpage>&#x2013;<lpage>329</lpage>.
                    <pub-id pub-id-type="doi">10.1007/978-3-030-24299-2_30</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref126">
                <label>121</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Tang</surname>
                            <given-names>C</given-names>
                        </name>
</person-group>:
                    <article-title>AI and big data in economic regulation: A comparative analysis of China and the United States.</article-title>
                    <source>

                        <italic toggle="yes">Appl. Comput. Eng.</italic>
</source>
                    <year>Jul. 2024</year>;<volume>69</volume>(<issue>1</issue>):<fpage>78</fpage>&#x2013;<lpage>84</lpage>.
                    <pub-id pub-id-type="doi">10.54254/2755-2721/69/20241458</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref127">
                <label>122</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Bhatta</surname>
                            <given-names>NP</given-names>
                        </name>
</person-group>:
                    <article-title>Governance Models in Education: Insights for Nepal&#x2019;s Federal Education System.</article-title>
                    <source>

                        <italic toggle="yes">AMC J.</italic>
</source>
                    <year>2024</year>;<volume>5</volume>(<issue>1</issue>):<fpage>34</fpage>&#x2013;<lpage>52</lpage>.
                    <pub-id pub-id-type="doi">10.3126/AMCJ.V5I1.75960</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref128">
                <label>123</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Hafid</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hocine</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Guezouli</surname>
                            <given-names>L</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Centralized and Decentralized Federated Learning in Autonomous Swarm Robots: Approaches, Algorithms, Optimization Criteria and Challenges: The Sixth Edition of International Conference on Pattern Analysis and Intelligent Systems (PAIS&#x2019;24)</chapter-title>
                    <source>

                        <italic toggle="yes">2024 6th Int. Conf. Pattern Anal. Intell. Syst.</italic>
</source>
                    <year>2024</year>; pp.<fpage>1</fpage>&#x2013;<lpage>8</lpage>.
                    <pub-id pub-id-type="doi">10.1109/PAIS62114.2024.10541145</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref129">
                <label>124</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Araujo-Vizuete</surname>
                            <given-names>G</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Robalino-L&#x00f3;pez</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>A Systematic Roadmap for Energy Transition: Bridging Governance and Community Engagement in Ecuador.</article-title>
                    <source>

                        <italic toggle="yes">Smart Cities.</italic>
</source>
                    <year>May 2025</year>;<volume>8</volume>(<issue>3</issue>):<fpage>80</fpage>.
                    <pub-id pub-id-type="doi">10.3390/SMARTCITIES8030080</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref130">
                <label>125</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Tallam</surname>
                            <given-names>K</given-names>
                        </name>
</person-group>:
                    <article-title>Transforming Cyber Defense: Harnessing Agentic and Frontier AI for Proactive, Ethical Threat Intelligence.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2503.0</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2503.00164</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref131">
                <label>126</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Balkin</surname>
                            <given-names>J</given-names>
                        </name>
</person-group>:
                    <article-title>The Path of Robotics Law.</article-title>
                    <year>2015</year>;<volume>6</volume>.
                    <pub-id pub-id-type="doi">10.15779/Z388V90</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref132">
                <label>127</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Winfield</surname>
                            <given-names>J</given-names>
                        </name>
</person-group>:
                    <article-title>Ethical governance is essential to building trust in robotics and artificial intelligence systems.</article-title>
                    <source>

                        <italic toggle="yes">R. Winfield, M JirotkaPhilosophical Trans. R. Soc. A.</italic>
</source>
                    <year>Nov. 2018</year>; vol.<volume>376</volume>(<issue>2133</issue>).
                    <pub-id pub-id-type="doi">10.1098/RSTA.2018.0085</pub-id>
                    <ext-link ext-link-type="uri" xlink:href="http://royalsocietypublishing.org">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref133">
                <label>128</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Murugesan</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Murugesan</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>The Rise of Agentic AI: Implications, Concerns, and the Path Forward.</article-title>
                    <source>

                        <italic toggle="yes">IEEE Intell. Syst.</italic>
</source>
                    <year>2025</year>;<volume>40</volume>(<issue>2</issue>):<fpage>8</fpage>&#x2013;<lpage>14</lpage>.
                    <pub-id pub-id-type="doi">10.1109/MIS.2025.3544940</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref134">
                <label>129</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Casper</surname>
                            <given-names>S</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>The AI Agent Index.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2502.0</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2502.01635</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref135">
                <label>130</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Samdani</surname>
                            <given-names>G</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Paul</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Saldanha</surname>
                            <given-names>F</given-names>
                        </name>
</person-group>:
                    <article-title>Agentic AI in the Age of Hyper-Automation.</article-title>
                    <source>

                        <italic toggle="yes">World J. Adv. Eng. Technol. Sci.</italic>
</source>
                    <year>Feb. 2023</year>;<volume>8</volume>(<issue>1</issue>):<fpage>416</fpage>&#x2013;<lpage>427</lpage>.
                    <pub-id pub-id-type="doi">10.30574/WJAETS.2023.8.1.0042</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref136">
                <label>131</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Bollineni</surname>
                            <given-names>PK</given-names>
                        </name>
</person-group>:
                    <article-title>Revolutionizing Financial Management: The Role of Agentic AI in SAP Finance.</article-title>
                    <source>

                        <italic toggle="yes">J. Comput. Sci. Technol. Stud.</italic>
</source>
                    <year>Apr. 2025</year>;<volume>7</volume>(<issue>2</issue>):<fpage>473</fpage>&#x2013;<lpage>482</lpage>.
                    <pub-id pub-id-type="doi">10.32996/JCSTS.2025.7.2.49</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref137">
                <label>132</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>P&#x011b;chou&#x010d;ek</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ma&#x0159;&#x00ed;k</surname>
                            <given-names>V</given-names>
                        </name>
</person-group>:
                    <article-title>Industrial deployment of multi-agent technologies: review and selected case studies.</article-title>
                    <source>

                        <italic toggle="yes">Auton. Agent. Multi-Agent Syst.</italic>
</source>
                    <year>Dec. 2008</year>;<volume>17</volume>(<issue>3</issue>):<fpage>397</fpage>&#x2013;<lpage>431</lpage>.
                    <pub-id pub-id-type="doi">10.1007/S10458-008-9050-0</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref138">
                <label>133</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Biswas</surname>
                            <given-names>D</given-names>
                        </name>
</person-group>:
                    <article-title>Stateful Monitoring and Responsible Deployment of AI Agents.</article-title>
                    <source>

                        <italic toggle="yes">Int. Conf. Agents Artif. Intell.</italic>
</source>
                    <year>2025</year>;<volume>1</volume>:<fpage>393</fpage>&#x2013;<lpage>399</lpage>.
                    <pub-id pub-id-type="doi">10.5220/0013160300003890</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref139">
                <label>134</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ahmed</surname>
                            <given-names>N</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hossain</surname>
                            <given-names>ME</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hossain</surname>
                            <given-names>Z</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Understanding the Capabilities and Implications of Agentic AI in Surveillance Systems.</article-title>
                    <source>

                        <italic toggle="yes">Indones. J. Adv. Res.</italic>
</source>
                    <year>Jan. 2025</year>;<volume>4</volume>(<issue>1</issue>):<fpage>91</fpage>&#x2013;<lpage>110</lpage>.
                    <pub-id pub-id-type="doi">10.55927/IJAR.V4I1.13682</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref140">
                <label>135</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Khowaja</surname>
                            <given-names>SA</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Dev</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Pathan</surname>
                            <given-names>MS</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Integration of Agentic AI with 6G Networks for Mission-Critical Applications: Use-case and Challenges.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2502.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2502.13476</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref141">
                <label>136</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Acharya</surname>
                            <given-names>DB</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kuppan</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Divya</surname>
                            <given-names>B</given-names>
                        </name>
</person-group>:
                    <article-title>Agentic AI: Autonomous Intelligence for Complex Goals&#x2014;A Comprehensive Survey.</article-title>
                    <source>

                        <italic toggle="yes">IEEE Access.</italic>
</source>
                    <year>2025</year>;<volume>13</volume>:<fpage>18912</fpage>&#x2013;<lpage>18936</lpage>.
                    <pub-id pub-id-type="doi">10.1109/ACCESS.2025.3532853</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref143">
                <label>137</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Madireddy</surname>
                            <given-names>RR</given-names>
                        </name>
</person-group>:
                    <article-title>Security Implications of Fully Autonomous Process Agents in Enterprise Workflows.</article-title>
                    <source>

                        <italic toggle="yes">J. Comput. Sci. Technol. Stud.</italic>
</source>
                    <year>May 2025</year>;<volume>7</volume>(<issue>3</issue>):<fpage>165</fpage>&#x2013;<lpage>171</lpage>.
                    <pub-id pub-id-type="doi">10.32996/JCSTS.2025.7.3.18</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref144">
                <label>138</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Le Jeune</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Liu</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Rossi</surname>
                            <given-names>L</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>RealHarm: A Collection of Real-World Language Model Application Failures.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2504.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2504.10277</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref145">
                <label>139</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ortega</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>A proposal for an incident regime that tracks and counters threats to national security posed by AI systems.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2503.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2503.19887</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref146">
                <label>140</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Hammond</surname>
                            <given-names>L</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Multi-Agent Risks from Advanced AI.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2502.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2502.14143</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref147">
                <label>141</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>McGregor</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>Preventing Repeated Real World AI Failures by Cataloging Incidents: The AI Incident Database.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2021</year>;<volume>abs/2011.08512</volume>:<fpage>15458</fpage>&#x2013;<lpage>15463</lpage>.
                    <pub-id pub-id-type="doi">10.1609/AAAI.V35I17.17817</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref148">
                <label>142</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Samdani</surname>
                            <given-names>G</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Paul</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Saldanha</surname>
                            <given-names>F</given-names>
                        </name>
</person-group>:
                    <article-title>Serverless architectures for agentic AI deployment.</article-title>
                    <source>

                        <italic toggle="yes">World J. Adv. Eng. Technol. Sci.</italic>
</source>
                    <year>Dec. 2022</year>;<volume>7</volume>(<issue>2</issue>):<fpage>320</fpage>&#x2013;<lpage>333</lpage>.
                    <pub-id pub-id-type="doi">10.30574/WJAETS.2022.7.2.0144</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref149">
                <label>143</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Li</surname>
                            <given-names>C</given-names>
                        </name>
</person-group>:
                    <article-title>Future Trends and Technological Innovations of Private AI Deployment.</article-title>
                    <source>

                        <italic toggle="yes">Sci. Technol. Soc. Dev. Proc. Ser.</italic>
</source>
                    <year>Sep. 2024</year>;<volume>1</volume>:<fpage>1</fpage>&#x2013;<lpage>14</lpage>.
                    <pub-id pub-id-type="doi">10.70088/6FMYNZ86</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref150">
                <label>144</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Khanna</surname>
                            <given-names>K</given-names>
                        </name>
</person-group>:
                    <article-title>Proactive fraud detection: Safeguarding customers with agentic AI.</article-title>
                    <source>

                        <italic toggle="yes">Int. J. Multidiscip. Res. Growth Eval.</italic>
</source>
                    <year>2024</year>;<volume>5</volume>(<issue>6</issue>):<fpage>1523</fpage>&#x2013;<lpage>1531</lpage>.
                    <pub-id pub-id-type="doi">10.54660/.IJMRGE.2024.5.6-1523-1531</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref151">
                <label>145</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Pauloski</surname>
                            <given-names>JG</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Babuji</surname>
                            <given-names>Y</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Chard</surname>
                            <given-names>R</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Empowering Scientific Workflows with Federated Agents.</article-title>
                    <source>

                        <italic toggle="yes">JG Pauloski, Y Babuji, R Chard, M Sak. K Chard, I Foster. Prepr. arXiv2505.05428, 2025&#x2022;arxiv.org.</italic>
</source>
                    <year>2025</year>. Accessed: Aug. 04, 2025.
                    <ext-link ext-link-type="uri" xlink:href="http://arxiv.org">Reference Source</ext-link>
                    <ext-link ext-link-type="uri" xlink:href="https://arxiv.org/abs/2505.05428">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref152">
                <label>146</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Rosenberg</surname>
                            <given-names>LB</given-names>
                        </name>
</person-group>:
                    <article-title>The Manipulation Problem: Conversational AI as a Threat to Epistemic Agency.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2023</year>;<volume>abs/2306.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2306.11748</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref154">
                <label>147</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Solano-Kamaiko</surname>
                            <given-names>IR</given-names>
                        </name>

                        <etal/>
</person-group>
                    <chapter-title>Who is running it?&#x2019; Towards Equitable AI Deployment in Home Care Work</chapter-title>
                    <source>

                        <italic toggle="yes">Proc. 2025 CHI Conf. Hum. Factors Comput. Syst.</italic>
</source>
                    <year>Apr. 2025</year>.
                    <pub-id pub-id-type="doi">10.1145/3706598.3713850</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref155">
                <label>148</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Fiaschetti</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Suraci</surname>
                            <given-names>V</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Priscoli</surname>
                            <given-names>FD</given-names>
                        </name>
</person-group>:
                    <chapter-title>The SHIELD framework: How to control Security, Privacy and Dependability in complex systems</chapter-title>
                    <source>

                        <italic toggle="yes">2012 Complex. Eng. (COMPENG). Proc.</italic>
</source>
                    <year>2012</year>; pp.<fpage>1</fpage>&#x2013;<lpage>4</lpage>.
                    <pub-id pub-id-type="doi">10.1109/COMPENG.2012.6242962</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref157">
                <label>149</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Simran</surname>
                            <given-names>SK</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hans</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <chapter-title>The AI Shield and Red AI Framework: Machine Learning Solutions for Cyber Threat Intelligence (CTI)</chapter-title>
                    <source>

                        <italic toggle="yes">2024 Int. Conf. Intell. Syst. Cybersecurity.</italic>
</source>
                    <year>2024</year>; pp.<fpage>1</fpage>&#x2013;<lpage>6</lpage>.
                    <pub-id pub-id-type="doi">10.1109/ISCS61804.2024.10581195</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref158">
                <label>150</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Bashir</surname>
                            <given-names>N</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Zafar</surname>
                            <given-names>MZ</given-names>
                        </name>
</person-group>:
                    <article-title>AI-Powered Cyberattacks: Impacts and Defense Strategies.</article-title>
                    <source>

                        <italic toggle="yes">World J. Adv. Res. Rev.</italic>
</source>
                    <year>Mar. 2025</year>;<volume>25</volume>(<issue>3</issue>):<fpage>510</fpage>&#x2013;<lpage>512</lpage>.
                    <pub-id pub-id-type="doi">10.30574/WJARR.2025.25.3.0751</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref159">
                <label>151</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Delli Priscoli</surname>
                            <given-names>F</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Ensuring cyber-security in smart railway surveillance with SHIELD.</article-title>
                    <source>

                        <italic toggle="yes">Int. J. Crit. Comput. Based Syst.</italic>
</source>
                    <year>2017</year>;<volume>7</volume>(<issue>2</issue>):<fpage>138</fpage>&#x2013;<lpage>170</lpage>.
                    <pub-id pub-id-type="doi">10.1504/IJCCBS.2017.084928</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref161">
                <label>152</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Chokkanathan</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Karpagavalli</surname>
                            <given-names>SM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Priyanka</surname>
                            <given-names>G</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>AI-Driven Zero Trust Architecture: Enhancing Cyber-Security Resilience.</article-title>
                    <source>

                        <italic toggle="yes">2024 8th Int. Conf. Comput. Syst. Inf. Technol. Sustain. Solut.</italic>
</source>
                    <year>2024</year>; pp.<fpage>1</fpage>&#x2013;<lpage>6</lpage>.
                    <pub-id pub-id-type="doi">10.1109/CSITSS64042.2024.10816746</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref162">
                <label>153</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Gurram</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>Generative AI for enhanced cybersecurity: building a zero-trust architecture with agentic AI.</article-title>
                    <source>

                        <italic toggle="yes">World J. Adv. Eng. Technol. Sci.</italic>
</source>
                    <year>Apr. 2025</year>;<volume>15</volume>(<issue>1</issue>):<fpage>2380</fpage>&#x2013;<lpage>2396</lpage>.
                    <pub-id pub-id-type="doi">10.30574/WJAETS.2025.15.1.0504</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref163">
                <label>154</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Shah</surname>
                            <given-names>H</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Shah</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <article-title>AI-driven adaptive authentication for zero trust security architectures.</article-title>
                    <source>

                        <italic toggle="yes">Int. J. Sci. Res. Arch.</italic>
</source>
                    <year>Mar. 2025</year>;<volume>14</volume>(<issue>3</issue>):<fpage>705</fpage>&#x2013;<lpage>712</lpage>.
                    <pub-id pub-id-type="doi">10.30574/IJSRA.2025.14.3.0645</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref164">
                <label>155</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Paul</surname>
                            <given-names>EM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kessie</surname>
                            <given-names>JD</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Salawudeen</surname>
                            <given-names>MD</given-names>
                        </name>
</person-group>:
                    <article-title>Zero trust architecture and AI: A synergistic approach to next-generation cybersecurity frameworks.</article-title>
                    <source>

                        <italic toggle="yes">Int. J. Sci. Res. Arch.</italic>
</source>
                    <year>Dec. 2024</year>;<volume>13</volume>(<issue>2</issue>):<fpage>4159</fpage>&#x2013;<lpage>4169</lpage>.
                    <pub-id pub-id-type="doi">10.30574/IJSRA.2024.13.2.2583</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref165">
                <label>156</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Obbu</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>Zero trust architecture for AI-powered cloud systems: Securing the future of automated workloads.</article-title>
                    <source>

                        <italic toggle="yes">World J. Adv. Res. Rev.</italic>
</source>
                    <year>Apr. 2025</year>;<volume>26</volume>(<issue>1</issue>):<fpage>1315</fpage>&#x2013;<lpage>1339</lpage>.
                    <pub-id pub-id-type="doi">10.30574/WJARR.2025.26.1.1173</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref166">
                <label>157</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Zhang</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Xu</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Shin</surname>
                            <given-names>B</given-names>
                        </name>
</person-group>:
                    <chapter-title>Towards Adaptive Zero Trust Model for Secure AI</chapter-title>
                    <source>

                        <italic toggle="yes">2023 IEEE Conf. Commun. Netw. Secur.</italic>
</source>
                    <year>2023</year>; pp.<fpage>1</fpage>&#x2013;<lpage>2</lpage>.
                    <pub-id pub-id-type="doi">10.1109/CNS59707.2023.10288810</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref167">
                <label>158</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Syros</surname>
                            <given-names>G</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Suri</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Nita-Rotaru</surname>
                            <given-names>C</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>SAGA: A Security Architecture for Governing AI Agentic Systems.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2504.2</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2504.21034</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref168">
                <label>159</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Onteddu</surname>
                            <given-names>AR</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Koehler</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kundavaram</surname>
                            <given-names>RR</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Artificial Intelligence in Zero-Knowledge Proofs: Transforming Privacy in Cryptographic Protocols.</article-title>
                    <source>

                        <italic toggle="yes">Eng. Int.</italic>
</source>
                    <year>2024</year>;<volume>12</volume>(<issue>1</issue>):<fpage>51</fpage>&#x2013;<lpage>66</lpage>.
                    <pub-id pub-id-type="doi">10.18034/EI.V12I1.743</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref169">
                <label>160</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Loevenich</surname>
                            <given-names>JF</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Towards Robust and Secure Autonomous Cyber Defense Agents in Coalition Networks</chapter-title>
                    <source>

                        <italic toggle="yes">MILCOM 2024-2024 IEEE Mil. Commun. Conf.</italic>
</source>
                    <year>2024</year>; pp.<fpage>152</fpage>&#x2013;<lpage>157</lpage>.
                    <pub-id pub-id-type="doi">10.1109/MILCOM61039.2024.10773821</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref170">
                <label>161</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Theron</surname>
                            <given-names>P</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Towards an active, autonomous and intelligent cyber defense of military systems: The NATO AICA reference architecture</chapter-title>
                    <source>

                        <italic toggle="yes">2018 Int. Conf. Mil. Commun. Inf. Syst.</italic>
</source>
                    <year>Jun. 2018</year>; pp.<fpage>1</fpage>&#x2013;<lpage>9</lpage>.
                    <pub-id pub-id-type="doi">10.1109/ICMCIS.2018.8398730</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref171">
                <label>162</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Kurra</surname>
                            <given-names>P</given-names>
                        </name>
</person-group>:
                    <article-title>Securing the cloud with AI: The future of autonomous threat defense.</article-title>
                    <source>

                        <italic toggle="yes">World J. Adv. Res. Rev.</italic>
</source>
                    <year>Apr. 2025</year>;<volume>26</volume>(<issue>1</issue>):<fpage>756</fpage>&#x2013;<lpage>762</lpage>.
                    <pub-id pub-id-type="doi">10.30574/WJARR.2025.26.1.1081</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref172">
                <label>163</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Chakrabarty</surname>
                            <given-names>PK</given-names>
                        </name>
</person-group>:
                    <article-title>Adversarial Attacks on Agentic AI Systems: Mechanisms, Impacts, and Defense Strategies.</article-title>
                    <source>

                        <italic toggle="yes">Int. J. Sci. Res.</italic>
</source>
                    <year>Apr. 2025</year>;<volume>14</volume>(<issue>4</issue>):<fpage>1367</fpage>&#x2013;<lpage>1369</lpage>.
                    <pub-id pub-id-type="doi">10.21275/SR25417074844</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref173">
                <label>164</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Syros</surname>
                            <given-names>G</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Suri</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Nita-Rotaru</surname>
                            <given-names>C</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>SAGA: A Security Architecture for Governing AI Agentic Systems.</article-title>
                    <year>Apr. 2025</year>.
                    <ext-link ext-link-type="uri" xlink:href="http://arxiv.org/abs/2504.21034">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref174">
                <label>165</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Loevenich</surname>
                            <given-names>JF</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Training Autonomous Cyber Defense Agents: Challenges &amp; Opportunities in Military Networks</chapter-title>
                    <source>

                        <italic toggle="yes">MILCOM 2024-2024 IEEE Mil. Commun. Conf.</italic>
</source>
                    <year>2024</year>; pp.<fpage>158</fpage>&#x2013;<lpage>163</lpage>.
                    <pub-id pub-id-type="doi">10.1109/MILCOM61039.2024.10773923</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref175">
                <label>166</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mechergui</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sreedharan</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>Goal Alignment: A Human-Aware Account of Value Alignment Problem.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2023</year>;<volume>abs/2302.0</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2302.00813</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref176">
                <label>167</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Carroll</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Foote</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Siththaranjan</surname>
                            <given-names>A</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>AI Alignment with Changing and Influenceable Reward Functions.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2024</year>;<volume>abs/2405.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2405.17713</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref177">
                <label>168</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Zhuang</surname>
                            <given-names>S</given-names>
                        </name>

                        <collab>D. H.-M. Neural</collab>
</person-group>:
                    <article-title>Consequences of misaligned AI.</article-title>
                    <source>

                        <italic toggle="yes">proceedings.neurips.cc.</italic>
</source>
                    <year>2021</year>. Accessed: Aug. 04, 2025.
                    <ext-link ext-link-type="uri" xlink:href="https://proceedings.neurips.cc/paper/2020/hash/b607ba543ad05417b8507ee86c54fcb7-Abstract.html">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref178">
                <label>169</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mechergui</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Neural</surname>
                            <given-names>SS</given-names>
                        </name>
</person-group>:
                    <article-title>Expectation Alignment: Handling Reward Misspecification in the Presence of Expectation Mismatch.</article-title>
                    <source>

                        <italic toggle="yes">proceedings.neurips.ccM Mechergui, S SreedharanAdvances Neural Inf. Process. Syst. 2024&#x2022;proceedings.neurips.cc.</italic>
</source>
                    <year>2024</year>. Accessed: Aug. 04, 2025.
                    <ext-link ext-link-type="uri" xlink:href="https://proceedings.neurips.cc/paper_files/paper/2024/hash/72393bd47a35f5b3bee4c609e7bba733-Abstract-Conference.html">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref179">
                <label>170</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Sun</surname>
                            <given-names>Z</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>SALMON: SELF-ALIGNMENT WITH INSTRUCTABLE REWARD MODELS</chapter-title>
                    <source>

                        <italic toggle="yes">12th Int. Conf. Learn. Represent. ICLR 2024.</italic>
</source>
                    <year>2024</year>. Accessed: Aug. 04, 2025.
                    <ext-link ext-link-type="uri" xlink:href="https://arxiv.org/pdf/2310.05910">https://arxiv.org/pdf/2310.05910</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref180">
                <label>171</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Singh</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>AI Alignment: Ensuring AI Objectives Match Human Values.</article-title>
                    <source>

                        <italic toggle="yes">Int. J. Sci. Res. Eng. Manag.</italic>
</source>
                    <year>Apr. 2025</year>;<volume>09</volume>(<issue>04</issue>):<fpage>1</fpage>&#x2013;<lpage>9</lpage>.
                    <pub-id pub-id-type="doi">10.55041/IJSREM46662</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref181">
                <label>172</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Jones</surname>
                            <given-names>B</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Stemmler</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Su</surname>
                            <given-names>E</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Users&#x2019; Expectations and Practices with Agent Memory.</article-title>
                    <source>

                        <italic toggle="yes">Proc. Ext. Abstr. CHI Conf. Hum. Factors Comput. Syst.</italic>
</source>
                    <year>2025 Apr.</year>.
                    <pub-id pub-id-type="doi">10.1145/3706599.3720158</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref182">
                <label>173</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>DeChant</surname>
                            <given-names>C</given-names>
                        </name>
</person-group>:
                    <article-title>On the risks and benefits of episodic memory in AI agents.</article-title>
                    <year>2023</year>. Accessed: Aug. 05, 2025.</mixed-citation>
            </ref>
            <ref id="ref183">
                <label>174</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ganguli</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Deb</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Banerjee</surname>
                            <given-names>D</given-names>
                        </name>
</person-group>:
                    <article-title>MARK: Memory Augmented Refinement of Knowledge.</article-title>
                    <year>May 2025</year>. Accessed: Aug. 05, 2025
                    <ext-link ext-link-type="uri" xlink:href="https://arxiv.org/pdf/2505.05177">https://arxiv.org/pdf/2505.05177</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref184">
                <label>175</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Vaithilingam</surname>
                            <given-names>P</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Semantic Commit: Helping Users Update Intent Specifications for AI Memory at Scale.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2504.0</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2504.09283</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref185">
                <label>176</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Rasmussen</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Paliychuk</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Beauvais</surname>
                            <given-names>T</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Zep: A Temporal Knowledge Graph Architecture for Agent Memory.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2501.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2501.13956</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref186">
                <label>177</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Helmi</surname>
                            <given-names>T</given-names>
                        </name>
</person-group>:
                    <article-title>Decentralizing AI Memory: SHIMI, a Semantic Hierarchical Memory Index for Scalable Agent Reasoning.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2504.0</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2504.06135</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref187">
                <label>178</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Kim</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Saad</surname>
                            <given-names>W</given-names>
                        </name>
</person-group>:
                    <chapter-title>Analysis of the Memorization and Generalization Capabilities of AI Agents: are Continual Learners Robust?</chapter-title>
                    <source>

                        <italic toggle="yes">ICASSP 2024-2024 IEEE Int. Conf. Acoust. Speech Signal Process.</italic>
</source>
                    <year>2024</year>; pp.<fpage>6840</fpage>&#x2013;<lpage>6844</lpage>.
                    <pub-id pub-id-type="doi">10.1109/ICASSP48485.2024.10447575</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref188">
                <label>179</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Springer</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>Making Transparency Clear: The Dual Importance of Explainability and Auditability.</article-title>
                    <year>Sep. 09, 2023</year>. Accessed: Aug. 05, 2025.
                    <ext-link ext-link-type="uri" xlink:href="https://www.academia.edu/106430231/Making_Transparency_Clear_The_Dual_Importance_of_Explainability_and_Auditability">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref189">
                <label>180</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ehsan</surname>
                            <given-names>U</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>New Frontiers of Human-centered Explainable AI (HCXAI): Participatory Civic AI, Benchmarking LLMs, XAI Hallucinations, and Responsible AI Audits</chapter-title>
                    <source>

                        <italic toggle="yes">Proc. Ext. Abstr. CHI Conf. Hum. Factors Comput. Syst.</italic>
</source>
                    <year>Apr. 2025</year>.
                    <pub-id pub-id-type="doi">10.1145/3706599.3706713</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref190">
                <label>181</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Balasubramaniam</surname>
                            <given-names>N</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kauppinen</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Rannisto</surname>
                            <given-names>A</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Transparency and explainability of AI systems: From ethical guidelines to requirements.</article-title>
                    <source>

                        <italic toggle="yes">Inf. Softw. Technol.</italic>
</source>
                    <year>Jul. 2023</year>;<volume>159</volume>:<fpage>107197</fpage>.
                    <pub-id pub-id-type="doi">10.1016/J.INFSOF.2023.107197</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref191">
                <label>182</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Waltersdorfer</surname>
                            <given-names>L</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sabou</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <article-title>Leveraging Knowledge Graphs for AI System Auditing and Transparency.</article-title>
                    <source>

                        <italic toggle="yes">J. Web Semant.</italic>
</source>
                    <year>Jan. 2025</year>;<volume>84</volume>:<fpage>100849</fpage>.
                    <pub-id pub-id-type="doi">10.1016/J.WEBSEM.2024.100849</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref192">
                <label>183</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Nannini</surname>
                            <given-names>L</given-names>
                        </name>
</person-group>:
                    <article-title>Habemus a Right to an Explanation: so What? - A Framework on Transparency-Explainability Functionality and Tensions in the EU AI Act.</article-title>
                    <source>

                        <italic toggle="yes">Proc. AAAI/ACM Conf. AI, Ethics, Soc.</italic>
</source>
                    <year>Oct. 2024</year>;<volume>7</volume>:<fpage>1023</fpage>&#x2013;<lpage>1035</lpage>.
                    <pub-id pub-id-type="doi">10.1609/AIES.V7I1.31700</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref193">
                <label>184</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Werz</surname>
                            <given-names>JM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Borowski</surname>
                            <given-names>E</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Isenhardt</surname>
                            <given-names>I</given-names>
                        </name>
</person-group>:
                    <article-title>Explainability as a means for transparency? Lay users&#x2019; requirements towards transparent AI.</article-title>
                    <source>

                        <italic toggle="yes">Cogn. Comput. Internet Things.</italic>
</source>
                    <year>2024</year>;<volume>124</volume>.
                    <pub-id pub-id-type="doi">10.54941/AHFE1004712</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref194">
                <label>185</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Bustamante</surname>
                            <given-names>P</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>On the Governance of Federated Platforms.</article-title>
                    <source>

                        <italic toggle="yes">SSRN Electron. J.</italic>
</source>
                    <year>2023</year>.
                    <pub-id pub-id-type="doi">10.2139/SSRN.4528712</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref195">
                <label>186</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Pauloski</surname>
                            <given-names>JG</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Babuji</surname>
                            <given-names>Y</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Chard</surname>
                            <given-names>R</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Empowering Scientific Workflows with Federated Agents.</article-title>
                    <year>May 2025</year>. Accessed: Aug. 05, 2025.
                    <ext-link ext-link-type="uri" xlink:href="https://arxiv.org/pdf/2505.05428">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref198">
                <label>187</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Panda</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Mukherjee</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>Architecting Intelligent Decentralized Data Systems to Enable Analytics with Entropy-Aware Governance, Quantum Readiness and LLM-Driven Federation.</article-title>
                    <source>

                        <italic toggle="yes">Int. J. Database Manag. Syst.</italic>
</source>
                    <year>Apr. 2025</year>;<volume>17</volume>(<issue>1/2</issue>):<fpage>17</fpage>&#x2013;<lpage>23</lpage>.
                    <pub-id pub-id-type="doi">10.5121/IJDMS.2025.17202</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref199">
                <label>188</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Yilmaz</surname>
                            <given-names>E</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Can</surname>
                            <given-names>O</given-names>
                        </name>
</person-group>:
                    <article-title>Unveiling Shadows: Harnessing Artificial Intelligence for Insider Threat Detection.</article-title>
                    <source>

                        <italic toggle="yes">Eng. Technol. &amp;amp; Appl. Sci. Res.</italic>
</source>
                    <year>2024</year>;<volume>14</volume>(<issue>2</issue>):<fpage>13341</fpage>&#x2013;<lpage>13346</lpage>.
                    <pub-id pub-id-type="doi">10.48084/ETASR.6911</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref200">
                <label>189</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Feng</surname>
                            <given-names>X</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Zheng</surname>
                            <given-names>Z</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hu</surname>
                            <given-names>P</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Stealthy attacks meets insider threats: A three-player game model</chapter-title>
                    <source>

                        <italic toggle="yes">MILCOM 2015-2015 IEEE Mil. Commun. Conf.</italic>
</source>
                    <year>Dec. 2015</year>; vol.<volume>2015-December</volume>: pp.<fpage>25</fpage>&#x2013;<lpage>30</lpage>.
                    <pub-id pub-id-type="doi">10.1109/MILCOM.2015.7357413</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref201">
                <label>190</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Chen</surname>
                            <given-names>Y</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hu</surname>
                            <given-names>X</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Yin</surname>
                            <given-names>K</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Evaluating the Robustness of Multimodal Agents Against Active Environmental Injection Attacks.</article-title>
                    <year>Apr. 2025</year>. Accessed: Aug. 05, 2025.
                    <ext-link ext-link-type="uri" xlink:href="https://arxiv.org/pdf/2502.13053">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref203">
                <label>191</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Matthews</surname>
                            <given-names>G</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Wohleber</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Lin</surname>
                            <given-names>J</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Cognitive and Affective Eye Tracking Metrics for Detecting Insider Threat: A Study of Simulated Espionage.</article-title>
                    <source>

                        <italic toggle="yes">Proc. Hum. Factors Ergon. Soc. Annu. Meet.</italic>
</source>
                    <year>2018</year>;<volume>62</volume>:<fpage>242</fpage>&#x2013;<lpage>246</lpage>.
                    <pub-id pub-id-type="doi">10.1177/1541931218621056</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref205">
                <label>192</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ioannidis</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Harper</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Quah</surname>
                            <given-names>MS</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Gracenote.ai: Legal Generative AI for Regulatory Compliance.</article-title>
                    <source>

                        <italic toggle="yes">CEUR Workshop Proc.</italic>
</source>
                    <year>2023</year>;<volume>3423</volume>:<fpage>20</fpage>&#x2013;<lpage>31</lpage>.
                    <pub-id pub-id-type="doi">10.2139/SSRN.4494272</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref206">
                <label>193</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Fratri&#x010d;</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Parizi</surname>
                            <given-names>MM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sileno</surname>
                            <given-names>G</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Do agents dream of abiding by the rules?: Learning norms via behavioral exploration and sparse human supervision.</article-title>
                    <source>

                        <italic toggle="yes">Proc. Ninet. Int. Conf. Artif. Intell. Law.</italic>
</source>
                    <year>2023</year>;<fpage>81</fpage>&#x2013;<lpage>90</lpage>.
                    <pub-id pub-id-type="doi">10.1145/3594536.3595153</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref208">
                <label>194</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mahajan</surname>
                            <given-names>P</given-names>
                        </name>
</person-group>:
                    <article-title>AI Family Integration Index (AFII): Benchmarking a New Global Readiness for AI as Family.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2503.2</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2503.22772</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref209">
                <label>195</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Labanieh</surname>
                            <given-names>MF</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Yusoff</surname>
                            <given-names>ZM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ayub</surname>
                            <given-names>ZA</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>THE ARTIFICIAL INTELLIGENCE (AI) READINESS IN ASEAN COUNTRIES: THE GOVERNMENT POLICIES AND FRAMEWORKS.</article-title>
                    <source>

                        <italic toggle="yes">ASEAN Leg. Insights.</italic>
</source>
                    <year>Dec. 2024</year>;<volume>1</volume>:<fpage>68</fpage>&#x2013;<lpage>76</lpage>.
                    <pub-id pub-id-type="doi">10.32890/ASEANLI2024.1.5</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref210">
                <label>196</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Tun</surname>
                            <given-names>HM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Naing</surname>
                            <given-names>L</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Malik</surname>
                            <given-names>OA</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Navigating ASEAN Region Artificial Intelligence (AI) Governance Readiness in Healthcare.</article-title>
                    <source>

                        <italic toggle="yes">Heal. Policy Technol.</italic>
</source>
                    <year>Mar. 2025</year>;<volume>14</volume>(<issue>2</issue>):<fpage>100981</fpage>.
                    <pub-id pub-id-type="doi">10.1016/J.HLPT.2025.100981</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref211">
                <label>197</label>
                <mixed-citation publication-type="book">
                    <collab>UNESCO</collab>:
                    <source>

                        <italic toggle="yes">Readiness assessment methodology: a tool of the Recommendation on the.</italic>
</source>
                    <publisher-name>UNESCO</publisher-name>;
Accessed: Aug. 05, 2025.
                    <ext-link ext-link-type="uri" xlink:href="https://www.unesco.org/en/articles/readiness-assessment-methodology-tool-recommendation-ethics-artificial-intelligence">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref213">
                <label>198</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Reuel</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Soder</surname>
                            <given-names>L</given-names>
                        </name>,

                        <collab>B. B.-F. I</collab>

                        <etal/>
</person-group>:
                    <article-title>Position: Technical research and talent is needed for effective AI governance.</article-title>
                    <source>

                        <italic toggle="yes">A Reuel, L Soder, B Bucknall, TA UndheimForty-first Int. Conf. Mach. Learn. 2024&#x2022;openreview.net.</italic>
</source>
                    <year>2024</year>. Accessed: Aug. 05, 2025.
                    <ext-link ext-link-type="uri" xlink:href="http://openreview.net">Reference Source</ext-link>
                    <ext-link ext-link-type="uri" xlink:href="https://openreview.net/forum?id=Be2B6f0ps1">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref214">
                <label>199</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Pihlakas</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Pyykk&#x00f6;</surname>
                            <given-names>J</given-names>
                        </name>
</person-group>:
                    <article-title>From homeostasis to resource sharing: Biologically and economically aligned multi-objective multi-agent AI safety benchmarks.</article-title>
                    <year>Jul. 2025</year>. Accessed: Aug. 05, 2025.
                    <ext-link ext-link-type="uri" xlink:href="https://arxiv.org/pdf/2410.00081">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref215">
                <label>200</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Moshkovich</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Mulian</surname>
                            <given-names>H</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Zeltyn</surname>
                            <given-names>S</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Beyond Black-Box Benchmarking: Observability, Analytics, and Optimization of Agentic Systems.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2503.0</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2503.06745</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref216">
                <label>201</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Davydova</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Jeffries</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Barker</surname>
                            <given-names>P</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>OSUniverse: Benchmark for Multimodal GUI-navigation AI Agents.</article-title>
                    <year>May 2025</year>. Accessed: Aug. 05, 2025.
                    <ext-link ext-link-type="uri" xlink:href="http://arxiv.org/abs/2505.03570">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref217">
                <label>202</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Geng</surname>
                            <given-names>L</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Chang</surname>
                            <given-names>EY</given-names>
                        </name>
</person-group>:
                    <article-title>REALM-Bench: A Real-World Planning Benchmark for LLMs and Multi-Agent Systems.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2025</year>;<volume>abs/2502.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2502.18836</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref218">
                <label>203</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Siegel</surname>
                            <given-names>ZS</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kapoor</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Nagdir</surname>
                            <given-names>N</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>CORE-Bench: Fostering the Credibility of Published Research Through a Computational Reproducibility Agent Benchmark.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2024</year>;<volume>abs/2409.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2409.11363</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref219">
                <label>204</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Clark</surname>
                            <given-names>B</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>EXACT: Towards a platform for empirically benchmarking Machine Learning model explanation methods.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2024</year>;<volume>abs/2405.1</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2405.12261</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref221">
                <label>205</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Jaiswal</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Mishra</surname>
                            <given-names>PC</given-names>
                        </name>
</person-group>:
                    <article-title>ARTIFICIAL INTELLIGENCE (AI) AND CYBERSECURITY LAW: LEGAL ISSUES IN AI-DRIVEN CYBER DEFENSE AND OFFENSE.</article-title>
                    <source>

                        <italic toggle="yes">ShodhKosh J. Vis. Perform. Arts.</italic>
</source>
                    <year>Jun. 2024</year>;<volume>5</volume>(<issue>6</issue>).
                    <pub-id pub-id-type="doi">10.29121/SHODHKOSH.V5.I6.2024.4144</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref222">
                <label>206</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Birkstedt</surname>
                            <given-names>T</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Minkkinen</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Tandon</surname>
                            <given-names>A</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>AI governance: themes, knowledge gaps and future agendas.</article-title>
                    <source>

                        <italic toggle="yes">Internet Res.</italic>
</source>
                    <year>2023</year>;<volume>33</volume>(<issue>7</issue>):<fpage>133</fpage>&#x2013;<lpage>167</lpage>.
                    <pub-id pub-id-type="doi">10.1108/INTR-01-2022-0042/FULL/PDF</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref224">
                <label>207</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Aryal</surname>
                            <given-names>S</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Leveraging Multi-AI Agents for Cross-Domain Knowledge Discovery.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2024</year>;<volume>abs/2404.0</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2404.08511</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref225">
                <label>208</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Clatterbuck</surname>
                            <given-names>H</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Castro</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Mor&#x2019;an</surname>
                            <given-names>AM</given-names>
                        </name>
</person-group>:
                    <article-title>Risk Alignment in Agentic AI Systems.</article-title>
                    <source>

                        <italic toggle="yes">ArXiv.</italic>
</source>
                    <year>2024</year>;<volume>abs/2410.0</volume>.
                    <pub-id pub-id-type="doi">10.48550/ARXIV.2410.01927</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref227">
                <label>209</label>
                <mixed-citation publication-type="data">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Adabara</surname>
                            <given-names>I</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sadiq</surname>
                            <given-names>BO</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Shuaibu</surname>
                            <given-names>AN</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <data-title>Trustworthy Agentic AI Systems: A Cross-Layer Review of Architectures, Threat Models, and Governance Strategies for Real-World Deployment.</data-title>[Dataset].
                    <source>

                        <italic toggle="yes">Trust. Agentic AI Syst. A Cross-Layer Rev. Archit. Threat Model. Gov. Strateg. Real-World Deploy. Suppl. Data. Figshare.</italic>
</source>
                    <year>Aug. 2025</year>.
                    <pub-id pub-id-type="doi">10.6084/M9.FIGSHARE.29986882.V4</pub-id>
                </mixed-citation>
            </ref>
        </ref-list>
    </back>
</article>
