AI systems are no longer passive tools that respond to queries. They are increasingly autonomous agents that take actions, execute workflows, and interact with applications, data, and physical systems at machine speed — and the Model Context Protocol has accelerated that shift by giving agents standardized interfaces to reach almost anything. This white paper sets out how to keep those agents contained, accountable, and under human authority.
Why behavioral control is not enough
The industry's response has been to extend cloud-based controls and AI tools to govern how an agent behaves. That is desirable, but not sufficient. Behavioral control works against the very property that makes an agent valuable: the more tightly you script what an agent may do, the less useful an agent you have. A guardrail embedded in the same probabilistic layer inherits that layer's unpredictability and susceptibility to manipulation — and these controls depend on a centralized cloud control plane that is itself a target.
Reach, not intent — containment first
Faction takes a different starting point. When resources, devices, and data are placed inside a Faction Network, they are invisible and unreachable to any agent outside it, and reachable inside only through cryptographic authorization. This is not a firewall rule an agent might probe; it is a property of the architecture. Structural segmentation bounds an agent's reachable surface before any behavioral policy runs — so even a fully compromised agent can talk only to the resources on its own segment.
Human authority, held continuously
A recurring mistake is to assume human-in-the-loop means a person approves every action. At machine speed that neither works nor is safe. The paper describes two postures that hold authority in place:
- Human-on-the-loop — the default at runtime. The agent operates autonomously within fixed cryptographic bounds, while humans supervise attributed, tamper-evident activity and can intervene at any moment.
- Human-in-the-loop — for the moments that matter. Live human presence is required at just two points: establishing an agent's authority, and approving or denying a specific high-stakes action.
Every agent is enrolled as its own cryptographic principal, bound to an accountable human sponsor, so its actions are attributable and its authority can be revoked at any moment.
What the paper covers
- The agentic AI challenge, the rise of MCP, and the limits of behavioral guardrails
- How Faction compares with VPNs and firewalls, cloud ZTNA/SASE, and peer-to-peer mesh
- The agentic AI trust and control layer, and the mechanisms of control
- Human authority, accountability, and control
- Scalability and granularity for agentic AI
- The hardware root of trust — Zero Trust to silicon, and quantum-assured trust