Context Is Not Authority: Structured Runtime Governance for Financial Market Agents

2026-08-10Artificial Intelligence

Artificial IntelligenceCryptography and Security
AI summary

The authors introduce SAGE-Fin, a system designed to control financial actions by focusing on the actual effects rather than just the written agreements. It carefully tracks obligations, verifies authority at every step, and ensures that only properly authorized operations are executed. They tested SAGE-Fin extensively with many cases and real customer requests, which led to positive feedback from independent teams and users. However, the authors clarify that these results show the system works as intended, not that it guarantees complete safety. They also report on past failures related to missed controls and outdated information that SAGE-Fin aims to prevent.

authority-handoff contractruntime controlfinancial obligationstyped adapterspolicy enforcementcoverage debtresponse gateconformance testingdigital-asset platformworkflow integration
Authors
Rui Tang, Qiangqiang Liu, Yichi Zhang, Youwei Wang, Xi Chen, Chen Dong
Abstract
Financial agents can turn correct context into an unauthorized effect: a customer-facing commitment, trade, or deployed policy. We present SAGE-Fin, a finance-specific authority-handoff contract that makes the proposed effect, not merely its text, the object of runtime control. SAGE-Fin compiles proposals into typed, adapter-bound candidates; records missing or stale institutional obligations as coverage debt; contracts authority under current market, account, policy, and dialogue state; and requires an exact-artifact receipt whose nominal type matches the consuming response, execution, or policy adapter. Evidence and workflow progress cannot substitute for effect authority, and prior authorization is rechecked after state changes. Across an authored 616-case catalog, five deterministic specifications yield 3,080 outputs; a label-isolated harness obtains 616/616 binary reference-prototype parity, including 3/3 named response-gate fixtures, while 22 tests cover selected paths. These results establish executable conformance, not independent safety accuracy. Separately, SAGE-Fin's response gate processed real customer-facing production requests at a confidential digital-asset platform. An operational team independent of the implementation team reached a strongly positive post-deployment conclusion on practical usefulness and workflow fit, and end-user feedback was also strongly positive. Disclosure permits only the review's independence, stakeholder classes, assessed dimensions, and directional conclusion, so this is qualitative field corroboration rather than an aggregate effect estimate. Three distinct de-identified predecessor failures, with independently confirmed 0/3 interception, ground repeated-emission drift, stale account evidence, and missing escalation state without estimating prevalence or treatment effect.