A Machine-Enforceable Constraint is enforced at a Kernel-Level Enforcement Point appropriate to the protected Operation.

In the diagram, the Constraint derived from the upstream Decision “DENY external transmission” is passed to Runtime Enforcement. Rather than controlling all Execution at a single point, the Constraint is applied to the Enforcement Point corresponding to the relevant Operation.

Different areas, including Process Execution, File Access, Network Access, Privilege Control, and Device Access, may require different Enforcement Mechanisms. In this Linux-based Reference Model, LSM Hooks and cgroup BPF are possible mechanisms depending on the Operation, while Seccomp and Syscall Filtering can serve as supplementary Controls.

These Enforcement Points do not interpret Governance. The Kernel compares the Machine-Enforceable Constraint formed upstream with the current Operation and verifies at Runtime whether the Operation satisfies the Constraint, then enforces the result.

For example, under “DENY external transmission,” the entire AI or Agent does not need to be stopped. Instead, the relevant Network Access can be Blocked, allowing only the necessary Constraint to be enforced at the Point closest to the prohibited Operation.

This structure connects Governance Decisions to specific System Operations and enables Enforcement at the required Execution Points.

The placement of LSM, cgroup BPF, and other mechanisms does not prescribe a Production Implementation. It is an exploratory Reference Model for concretizing the Execution Boundary.