DP13 – AI Containment
Patches and comments are scoped to the whole document family, not to a single revision. When you open a revision, highlights show what still applies to that revision body; anything anchored to text a later revision removed is listed as needing re-anchoring, and anything that can no longer be merged at all is marked obsolete. See all patches.
Comparing Revision 03 with Revision 04. Struck-through text was removed; highlighted text was added.
*Bounded AI behavior enforced at runtime, not promised in policy*

<!-- dp-local-version: 1.0 | standardized: 2026-07-27 --> <!-- govhub-sync: ml=ML-Draft-004 revision=03 submission=7c7c3a99-74fc-4c41-ac37-2422a056be3b hash=01b900abca77ea0f synced=2026-08-08T21:35:00Z -->
## 1. Purpose of This Draft
Published: 2026-08-08
Pages: 10 | Words: 4527
What changed:
Synced from the book local rail (content/local/dpN.md), which carries the current working text for this chapter: expanded sections, renamed and renumbered headings, and editorial cleanup since the last revision. Published as a new revision so prior revisions stay intact.
Published: 2026-08-05
Pages: 10 | Words: 4512
What changed:
Numbered section headings and cross-reference fixes for collaborative review
Published: 2026-08-04
Pages: 10 | Words: 4511
What changed:
Synced from the book local rail (content/local/dpN.md), which carries the current working text for this chapter: expanded sections, renamed and renumbered headings, and editorial cleanup since the last revision. Published as a new revision so prior revisions stay intact.
Published: 2026-05-04
Pages: 6 | Words: 2899
What changed:
The upgraded DP13 expands containment from a technical safeguard into a comprehensive control system covering both capability and influence. The earlier version focused primarily on bounding what agents can do (tools, scope, execution limits). The new version adds a second, equally important dimension: how agents affect perception, behavior, and collective reality. This explicitly addresses modern risks like persuasion, narrative shaping, and coordinated influence—not just misuse of tools.
Another major shift is the move toward verifiable, policy-bound containment. The upgraded draft requires that containment be inspectable and tied directly to governance policies (DP12), with visible configuration, logs, and attestations (e.g., TEE-backed enforcement). It also introduces cross-system verification, ensuring containment persists—or visibly degrades—when agents move across platforms. This closes a critical gap: containment can no longer disappear quietly when systems interconnect.
Finally, DP13 now explicitly addresses adversarial and emergent failure modes at scale, especially from external agents. It expands threat modeling to include coordinated influence, incentive leakage, containment bypass via integrations, and “containment theater” (where safeguards appear present but aren’t enforced). It also strengthens the notion that containment must be default-on, adaptive, and resilient under interoperability and composability. The result is a shift from static guardrails to a dynamic, system-wide boundary layer that ensures AI remains bounded—even as it scales, integrates, and interacts across environments.