SovereignRoot blog

AI agent boundaries, honestly explained

Practical, no-hype writing on signed policy files, prompt injection, and what actually enforces a boundary.

What a signed AI policy file can and can't do

A signed sovereignty.json is tamper-evident and portable. It is not, by itself, a security boundary.

How to define AI agent boundaries that survive model changes

Deny-overrides, require-approval, and attenuation-only semantics — a practical guide.

Prompt injection, policy files, and the enforcement gap

Putting a policy in a prompt is not the same as enforcing it. Here's the gap.