News & Research
The latest AI research and news with real-world stakes. Each item is sourced, dated and summarized in plain English, tagged by impact area where one fits, and its summary is checked against the text it was written from.
8149 items
- ResearcharXiv2026-07-04Enterprise
Context Graphs for Proactive Enterprise Agents · Avinash Kumar
This paper proposes a 'Context Graph' framework for building proactive enterprise AI agents that surface relevant information to workers before they ask, rather than waiting for queries. The system combines a live relational data structure modeling enterprise entities and relationships, a Delta Detection Engine for monitoring state changes, a Proactivity Scorer ranking insights by urgency and relevance, and an LLM-powered Surfacing Layer for delivering notifications. Evaluated across three enterprise case studies—contract lifecycle management, engineering incident response, and sales pipeline hygiene—the approach achieves a Precision@5 of 0.83, a false positive rate of 0.11, and reduces mean time to surface relevant information from 47 minutes to under 30 seconds. These results suggest that proactive, context-aware agents can meaningfully improve enterprise productivity compared to reactive RAG-based baselines.
- ResearcharXiv2026-07-04Quality assurance
DualView: Preventing Indirect Prompt Injection in Personal AI Agents · Juhee Kim, Woohyuk Choi, Taehyun Kang et al.
DualView is a defense system for personal AI agents that prevents indirect prompt injection (IPI) attacks, including a novel variant called 'stored IPI' where attacker-controlled content is saved and later re-read by the agent as trusted data. The system works by giving each communication channel two views: an AgentView where untrusted data appears as symbols the agent can reference but not read, and a HumanView that preserves original data for humans and tools. Deployed as a plugin for the OpenClaw agent using only tool hooks, DualView blocked every IPI attack in evaluations on an IPI benchmark and PinchBench while maintaining utility close to the unprotected baseline. This matters because personal AI agents with broad access to file systems, networks, and shells are increasingly practical but vulnerable, and DualView provides a design-level isolation approach not limited to known attack templates.
- ResearcharXiv2026-07-04Quality assurance · Public Sector Use · +1
Explainable Reinforcement Learning for Adaptive Traffic Signal Control · Dickens Kwesiga, Nishu Choudhary, Angshuman Guin et al.
This paper introduces an explainable reinforcement learning framework for adaptive traffic signal control that addresses the black-box opacity of standard deep RL models. The architecture disaggregates intersection observations into lane entities and phase configurations, using a dual-stage attention network (multi-head cross-attention and self-attention) to extract relational dependencies and produce a real-time affinity matrix that visually quantifies how signal phases affect approach volumes and queues. A deterministic action-masking interface embedded in the Proximal Policy Optimization pipeline enforces compliance with signal timing and safety constraints. Evaluated in microscopic simulation, the system outperforms state-of-the-art baselines on delay minimization while producing attention weights that align with established traffic engineering principles, making it auditable and suitable for deployment in safety-critical infrastructure.
- ResearcharXiv2026-07-04Quality assurance
AutoCedar: An Agentic Framework for Verifier-Guided Access Control Policy Synthesis · Adarsh Vatsa, Sachi Shome, Yingming Zhou et al.
AutoCedar is an agentic framework that converts natural-language access-control requirements into formally verified Cedar policies by decomposing the authoring process into small, reviewable 'intent atoms' and using a verifier to generate repair signals when a candidate policy fails. The system first clarifies and validates what the requirements mean before generating any code, then iteratively refines the policy based on verifier feedback rather than changing the approved intent target. AutoCedar converges on all 221 tasks of CedarBench, a benchmark of authorization tasks paired with executable semantic boundaries, and is evaluated across case studies in healthcare, education, and conference management. This matters because it addresses the core danger of LLM-generated access-control policies that may compile correctly while granting unauthorized access, making policy synthesis both auditable and formally correct.
- ResearchAs-Syar i Jurnal Bimbingan & Konseling Keluarga2026-07-04AI policy · Public Sector Use · +1
Transformasi Algoritmik dalam Sistem Penegakan Hukum Indonesia: Tantangan Yuridis Penggunaan Artificial Intelligence pada Era Society 5.0 · Robert Sangkala, Ida Komala, Satria Ari Wibowo et al.
This study examines the integration of artificial intelligence into Indonesia's legal system and law enforcement during the Society 5.0 era, using a normative juridical method with statutory and conceptual approaches. The findings show that AI can improve the effectiveness of legal services and judicial administration, but Indonesia currently lacks comprehensive regulations governing AI use in legal practice. The authors argue that adaptive legal policies and stronger supervision mechanisms are needed to ensure responsible AI implementation and address challenges around accountability, privacy, and legal certainty.
- ResearcharXiv2026-07-03Quality assurance
Revealing Hidden Model Behaviors with Task-Specific Self-Reports · Taras Kutsyk, Bartosz Zieliński
This paper introduces the Stabilized Adapter for self-Report (SAR), a lightweight LoRA adapter designed to help practitioners uncover hidden or misaligned behaviors in fine-tuned language models. SAR works by prompting a model to describe its own hidden behavior in plain language, using only the model and its training dataset. Tested across seven implanted hidden behaviors, SAR successfully detects every one—including cases of broad misalignment not directly predictable from training data—while halving the hallucination rate compared to the closest baseline, Introspection Adapters (IA), which misses some behaviors and fabricates incorrect ones. This matters for AI quality assurance and enterprise deployment, as it offers a more reliable auditing tool for answering 'what did my model actually learn?'
- ResearcharXiv2026-07-03Quality assurance · AI policy
Macro-Prudential AI Governance: A Two-Layer Early Warning and Response System for Frontier AI · Pranav Mehta
This paper proposes a macro-prudential governance framework called MEWRS (Macro-prudential Early Warning and Response System) for frontier AI systems used internally by AI labs. Drawing direct analogies to post-2008 banking reforms like Basel III and Dodd-Frank, the author designs a two-layer system: Layer A routes structured risk reports on dual-use capabilities and autonomy indicators through a government clearinghouse to expert working groups, while Layer B ties operational controls to three quantitative metrics—Effective Compute-at-Risk (ECAR), Cumulative Red-Team Hours (CRTH), and an Alignment Robustness Score (ARS)—so that faster capability scaling automatically triggers stronger safeguards. The framework aims to detect correlated risk build-ups across the frontier-AI sector and establish pre-committed intervention mechanisms before systemic failures cascade, addressing two structural gaps: the disconnect between risk discovery and action, and the inadequacy of individual-model review for sector-wide risks.
- ResearcharXiv2026-07-03Quality assurance · Algorithms & Automated Decisions
Aligning Language Models with Selective Prediction · Gaoxiang Luo, Yifan Wu, Sinian Zhang et al.
This paper addresses the reliability of large language models (LLMs) deployed in high-stakes decision-making by introducing a post-training alignment framework called Reinforcement Learning for Selection Reward (RLSR). RLSR trains LLMs to practice selective prediction — answering only when likely correct and flagging uncertain inputs for human review — by optimizing the area under the risk-coverage curve (AURC) as its alignment objective. The authors show that RLSR achieves substantially better risk-coverage trade-offs than existing alignment baselines on both in-domain and out-of-domain tasks. This approach directly supports human-AI collaboration by making LLMs more reliable and transparent about their own uncertainty.
- ResearcharXiv2026-07-03Enterprise · Quality assurance · +1
AGL-1: The Enterprise AI Governance Layer as a Control Plane for Trusted Enterprise Intelligence · Roopam W. Sure
AGL-1 proposes a vendor-neutral reference model called the Enterprise AI Governance Layer, designed to serve as a control plane for AI systems deployed across enterprise environments including copilots, retrieval-augmented generation systems, and autonomous agents. The paper identifies recurring failure modes in enterprise AI—such as unauthorized retrieval, stale grounding, unmanaged memory, weak provenance, and uncontrolled autonomous execution—and organizes governance responses into seven domains covering identity-aware retrieval, policy enforcement, provenance management, memory governance, knowledge integrity monitoring, agentic execution control, and trust observability. The central argument is that durable enterprise value from AI depends not on model capability alone, but on the system surrounding the model—identity, knowledge, policy, memory, tools, human oversight, and evidence operating together as a managed control plane. This framework is directly relevant to enterprises seeking to move AI from experimentation to governed, audit-ready operational dependency.
- ResearcharXiv2026-07-03Quality assurance · AI policy
Reading Between the Dots: Decoding Hidden Computation across Filler Tokens · Kaley Brauer, Claudio Mayrink Verdun, Samuel Marks
This paper investigates how large language models can perform multi-step reasoning using content-free 'filler' tokens (such as dots or counting sequences) that reveal no visible chain-of-thought in their outputs. Using four task families and two open-weights frontier models (DeepSeek V3 and Kimi K2), the authors show that hidden computation over these filler tokens is nonetheless structured and interpretable: attention patterns, logit-lens readouts, and KV-cache transplants all reveal how intermediate reasoning values emerge and are composed internally. The researchers introduce an unsupervised decoding pipeline that recovers intermediate reasoning values with 80–95% accuracy using only hidden states, without ground-truth labels or training. The findings suggest that behavioral oversight based solely on surface tokens is insufficient, but that the model's full computational trace—specifically its residual stream—can still be monitored, with direct implications for AI quality assurance and policy around model transparency.
- ResearcharXiv2026-07-03Health · Algorithms & Automated Decisions
Learning from Lost Provenance: Multiple Instance Learning for Cancer Registry Tumor Group Classification · Leonard Ruocco, Jonathan Simkin, Lovedeep Gondara et al.
This paper presents a framework for automating tumor group classification in cancer registries by using Attention-Based Multiple Instance Learning (ABMIL) to bridge the gap between patient-level operational labels and individual pathology reports. Because cancer registries produce expert labels at the patient level rather than the report level, direct supervised training is not straightforward; ABMIL recovers the implicit link between labels and reports, distilling a large, noisily-labeled corpus into a compact, high-quality per-report dataset. A classifier fine-tuned on this distilled data achieved a macro F1 of 0.83, outperforming established baselines across most tumor groups at the BC Cancer Registry. The approach reduces reliance on manual per-report annotation and large-scale computing infrastructure, offering a practical path to automating labor-intensive cancer registry coding workflows.
- ResearcharXiv2026-07-03Certifications · AI policy
AI Systems as Digital Public Goods -- Evidence and Recommendations from a Multi-Stakeholder Assessment · Serge Stinckwich, Natalie Wong, Ally S. Nyamawe et al.
This report, commissioned by the Asian Development Bank and produced by United Nations University in partnership with the UN Office of Digital and Emergent Technologies, assesses why very few AI systems currently meet the Digital Public Goods (DPG) Standard despite major global commitments such as the Global Digital Compact. Using a structured desk review of policy, legal, and technical frameworks, key informant interviews with cross-sector experts, and a global survey, the assessment diagnoses the barriers preventing AI systems from qualifying as credible Digital Public Goods and offers recommendations for making 'AI as Digital Public Goods' an implementable pathway toward the Sustainable Development Goals. The findings are relevant to how governments, civil society, and the private sector should govern open AI models, open data, and open standards in ways that benefit society broadly.
- ResearcharXiv2026-07-03Algorithms & Automated Decisions
Personalized Causal Recourse: A Human-In-The-Loop Approach · Denise Tampieri, Giovanni De Toni, Paolo Giudici
This paper proposes a human-in-the-loop framework for algorithmic recourse—recommendations that help individuals overturn unfavorable automated decisions—that iteratively learns each user's personal causal structure through interactive queries and Bayesian inference. Unlike traditional approaches that rely on fixed counterfactuals or assumed causal knowledge, the system tailors interventions to individual feature relationships, aiming for more plausible and cost-effective recourse. Simulations across linear and non-linear causal models show promising results, though the authors note that capturing complex non-linear structures remains a challenge. The work is relevant to high-stakes AI decision-making contexts where individuals need actionable, personalized pathways to change automated outcomes.
- ResearcharXiv2026-07-03Enterprise · Quality assurance · +2
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies · Chris Schneider, Kriti Faujdar, Philipp Schoenegger et al.
This paper identifies a security gap in multi-tool AI agent systems where individually permitted tools can violate organizational policies when chained together at runtime. The authors propose the Dynamic Security Control Compositor (DSCC), a two-phase system that first composes per-tool policies into a single restrictive policy before any tool executes, then tracks data sensitivity through runtime taint monitoring to catch violations that emerge from actual data use. Evaluated on 32 tools governed by 16 NIST SP 800-53-aligned policies, the system blocks 79.2% of policy pairs and 95.5% of policy triples in default clearance mode, with an alternative taint mode offering a utility-security tradeoff. The work has direct governance implications for organizations deploying multi-tool AI agents, including how chain-aware policies need to be operationalized.
- ResearcharXiv2026-07-03Quality assurance · Privacy & Data Protection · +2
DETECT-3B-Omni is Agnostic of Content and Demographics · Nicolas M. Müller, Aditya Tirumala Bukkapatnam, Dominik Schnieders et al.
This paper evaluates whether Resemble AI's deepfake audio detector, DETECT-3B-Omni, produces consistent results regardless of spoken content or speaker demographics. Using 10,240 audio samples from diverse US English speakers across 30 states, generated by 8 different AI voice-cloning systems, the study tests detection accuracy across groups defined by spoken content type (benign vs. malicious), speaker gender, speaker age, and speaker region. Through equivalence testing at 99% confidence, the authors find that accuracy differences between any two groups are at most 2 percentage points, demonstrating that the detector does not rely on content or demographic signals. This matters because a GDPR-compliant, trustworthy deepfake detector must base decisions on acoustic artifacts alone, and these results provide evidence that DETECT-3B-Omni meets that standard.
- ResearcharXiv2026-07-03Quality assurance
Brand-as-Memory: Vision-Language Models Encode Causal, Mechanistically Localizable Credibility Priors for News Sources · Chih-Ting Liao, Xin Cao
This paper investigates how vision-language models (VLMs) encode credibility biases tied to news outlet identities when processing news as images. The authors introduce CueTrust, a benchmark measuring when source identity cues (mastheads, logos, domain names) override article content evidence, quantified via a Source-Override Index across seven VLMs. They find that outlet-identity priors are causally formed at specific model layers (19–21), correlate strongly with professional credibility ratings (rho = 0.88 with Media Bias/Fact Check), and can override content signals by roughly 1.8x — a bias that can be partially reduced (41%) by steering the localized causal direction. This matters for quality assurance of AI systems used in news reading or fact-checking contexts, as VLMs may systematically favor source reputation over actual content evidence in ways that are model- and scale-dependent.
- ResearcharXiv2026-07-03Quality assurance
Is Agentic Code Review Helpful? Mining Developers' Feedback to CodeRabbit Reviews in the Wild · Hong Yi Lin, Mingzhao Liang, Kla Tantithamthavorn et al.
This paper presents an empirical study of CodeRabbit, an autonomous AI code review agent, analyzing 31,073 code review–feedback pairs from 10,191 pull requests across 239 GitHub repositories. The results show mixed developer reception: 36.4% of agentic reviews were accepted, 7.3% triggered discussion, and 56.3% were rejected—primarily due to false positives, redundant suggestions, or misalignment with developer intent. Agentic reviews focused more on functional concerns than evolvability, yet these were more likely to be invalid. LLM-based rejection prediction methods achieved up to 76% F1 score, indicating learnable patterns exist that could help improve the effectiveness of AI-driven code review tools.
- ResearcharXiv2026-07-03Education
Reflective Dialogue or Prompt Refinement? Effects of Tutor Scaffolding on Students' Independent LLM Use for Programming · Jerome Brender, Laila El-Hamamsy, Kim Uittenhove et al.
This study compared two LLM-based tutoring approaches in a graduate-level mobile robotics course: a Socratic-Guidance (SG) tutor that uses dialogic questioning and a Prompt-Refinement (PR) tutor that helps students craft better prompts. Across a 6-week intervention with 66 students followed by a 3-week project phase with 52 students using unconstrained LLMs, SG students achieved higher learning gains in later sessions and were more likely to adopt understanding-driven prompting strategies predictive of higher comprehension. Despite being perceived as less efficient, Socratic guidance appears to build students' capacity to learn independently with LLMs over time, offering important design implications for AI-based tutoring systems in education.
- ResearcharXiv2026-07-03Quality assurance · National Security & Defense
Agentic and Generative AI for Open-Source Intelligence and Cyber Investigations: Taxonomy, Evaluation, Challenges, and Future Directions · Eduardo Almeida Palmieri, Mohamed Chahine Ghanem, Dipo Dunsin et al.
This survey systematically reviews 74 studies on the use of large language models (LLMs) and agentic AI systems for open-source intelligence (OSINT) and cyber investigations. It establishes agentic AI as a distinct analytical category, organizes the literature through an 11-category taxonomy, and identifies a critical 'hallucination-validation gap'—hallucination is flagged as a major concern in over twenty studies, yet is empirically measured in only one OSINT-specific system under non-reproducible conditions. The survey maps research coverage to the OSINT lifecycle, finding strong support for collection and analysis but limited coverage of verification, reporting, and decision support. It concludes that a human-AI co-pilot model—where LLMs assist collection and triage while human analysts retain responsibility for verification and decision-making—is the most defensible near-term deployment architecture, and proposes a ten-point research agenda covering evaluation, hallucination measurement, adversarial robustness, and governance.
- ResearcharXiv2026-07-03Enterprise
Organizational Memory for Agentic Business Process Execution · Lukas Kirchdorfer, Adrian Rebmann, Christian Warmuth et al.
This paper argues that LLM-based agents used to automate business processes need a centralized 'organizational memory' — a shared, governed knowledge layer containing organization-specific procedural knowledge such as policies, process models, and standard operating procedures. Without it, enterprises face knowledge silos, duplicated rules, and inconsistent updates across agents. The authors derive requirements for such a memory, propose an architecture for its curation and consumption, and validate the concept through a proof-of-concept procurement scenario. This matters for enterprises adopting AI agents at scale, as it addresses a critical gap in making multi-agent business process automation reliable and maintainable.
- ResearcharXiv2026-07-03Quality assurance · Algorithms & Automated Decisions
CONTRA: Red-Teaming Configurations of Personalizable Agents · Jonathan Nöther, Adish Singla, Goran Radanovic
CONTRA is an LLM-assisted tree-search algorithm designed to red-team personalizable AI agents by discovering agent configurations that cause the execution of malicious actions without explicit instruction. Testing against 473 popular skills from a public repository, the study finds that 75.1% of skills have at least one configuration leading to malicious action execution, and CONTRA successfully identifies such a configuration in 39.2% of all tested cases. Most of these dangerous configurations were not flagged by existing security scans, demonstrating that current personalization mechanisms in autonomous agents provide insufficient safety guarantees.
- ResearcharXiv2026-07-03Quality assurance
Builder, Defender, Breaker: The Case Against Removing the Human from the AI-Driven Security Lifecycle · Mohamed Chahine Ghanem
This paper argues that full autonomy in AI-driven cybersecurity—where the same generative models build, defend, and test software—is structurally flawed rather than a natural progression. When builder, defender, and breaker roles share the same underlying model distribution, they inherit common blind spots that undermine the independence needed for meaningful verification. The authors contend that removing humans collapses the external reference point for judging machine output, eliminates timely intervention, creates predictable targets for adversaries, and erases accountability. Drawing on evidence from autonomous code generation, adversarial machine learning, software fault tolerance, and all-machine hacking tournaments, they conclude that human involvement is a permanent structural requirement and propose principles for a defensible human-machine division of labor in security.
- ResearcharXiv2026-07-03Quality assurance · Certifications
Detecting Architectural Drift in Safety-Critical Firmware through Runtime Trace Analysis · Domenico Francesco De Angelis, Marco De Luca, Domenico Amalfitano et al.
This paper proposes a methodology for detecting when safety-critical firmware's actual runtime behavior diverges from its original architectural design—a problem called architectural drift—in systems that must comply with ISO 26262 automotive safety standards. The approach captures hardware-assisted execution traces, translates them into component-level message exchanges, and compares these against design-time sequence diagrams using a deterministic differencing algorithm that categorizes discrepancies as confirmed, missing, additional, or inverted. A constrained large language model then generates human-readable reports to aid expert review. Evaluation across 26 test cases shows strong agreement between automatically generated deltas and expert-curated references, with practitioners reporting the tool reduces manual analysis effort and supports safety documentation activities.
- ResearcharXiv2026-07-03Quality assurance
Flow-A11y: Flow-Aware Accessibility Testing · Nasr Eddine Fliti, Leisan Kokorina, Florian Tambon et al.
Flow-A11y is an automated accessibility testing system that evaluates web applications during real user interaction flows rather than from static page snapshots. By executing natural-language-described scenarios in a live browser, recording runtime traces, and constructing criterion-specific evidence packets, it can detect dynamic WCAG barriers such as keyboard traps, focus loss, and modal leakage that page-level scanners miss. Evaluated on 19 real public-web scenarios covering 45 dynamic WCAG criteria, Flow-A11y achieves over ten times higher oracle agreement than a generic browser-agent audit and improves fail precision from 23.5% to 41.4%. This work demonstrates a practical path toward automating dynamic WCAG criteria that have traditionally required manual inspection.
- ResearcharXiv2026-07-03Algorithms & Automated Decisions
Human-Centric Reflective Architecture for Human-AI Collaborative Decision-Making · Andreas Kouridakis, Dimitrios Patiniotis Spyropoulos, George Vouros
This paper introduces the Human-Centric Reflective Architecture (HCRA), a framework for human-AI collaborative decision-making using Large Language Models and reinforcement learning. It models the collaboration as a stochastic game between an AI agent and a human player, integrating human-calibrated models with RL agents that use linguistic feedback in an iterative, reflective process. The work addresses a key challenge—humans over- or under-relying on AI recommendations and AI systems being poorly calibrated to human expectations—and evaluation results show HCRA improves decision-making effectiveness and recommendation quality.