Summary

  • Revision 02 of the agentic sensing draft proposes a decrementing interaction level to limit delegation hops, tiers or workers, but leaves child-task selection to each agent’s implementation and local knowledge.
  • Reaching zero can prove that another handoff should not occur under one encoding. It cannot prove that raw-data locality, trusted-source, encryption, fusion, capability or outcome requirements survived every earlier edge.

The final agent did not delegate again. Its counter was zero, exactly as the originating request required. The audit still failed. Two handoffs earlier, a child had copied the sensing task but dropped the rule that raw observations must stay on the originating device. The graph was finite. The policy was not intact.

That is the most consequential boundary in revision 02 of Solutions for enabling agentic sensing with network optimization, submitted by Carlos J. Bernardos, Alain Mourad and Muhammad Awais Jadoon on 2 October 2026. The draft describes a distributed sensing architecture in which AI agents for Sensing, or AIaS, coordinate with AI agents for Network, or AIaN. A Sensing Control Function can delegate a task to an agent; the agent can recruit sensors and a processing function; networking agents can request connectivity; monitoring can later provoke reconfiguration.

The proposal is an active individual Internet-Draft, not an NMRG-adopted document, an IETF standard or a deployment report. Datatracker gives it no stream, responsible Area Director or formal standards-process standing. The text says intended status Experimental. Revision 02 changes the date, expiry and acknowledgment record from revision 01 but does not add a security design. Its IANA section says N/A; its Security Considerations section remains TBD.

Those limits are not a reason to dismiss the architecture. They are a reason to read it at the correct layer. The draft is useful design evidence about the information an agentic sensing system may need. It is not evidence that the illustrated handoffs preserve those fields, that any implementation exists, or that an autonomous loop can safely change a network.

A request carries more than a task name

The proposed request is unusually revealing because it already acknowledges how many constraints accompany a sensing goal. It can describe spatial and temporal accuracy, stationary or mobile targets, processing location, confidentiality, trusted generating entities, acceptable fusion, energy objectives and allowed agent interactions. Raw data may need to remain local. Remote processing may be allowed only after partial transformation. Some sources may be trusted while others are not. Different trust levels may or may not be mixed.

Each item answers a different question. “Encrypt all exchanged data” governs transport or storage protection. “Process raw data locally” governs location and transformation. A trusted-source list governs admissible provenance. A fusion rule governs which observations may be combined. An accuracy target governs output quality. An energy target constrains resource choice. None can safely be replaced by the others.

The draft then introduces an allowed level of agentic AI interactions. The parameter may prevent interaction with sensing agents, network agents or agents under different ownership. It may decide whether agents monitor and propose reconfiguration. It may also denote maximum hops, tiers, workers or graph depth. As an example, the value can be decreased by one whenever an agent delegates.

An illustrative encoding gives zero as no delegation, one as permission for a local AIaS to interact with a local AIaN, two as permission to contact other sensing nodes without further delegation, and three as permission for additional levels. Later text says another interaction can occur only when the received value is greater than one and that each level decreases it by one.

This is a topology budget. It can be a good one. Bounded delegation reduces uncontrolled graph growth and gives operators a simple invariant to test. But a topology budget is not a policy carrier. A child can decrement correctly while deleting, weakening, mistranslating or selectively enforcing every other field.

The same integer can count different realities

The draft deliberately says the parameter “might be expressed in different ways.” That flexibility becomes a protocol hazard if implementations do not agree on what is consumed. Three tiers is not the same as three workers. In a branching graph, one parent can contact three children at one depth. A hop limit does not cap total nodes, concurrent requests, administrative domains, data copies or actions.

Even the example mixes local AIaS-to-AIaN interaction with delegation to remote sensing nodes. Does a local network agent consume a tier? Is a request from the networking agent to an SMF or AMF another agentic hop? Does a retry consume budget? Does monitoring begin a new chain or continue the old one? A numeric field without a normative accounting model gives two conforming-looking systems different control surfaces.

The safe design is to name every budget. maxDelegationDepth, maxWorkers, maxConcurrentBranches, maxAdministrativeDomains and maxActions are different controls. Each edge should record the before and after value, the parent, the child, the task fragment and the rule that justified the handoff. Otherwise zero at the leaf says only that one local variable was exhausted.

Attenuation must be monotonic

Delegation should not merely copy authority; it should attenuate it. A child may receive the right to collect one signal in one place for one interval, not the parent’s full capacity to recruit agents or change routes. A networking agent may request a path with bounded properties, not inherit authority to modify unrelated infrastructure. A processing node may receive transformed observations, not raw data.

That requires an immutable policy identity and an explicit capability at each edge. The handoff should bind the task, policy version or hash, permitted data classes, transformations, destinations, time window, geographic or administrative scope, delegation flag and remaining budgets. The child’s receipt should state what it accepted. A later result should point back to that exact edge.

No single cryptographic primitive completes this job. A signature can attribute a handoff to a key. Attestation, in the sense described by RFC 9334, can supply evidence about an environment for a verifier to appraise. Neither says that the signer was authorised for this task or that the relying party’s policy was enforced. Identity, environment state, capability and observed effect remain separate propositions.

The draft itself makes the gap explicit in another way. It says the decision that additional sensing tasks are needed is outside scope and depends on an agent’s implementation and local knowledge. That is where authority can expand silently. A parent sends a bounded goal; the child invents subtasks; those subtasks drive network configuration; monitoring later generates more actions. Without edge receipts, the originating principal cannot reconstruct which local inference caused which physical or network effect.

“Configured” is not “delivered”

The sequence diagram includes requests from sensing agents to network agents and then to a network-control function. Responses travel back through the chain. A response can report that a configuration request was accepted or applied. It cannot by itself prove that packets followed the intended path, arrived within the required interval, remained confidential, or reached the chosen processing node.

Network telemetry provides observations, not automatic causality. RFC 9232 describes a framework in which data can be generated, exported, analysed and consumed. An observed latency change may correlate with a configuration, yet another event may have caused it. A sensing system needs both the configuration receipt and independently attributable delivery evidence.

The same separation applies at the sensing layer. A processing function can return a result without proving which sensors contributed, whether one branch timed out, whether preprocessing altered the data, or whether accuracy remained inside tolerance. A successful aggregate response must not erase a missing branch. The evidence set should retain source membership, acquisition times, transformation steps, exclusions, uncertainty and the calculation of the reported KPI.

Energy makes the trade-off visible. The draft permits energy requirements alongside sensing accuracy, latency, confidence and privacy. An optimiser can reduce energy while degrading refresh rate or moving processing into a forbidden location. “Optimised” has no meaning until the objective vector, constraints and observed result are named. A lower wattage is not success if the requested sensing task is no longer achieved.

Monitoring is another authority boundary

The draft closes its procedure with monitoring. Agents or legacy network mechanisms may watch connectivity, estimated sensing precision and energy consumption. Thresholds can be associated with actions, and monitoring may trigger reconfiguration.

That feedback loop is precisely where a missing policy receipt becomes cumulative. If a child already lost the locality constraint, its monitoring response can request another configuration under the weakened view. Each iteration then appears to improve the local metric while moving farther from the originating mandate.

A monitor should emit an observation and a proposed action, not directly inherit actuation authority. The proposal needs an identified decision owner, current policy version, allowed actuator, scope, rollback condition and new observation after the change. The entity that measures a threshold need not be the entity permitted to alter routing, radio state, compute placement or data exposure.

Revision 02 offers no security mechanism for this chain; the section is still TBD. That fact should be visible in any trial. It would be misleading to treat the draft’s list of governance fields as proof that enforcement has been designed. The list is a requirements surface waiting for a protocol and threat model.

What a defensible receipt chain would show

A deployment experiment should preserve at least eight linked records. First, the original task and accountable principal. Second, the immutable policy version and permitted transformations. Third, every delegation edge, child identity and attenuated capability. Fourth, every network configuration request and authorised actuator. Fifth, configuration acceptance plus observed connectivity. Sixth, custody and transformation of sensing data. Seventh, KPI evidence with uncertainty and missing contributors. Eighth, the monitoring trigger, reconfiguration decision and post-change outcome.

The chain should distinguish refusal, timeout, partial result and verified failure. An absent child response is not a zero-valued measurement. A processing node that saw three of four expected sources should not describe a complete fusion. An agent that cannot prove policy continuity should stop or return an explicit unknown, rather than filling the gap with local confidence.

This approach follows the reality-layer discipline in Heng Lu’s work. The counter is symbolic state. The delegation edge is a control act. Network configuration is another act. Packet delivery, data location and sensing accuracy are observed realities. Moving evidence between those layers requires an explicit join, not a convenient label.

Minimum Initial Specification points toward a narrow first protocol: identify the principal, bind a policy hash, attenuate a capability, name the budgets and return edge receipts. Running-Code Primacy then demands independent implementations and captured traces before the architecture earns deployment claims. A sequence diagram is not a closed-loop safety result.

The opening audit therefore reaches a precise conclusion. Zero was not false. It was simply insufficient. It showed that the final agent understood one stopping rule. It did not show that the policy survived the journey. The next design revision should not ask the counter to do more. It should make every handoff prove exactly what it carried, exactly what it narrowed and exactly what happened next.

Sources