EBTE Secures AI Tool Execution with Server-Verified Claims

Genliang Zhu (Accentrust, Georgia Institute of Technology), Chu Wang (Accentrust, University of Illinois Urbana-Champaign)· July 30, 2026 View original

Summary

This paper introduces Explanation-Bound Tool Execution (EBTE), a mediation layer that converts AI agent rationales into structured action claims, verifying them against server-held policies before execution. EBTE enhances security by not trusting model rationales directly, ensuring actions align with intent and policy.

AI agents that use tools often provide free-form rationales for their actions, but these rationales are not reliable for authorization or introspection. This presents a security and control challenge. The new research proposes Explanation-Bound Tool Execution (EBTE), a mediation layer designed to enhance the security and trustworthiness of AI agent tool use. EBTE works by transforming the decision-relevant content from an AI agent's rationale into structured, typed action claims. These claims are then rigorously checked against a set of server-held facts, including intent, policy, payload, tool specifications, risk assessments, provenance, and freshness. This process ensures that conflicts deny execution, incomplete or uncertain claims are reviewed, and only fully matching claims are eligible for governed execution. The system was formalized and implemented, demonstrating conformance across numerous scenarios and effectively blocking high-risk attack proposals, proving its feasibility for server-checked action claims without relying on the AI model's internal reasoning.

Why it matters

For professionals building and deploying AI agents that interact with external systems, EBTE offers a critical security mechanism to ensure agent actions are compliant, authorized, and safe, mitigating risks associated with untrustworthy model rationales.

How to implement this in your domain

  1. 1Evaluate current AI agent tool execution pipelines for reliance on model-generated rationales.
  2. 2Investigate integrating a mediation layer like EBTE to convert rationales into verifiable action claims.
  3. 3Define clear server-held policies and facts (intent, risk, authorization) against which AI agent claims can be checked.
  4. 4Develop robust audit trails for AI agent actions, leveraging the structured claims generated by EBTE.

Who benefits

CybersecurityAI DevelopmentFinancial ServicesHealthcareManufacturing

Key takeaways

  • AI agent rationales are unreliable for security and policy enforcement.
  • EBTE converts model rationales into structured, verifiable action claims.
  • Claims are checked against server-held policies, ensuring compliance and safety.
  • This approach enhances security for AI agent tool execution without trusting model introspection.

Original post by Genliang Zhu (Accentrust, Georgia Institute of Technology), Chu Wang (Accentrust, University of Illinois Urbana-Champaign)

"arXiv:2607.25364v2 Announce Type: new Abstract: Tool-using agents expose structured calls but commonly attach free-form rationales. Such rationales are neither authorization nor reliable introspection. We present Explanation-Bound Tool Execution (EBTE), a claim-carrying mediation…"

View on X

Originally posted by Genliang Zhu (Accentrust, Georgia Institute of Technology), Chu Wang (Accentrust, University of Illinois Urbana-Champaign) on X · view source

Want to go deeper?

Turn these trends into skills with Learnijoy's hands-on AI & tech courses.

Explore courses