Once execution has been authorized through Decision and an authorization Key has been issued, the process proceeds to the stage in which the operation is actually executed. In I2EA, this stage is defined as “Execution.” However, authorization at the Decision stage does not mean that an AI system is free to execute the operation directly. Immediately before execution, a mechanism is required to verify that the request has been properly authorized.
In I2EA, this role is performed by the “Execution Boundary.” The Execution Boundary is positioned at the OS-level execution boundary and verifies the required authorization information when an AI system or application attempts to access external APIs, networks, files, or other system resources.
Consider, for example, an AI system attempting to use an external image-generation API. If the necessary Fact, Evaluation, and Policy information has been verified in the preceding stages and the Decision Engine has authorized the execution, the request is accompanied by a valid authorization Key. The Execution Boundary verifies this Key and allows access to the API only when the required conditions are satisfied.
Conversely, if required tags are missing, the Policy Check has not been completed, or no valid authorization Key exists, the execution request cannot cross the boundary. Importantly, the Execution Boundary itself does not make semantic judgments such as “Is this execution appropriate?” or “May this information be transmitted?” Those judgments have already been addressed through the preceding Evaluation, Policy, and Decision stages.
The role of the Execution Boundary is to deterministically verify whether a valid authorization Key exists and, based on that verification, allow or block execution. This separates governance decision-making from physical execution control.
An AI system cannot cross the Execution Boundary merely because it determines that an action is permissible. Actual execution requires an authorization Key issued through the required governance process.
Authorization is also not a permanent permission granted to an AI system or application as a whole. It can be bound to a specific execution request. Accordingly, even for the same AI system, a different Action or Context may require a new Decision and authorization.
Accordingly, Execution is the stage in which a valid authorization Key issued through Decision is verified at the Execution Boundary, allowing only authorized operations to reach actual system resources.
Through this mechanism, I2EA does not merely present Policy as a set of rules that should be followed. Rather, it connects governance to actual system behavior, from authorization through Decision to execution control at the Execution Boundary.