{
  "id": 5697,
  "url": "https://arxiv.org/abs/2604.16870v2",
  "title": "Governed MCP: Kernel-Level Tool Governance for AI Agents via Logit-Based Safety Primitives",
  "summary": "AI agents increasingly call external tools (file system, network, APIs) through the Model Context Protocol (MCP). These tool calls are the agent's syscalls: privileged operations with side effects on shared state, yet today's safety enforcement lives entirely in userspace, where a 10-line script can bypass it. I propose Governed MCP, a kernel-resident tool governance gateway built on a logit-based safety primitive (ProbeLogits). The gateway interposes on every MCP tool call in a 6-layer pipeline",
  "authors": "Daeyeon Son",
  "category": "research",
  "topics": "regulation,agents-autonomy",
  "orgs": null,
  "regions": null,
  "published_at": "2026-04-18T06:40:20.000Z",
  "fetched_at": "2026-07-14T16:31:57.534Z",
  "source_slug": "arxiv-ethics",
  "source_name": "arXiv",
  "source_homepage": "https://arxiv.org",
  "ethics_ai_record_url": "https://ethics.ai/record/5697",
  "original_url": "https://arxiv.org/abs/2604.16870v2",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}