The Cognitive Continuity Test: Verifying Governed State Transitions in Persistent AI Agents

arXiv:2610.00132 · cs.CR, cs.AI · Submitted 2026-09-09 · Read on arXiv

Listen

Radio episode about this paper

Transcript

Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.

Nadia: I'm Nadia, and with me are Elias and Priya, guest researcher.

Elias: Today's paper: "The Cognitive Continuity Test".

Nadia: Persistent AI agents revise beliefs, consolidate memory, and replace execution substrates. The Cognitive Continuity Test (CCT) introduces a policy-relative contract for verifying explicit agent-state transitions using scoped authority, provenance,

Elias: First, who's behind it and why it matters.

Title and authors: Nadia: We’ve been talking about "The Cognitive Continuity Test: Verifying Governed State Transitions in Persistent AI Agents," and the core idea is setting up a formal contract for checking if an AI agent's changes to its state are allowed by its policy. The authors of this paper are Jun He and Deying Yu, and they’ve focused on using the CCT to verify those explicit agent-state transitions.

Elias: That’s right, Nadia; essentially, they are proposing a mechanism that uses scoped authority and provenance records to determine if an agent's transition from one state to another was legitimate according to its governing policy. It moves us away from just observing the behavior of the AI and toward formally verifying the authorization behind every change it makes.

Priya: What I find compelling about their focus is that they are defining what a valid transition looks like through these formal criteria, rather than just trying to catch errors after an agent has already made them in a live environment. It sounds like they’re building a verification standard from the ground up.

Nadia: Exactly, Priya; the paper introduces this Cognitive Continuity Test as that policy-relative contract used for verifying submitted transitions, and it uses specific components like scoped authority and candidate-persistence receipts to distinguish between things that are verified as admissible, those that are an affirmative violation of policy, and those where we just don't have enough required evidence.

Elias: And I want to emphasize how they handle the verification process by breaking it down into several distinct stages—starting with deterministic historical policy resolution and moving through lineage checks, authority verification, provenance completeness, and finally semantic invariant evaluation.

Priya: When you talk about those stages, I’m thinking about the data flow; does this mean that to verify a single transition claim for an agent, we have to pull in its entire history of beliefs and relationships just to check one move? That sounds computationally intensive.

Nadia: It is intensive because the contract demands checking eight invariant classes across that whole state definition—Lineage, Authority, History, Time, Beliefs, Relationships, Norms, and Provenance—to ensure the transition adheres to all policy predicates. It’s a comprehensive check on the agent's entire operational DNA before we even consider whether it can execute that move.

Elias: That level of detail is what gives it its power, but the paper does acknowledge that it relies on assumptions about the checker and evaluator being sound, which they call conditional soundness. It doesn't prove the implementation itself.

Priya: That assumption about soundness is something we have to be careful with when thinking about real-world deployment; if the assumptions are wrong, the entire verification framework might not catch a subtle policy violation that an agent actually performs. What kind of assumptions are they making there?

Nadia: The paper states that it’s conditional on the specified checker and evaluator assumptions, meaning we need to trust those tools to correctly implement the logic defined by the eight invariant classes and the ternary decision procedure—VALID, INVALID, or INDETERMINATE.

Elias: And those assumptions are what allow them to use things like IdentityLineageBench to generate transition families and check against those five hundred seventy-six canonical labels to establish synthetic conformance metrics. It’s a way of testing the *contract*, not necessarily testing the perfect deployment.

Priya: So, so we're looking at a system that attempts to formally capture the rules of governance for persistent AI agents by defining this contract, and then using benchmarks to see how well that contract holds up against various types of changes. That sounds like a solid starting point for understanding agent compliance.

Nadia: Exactly, Priya; it’s about establishing that formal structure first, which then allows us to have more meaningful conversations about what kind of security we need when deploying these agents into the real world.

Elias: And that contract is built around things like the policy t, which specifies lineage, authority, history, time, belief, relationship, normative, and provenance predicates. It’s all about binding the agent's actions to a pre-state governance artifact Nt.policy ref.

Priya: It sounds like this work is less about finding a single exploit and more about creating a comprehensive verification language that can assess the overall compliance of an agent’s long-term operational path, which is something we really need for privacy assurance.

Nadia: That’s the high-level goal; it moves us into the realm of verifiable governance for AI agents, which is a crucial area for security research right now. This sets up the next part of our discussion where we look at how they improve this foundational test itself.

The paper's summary: Elias: Now that we’ve discussed the structure of the Cognitive Continuity Test, let’s get into what the paper actually summarizes about its core mechanism. They are summarizing how the CCT functions as a policy-relative contract designed specifically to verify explicit agent-state transitions in persistent AI agents.

Nadia: So, essentially, they’re summarizing that the CCT takes a predecessor state X t, a witness tau t, the successor state X t+one and some trusted context to return one of three verdicts: VALID, INVALID, or INDETERMINATE. The key is that it distinguishes between verified admissibility, an affirmative violation of policy, and unresolved required evidence.

Priya: That distinction between those three outcomes is vital for practical application; knowing when something is definitively wrong versus when we just need more data helps us manage our expectations about agent behavior in a complex system. What does the INDETERMINATE verdict mean in this context?

Elias: When the verdict is INDETERMINATE, it means that there are no contradictions established, but there is still unresolved required evidence needed to make a final call on admissibility; it supports "retry and audit without admitting unsupported transitions".

Nadia: That’s the practical benefit—it lets us audit without having to admit we don't have enough proof for a transition that might actually be valid under different interpretations of the policy. They are summarizing that the supported claim is simply conformance of structured transition records to declared policy.

Priya: From a measurement perspective, if we use this framework, we’d be looking for transitions where the data strongly points toward VALID or INVALID rather than INDETERMINATE, because those are the actionable states for our analysis. It helps us filter out the ambiguous noise.

Elias: And they summarize that this process is supported by a set of eight invariant classes—Lineage, Authority, History, Time, Beliefs, Relationships, Norms, and Provenance—which collectively form the checks C that determine the final verdict.

Nadia: So they are summarizing that this multi-faceted check ensures comprehensive coverage across all aspects of the agent’s operational definition, making it a very thorough way to assess adherence to policy compared to simpler checks.

Priya: It sounds like they’ve mapped out a complete landscape for state verification, covering everything from the temporal consistency of knowledge acquisition to the relationships that might change over time. That’s quite broad coverage for one test structure.

Elias: Indeed, it shows that they are not just looking at one aspect of continuity but ensuring all aspects are checked against their respective policy predicates defined in t.

Nadia: So, to summarize the paper's summary, it’s a formal contract that uses specific components like scoped authority and candidate-persistence receipts to distinguish between valid transitions, violations, and unresolved evidence based on an evaluation of eight invariant classes.

Priya: It’s a very rigorous way to characterize agent continuity by tying the transition record directly back to the declared policy artifact. That linkage is what gives it its weight in terms of data integrity for any subsequent analysis we do.

The paper's improvements: Nadia: Now that we understand how the CCT works, let’s look at the specific improvements the authors suggest to make this framework more robust and applicable for real deployment scenarios. They aren't just presenting a static test; they are suggesting ways to enhance it.

Elias: The paper suggests several enhancements, including introducing an executable post-resolution verifier, which allows for reproducible classification artifacts and provides a concrete way to get the results out of the system. This is important because it moves us from just theoretical checks to something that can be run and tested.

Priya: An executable verifier sounds like it solves some of the implementation worries we mentioned earlier; if we have a runnable tool, we can test how well this framework actually catches those subtle policy violations in a real-world scenario, which is much more valuable than just seeing theoretical results.

Nadia: That’s right; and they also highlight the need for additional validation for things like natural-language extraction quality and ensuring live-runtime exclusivity. They acknowledge that their current structure doesn't fully guarantee those aspects on its own.

Elias: And a specific improvement is the focus on the Authority invariant, which requires checking if every operation has authorized credentials under the pre-state governance, explicitly stating that missing credentials yield UNKNOWN, and an excluded signer or insufficient scope yields FAIL.

Priya: That sounds like they are directly addressing the need for stronger security guarantees against unauthorized succession claims by making the authority check a hard stop, rather than just a soft warning. That’s something we can definitely use in our privacy assessments of agent interaction.

Nadia: They also suggest a mechanism for "policy-permitted forgetting" of working memory while strictly preserving the order and timestamps of prior events through authorized tombstones, differentiating this controlled revision from unauthorized memory poisoning. That’s a nuanced improvement for managing agent persistence responsibly.

Elias: And finally, they suggest a way to recover from failures by replaying only the authenticated committed suffix to the last activated state, which helps mitigate "stale rollback masquerades" by ensuring that stale or uncommitted content doesn't become the operational successor. It’s about robust failure recovery for persistence.

Priya: So, these improvements seem geared toward making the CCT a more practical tool—giving us a way to test it executably, strengthening the authority checks, and handling complex scenarios like controlled memory revision in a way that respects data integrity.

Nadia: Exactly; they are moving toward an operational system where we can actually see if these formal contracts hold up under stress, rather than just seeing them work in isolation against generated transition families. This is where the real security value lies.

Conclusion: Elias: So, to wrap up our discussion on "The Cognitive Continuity Test: Verifying Governed State Transitions in Persistent AI Agents," we’ve seen how this framework establishes a formal contract for verifying agent state transitions using scoped authority, provenance records, and deterministic application.

Nadia: We’ve covered how the CCT evaluates eight invariant classes—Lineage through Provenance—to distinguish between valid transitions, violations, and unresolved evidence based on a ternary decision procedure. The paper shows that this approach moves us toward verifying the conformance of structured transition records to declared policy.

Priya: From my viewpoint, the implications are that we can start demanding a formal contract for every significant change in agent state rather than just observing behavior, which is a big step for auditing and data integrity.

Elias: And I see the improvements—the executable verifier and the focus on strengthening authority checks—as crucial steps toward making this framework more practical, addressing implementation concerns while reinforcing the necessary cryptographic bindings.

Nadia: So, in essence, we’re looking at a system that provides a verifiable way to check if persistent AI agents are adhering to their governance through a formal contract called the Cognitive Continuity Test. It’s a framework for establishing agent continuity verification.

Priya: I think the most important part is establishing this baseline of synthetic conformance so that when we deploy systems, we have a clear yardstick to measure how much policy adherence we are actually achieving in practice.

Elias: And the full picture of "The Cognitive Continuity Test: Verifying Governed State Transitions in Persistent AI Agents" is that it’s a solid framework for establishing agent continuity verification.

Nadia: That’s everything we have on this paper today, and I think the next step is seeing how these formal contracts translate into actual deployed systems.

Priya: I look forward to hearing what the next set of papers brings to this field, because understanding these underlying verification mechanisms is key to building trustworthy AI infrastructure.

cs.CR, cs.AI

Submitted: 2026-09-09

Updated: 2026-09-09

Comments: 17 pages, 2 figures, 3 tables. Includes formal proofs, transition taxonomy, and benchmark schema appendices. Reference verifier and reproducible evaluation artifacts available at https://github.com/openkedge/cctbench

Code: https://github.com/openkedge/sitbench

License: http://creativecommons.org/licenses/by/4.0/

Importance score: 91/100

The gist: Persistent AI agents revise beliefs, consolidate memory, and replace execution substrates.

Key concepts

Cognitive Continuity Test (CCT)
A policy-relative contract used to verify explicit agent-state transitions by checking if a proposed change adheres strictly to declared policies. It returns VALID, INVALID, or INDETERMINATE based on contradictions or missing evidence.
Explicit Identity State (Xt)
The complete snapshot of an AI agent at any moment, including its history (Ht), memory (Mt), beliefs with justifications (Bt), and governance commitments (Nt). This detailed structure allows the CCT to verify transitions against a comprehensive context.
Deterministic Application
The process where a candidate state is computed by applying a proposed mutation manifest to the current state. This ensures that the resulting successor state is calculated consistently, allowing for direct comparison against policy requirements.
Invariant Classes
Eight specific checks (Lineage, Authority, History, Time, Beliefs, Relationships, Norms, and Provenance) that the CCT evaluates. These invariants ensure various aspects of the transition—from historical agreement to operational authorization—are correctly maintained.

Terminology

Summary

Persistent AI agents revise beliefs, consolidate memory, and replace execution substrates. The Cognitive Continuity Test (CCT) introduces a policy-relative contract for verifying explicit agent-state transitions using scoped authority, provenance, deterministic application, semantic predicates, and candidate-persistence receipts to distinguish verified admissibility from affirmative violation or unresolved required evidence.

The Core Contract: Cognitive Continuity Test (CCT)

The CCT is defined as a policy-relative contract for verifying explicit agent-state transitions. It takes the predecessor state Xt, witness τt, successor Xt+1, and trusted context to return one of three verdicts: VALID, INVALID, or INDETERMINATE. A known contradiction yields INVALID; unresolved required evidence yields INDETERMINATE when no contradiction is established. This distinction supports retry and audit without admitting unsupported transitions. The supported claim is the conformance of structured transition records to declared policy.

State and Witness Modeling

The explicit identity state Xt is defined as a tuple: Xt = ⟨Ht, Mt, Kt, Bt, Rt, Nt, St⟩. This includes the authenticated event chronicle (Ht), mutable memory store (Mt), acquired knowledge (Kt), beliefs with justifications and revision history (Bt), relationships and disclosure metadata (Rt), governance and policy commitments (Nt), and explicit self-model fields (St). A mutation manifest ∆t = (δ1,..., δm) contains typed operations with targets, arguments, and preconditions. Deterministic application computes the entire candidate or fails: Xbt+1 = Apply(Xt, ∆t). The proposal digest qt is defined as ⟨id, t, pt, ∆t, At, Et⟩.

The Verification Procedure

The verification process follows Algorithm 1: VERIFYCOGNITIVECONTINUITY. It involves a series of stages:

  1. Stage 0: Deterministic Historical Policy Resolution to obtain the resolved policy Πbt from Nt.policy ref using a trusted resolver omega.

  2. Stage 1: Lineage and Cryptographic Integrity (Ilin), checking if predecessor, identity, epoch, protocol version, and policy-required head evidence agree.

  3. Stage 2: Authority and Governance Verification (Iauth), ensuring Every operation requires scoped credentials under pre-state Nt.

  4. Stage 3: Provenance Completeness (Iprov), verifying that DependencyResolved(δ, Et, Πt,prov) must hold for every policy-required dependency of each operation.

  5. Stage 4: Deterministic State Application (Capply), checking if Xt+1 = Apply(Xt, ∆t).

  6. Stage 5: Semantic Invariant Evaluation and Attestations (Ihist, Itemp, Ibel, Irel, Inorm).

Invariant Classes and Separation Results

The CCT evaluates eight invariant classes: Lineage (Ilin), Authority (Iauth), History (Ihist), Time (Itemp), Beliefs (Ibel), Relationships (Irel), Norms (Inorm), and Provenance (Iprov). The separation results concern transition claims rather than live runtime identity. Key propositions include:

(Proposition 1)

How it works

The CCT evaluates a set of checks C = [Cpol, Capply, Ilin, Iauth, Iprov, Ihist, Itemp, Ibel, Irel]. The ternary decision is determined by: INVALID if F ≠ ∅, INDETERMINATE if F = ∅ and U ≠ ∅, or VALID if F = U = ∅. This structure ensures that a present independent contradiction dominates missing evidence.

Key Invariant Predicates

(Ilin)

Lineage requires: "(1) predecessor, identity, epoch, protocol version, and policy-required head evidence agree; (2) Xt+1 = Apply(Xt, ∆t); (3) pre-state governance authorizes every operation; (4) policy-required dependencies resolve with matching content commitments; and (5) all declared semantic predicates Pk hold."

(Iauth)

Authority requires: ∀δ ∈ ∆t: Authorized(δ, qt, Nt, Πt,auth). Missing credentials yield UNKNOWN; an excluded signer or insufficient established scope yields FAIL.

Evaluation Methodology

The evaluation uses IdentityLineageBench to generate 24 transition families covering legitimate changes (L1–L10), invalid mutations (I1–I10), and evidence gaps (D1–D4). The six arms of evaluation include: State similarity, Memory overlap, SIT, Lineage only, CCT, and Fixture oracle. The results establish synthetic conformance, not superiority to a policy-aware deployed system.

Improvements for AI systems

Here are the specific improvements to AI systems that can be made by applying the Cognitive Continuity Test (CCT) framework, based on the provided paper:


  1. A system implementing CCT can distinguish between a state transition claim being definitively authorized, affirmatively violated, or requiring further evidence.

  2. The improved system will provide a formal contract (the CCT) for verifying explicit agent-state transitions using scoped authority and provenance records rather than just behavioral similarity benchmarks.

  3. The system will be capable of rejecting unauthorized succession claims even if they retain the predecessor's memories and behavior, by checking the required Authority invariant in the CCT.

  4. The system will prevent behavioral cloning or impersonation attacks by requiring specific, authenticated credentials (via the Authority predicate) for any operation that modifies state, rather than just verifying similarity to a past state.

  5. The improved system will maintain an audit trail where every proposed state change is bound by a signed witness core and a candidate-persistence receipt, ensuring that historical audits remain valid even if the live runtime changes.

  6. The system will allow for policy-permitted forgetting (L6) of working memory while strictly preserving the order and timestamps of prior events via authorized tombstones, differentiating this controlled revision from unauthorized memory poisoning (I16).

  7. The system will enforce temporal consistency by verifying that any new knowledge acquisition time is not backdated relative to its authenticated acquisition time, preventing temporal regression (I8) attacks.

  8. The system will validate belief revisions (L3) only when accompanied by authentic, scoped support records matching the required proposition, value, and confidence thresholds defined in the policy.

  9. The system will ensure that relational changes (L4), such as trust elevation or count updates, are supported by authenticated positive interaction records that meet specific cardinality and uniqueness constraints, preventing fabricated metrics from supporting later authority claims (I4).

  10. The system will provide a robust mechanism for recovering from failures by replaying only the authenticated committed suffix to the last activated state, ensuring that stale or uncommitted content does not incorrectly become the operational successor (L9), mitigating stale rollback masquerades (I8).

  11. The system will allow for verification of complex, multi-step lineage continuity across a sequence of transitions by checking transitive invariants, ensuring that the entire chain of events adheres to the policy constraints.

  12. The system will be capable of running an offline post-resolution verifier against generated transition families (IdentityLineageBench) to establish synthetic conformance metrics for its policy adherence before deployment.

Abstract

Persistent AI agents revise beliefs, consolidate memory, and replace execution substrates. Similar successor states can accompany differently authorized transition claims, while legitimate development can change state substantially. We introduce the Cognitive Continuity Test (CCT), a policy-relative contract for verifying submitted transitions using scoped authority, provenance, deterministic application, semantic predicates, and candidate-persistence receipts. CCT distinguishes verified admissibility, affirmative violation, and unresolved required evidence. Separation results concern transition claims rather than live runtime identity; soundness is conditional on the specified checker and evaluator assumptions. IdentityLineageBench provides 24 generated transition families. The reference post-resolution verifier matches all 576 canonical held-out labels; lexical state similarity and a lineage-only diagnostic baseline admit 60.0% and 80.0% of invalid fixtures. These comparisons establish synthetic conformance, not superiority to a policy-aware deployed system. Signed adversarial regressions cover fabricated interaction counts, unsupported belief changes, and mixed missing/contradictory evidence. SIT behavior and actual model migration remain unmeasured. An 18,000-execution valid-path study measures a 6.21 ms default median on resident inputs. We specify the additional activation and recovery obligations needed for deployment.

Sources

Related papers