Skip to main content
Docs/Failure-Mode Library

AI Trust Failure-Mode Library

Reference failure modes for AI systems. Each entry describes the failure mode, affected architecture, potential impact, relevant target Vallum patterns, evidence a future implementation would need, and explicit Build 01 limitations.

Important: These entries describe reference failure modes. They are not error codes emitted by the named third-party platforms unless explicitly documented otherwise. They represent architectural risk patterns that may occur in AI systems and target controls that would require production implementation and independent assessment. Build 01 operates no Vallum service, compliance review, or customer evidence pipeline.

VTF-001

Unbounded Agent Output in Regulated Deployment Pipeline

Affected Architecture

AI agents integrated into CI/CD or deployment workflows

Preconditions

An AI agent produces outputs that vary across invocations. A deployment pipeline may need bounded, reviewable outputs for assurance or documentation. No structural boundary exists between the agent's output and the downstream system.

Potential Impact

Unverifiable agent behavior in production, difficulty reproducing or reviewing specific outputs, documentation gaps, and inability to demonstrate that deployed behavior matches tested behavior.

Target Vallum Pattern

The target Titan Handshake design would record an authorization decision before a deployment proceeds. A future Titan Verify adapter could assemble supporting records showing what was authorized, by whom, and under which policy; Build 01 does not operate either service.

Reference Evidence a Future Implementation Would Need

Target records: authorization decision, policy evaluation, and deployment-decision evidence manifest

Limitations

The target design would not make LLM outputs deterministic or replace output validation. Build 01 records local policy and evidence examples only; schema enforcement and deployment controls remain application responsibilities.

Additional External Controls Required

Application-level output validation, model testing frameworks, CI/CD security policies, deployment approval workflows

VTF-002

Cross-Tenant Data Exposure in Multi-Tenant AI System

Affected Architecture

Multi-tenant AI applications with shared infrastructure (vector databases, model endpoints, caching layers)

Preconditions

Multiple tenants share underlying infrastructure. Application-level tenant filtering contains a bug or misconfiguration. A query from Tenant A returns data belonging to Tenant B.

Potential Impact

A data breach affecting one or more tenants, loss of trust, and potential notification, contractual, or legal obligations that qualified counsel and security professionals must assess.

Target Vallum Pattern

The Build 01 policy reference denies cross-tenant requests in local tests. A production Titan Handshake design would need identity-bound tenant enforcement, durable isolation, and private evidence handling; no hosted Verified Ops or public verification endpoint exists.

Reference Evidence a Future Implementation Would Need

Target records: tenant-scoped policy decisions, cross-tenant denials, and isolation-boundary events

Limitations

Build 01 does not control a customer database, memory store, cache, network, or identity provider. Its local tenant checks are not production isolation. Any future integration would protect only explicitly routed operations, while each application remains responsible for its own data boundaries.

Additional External Controls Required

Application-level tenant isolation in data stores, vector database namespace enforcement, infrastructure-level network segmentation, regular penetration testing

VTF-003

Uncontrolled Metadata Disclosure via Agent Tool Calls

Affected Architecture

AI agents with external API access (tool-use, function-calling, plugin systems)

Preconditions

An AI agent makes outbound API calls to third-party services. The agent includes operational metadata (user identifiers, internal state, business context) in request parameters or headers. No boundary exists between internal context and outbound communications.

Potential Impact

Gradual disclosure of business intelligence through aggregated metadata. Competitive intelligence leakage. Privacy violations if personal data is included in outbound requests. Potential regulatory exposure under data minimization requirements.

Target Vallum Pattern

A future policy boundary could record outbound-operation decisions when calls are explicitly routed through it. Build 01 demonstrates proposal-only orchestration and does not inspect, filter, transmit, or audit customer API calls.

Reference Evidence a Future Implementation Would Need

Target records: outbound-operation policy decisions and approved-communication events

Limitations

Build 01 has no customer egress path or network enforcement. A future policy record would not itself sanitize payloads; content filtering, data-loss prevention, and outbound-request controls remain application and network responsibilities.

Additional External Controls Required

Outbound request sanitization middleware, data loss prevention (DLP) tools, network-layer egress controls, API gateway policies, agent tool-call allowlists

VTF-004

Unauthorized Operation Execution via Instruction Manipulation

Affected Architecture

AI agents with tool access where permissions are defined in prompt context

Preconditions

An AI agent's permissions are defined within its prompt or instruction context. An attacker injects instructions (via user input, processed documents, or retrieved content) that cause the agent to execute operations beyond its intended scope. No external permission enforcement exists.

Potential Impact

Unauthorized data access, record modification, or workflow execution. Privilege escalation that bypasses intended access controls. Audit trails that appear legitimate (the agent 'chose' to act) making detection difficult.

Target Vallum Pattern

The Build 01 policy reference evaluates permissions outside model output. In a correctly integrated future design, an injected instruction could not expand policy-granted permissions for operations that are actually routed through that boundary.

Reference Evidence a Future Implementation Would Need

Target records: out-of-scope denials and policy evaluations showing checked permissions

Limitations

Build 01 does not protect deployed operations or prevent prompt injection. The pattern would cover only operations routed through a production policy boundary; direct database access, unprotected APIs, compromised credentials, and human approval failures remain outside that boundary.

Additional External Controls Required

Comprehensive operation gating (all sensitive operations require authorization), input sanitization, agent sandboxing, least-privilege infrastructure access, monitoring for anomalous agent behavior

VTF-005

Incomplete Audit Trail for Automated Operational Decisions

Affected Architecture

AI-assisted operational workflows (deployment approvals, configuration changes, artifact releases)

Preconditions

An AI system participates in operational decisions (e.g., approving a deployment, recommending a configuration change). The decision is executed but no structured evidence records why the decision was made, what inputs were considered, or what policies were evaluated.

Potential Impact

Difficulty investigating automated decisions, documenting control operation, answering why an action occurred, or supplying evidence requested by auditors, regulators, customers, or incident responders.

Target Vallum Pattern

Build 01 demonstrates local policy decisions, typed events, redaction, deterministic hashes, and tamper checks. A future Handshake, Verify, and Sign implementation could connect those patterns to durable identity-bound records, but no such hosted pipeline operates today.

Reference Evidence a Future Implementation Would Need

Target records: bounded decision context, evidence-chain manifests, signature metadata, and controlled status references

Limitations

Build 01 produces only local reference evidence. A future implementation would capture only explicitly integrated operations; direct API calls, manual actions, unprotected systems, and off-platform decisions would remain outside its coverage.

Additional External Controls Required

Comprehensive integration of auditable operations with Titan Handshake, application-level logging for non-Vallum operations, log aggregation and SIEM, regular audit gap assessments

Discuss the reference patterns

Submit an early-access request to discuss requirements and questions. This is not an architecture assessment, compliance service, audit, certification, or commitment to provide professional advice.

Request an early-access discussion