BP3 Precedent Gates for AI Incident Response
Alan Yang · Team Alan AI safty
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
BP3 is an incident-response protocol that separates permission from precedent evidence: it passes qualified familiar actions, stops known hazards, and holds uncertain actions for bounded local investigation.

Reviews
The author dismantles their own novelty claim in three places. Related Work concedes that "access control, evidence reuse, and isolated testing are established mechanisms" and that the work "does not establish novelty or superiority over more complete policy engines." The comparison is against "a deliberately minimal permission baseline, not a state-of-the-art security system," so 5/50 against 40/50 is beating a strawman by construction. And the Discussion goes further: "more of the benefit may be obtained by strengthening ordinary policy enforcement without a shared precedent system." That is the author saying the contribution may be unnecessary.
The archive isn't hosted. Everything else about the reproducibility story is done well- the hashes, the manifest, and the exact commands- and none of it is checkable by a reader.
This project provides a rigorous and methodical approach to autonomous agent containment, moving well beyond weak reach conformance baselines. The inclusion of deterministic ablations, audit chain certification and transparent failure analysis regarding concealed tool semantics makes this a standout contribution to AI safety evaluation, Future iterations would benefit from transitioning from synthetic SQLite fixtures to live instrumented tool adapters and multi-model evaluations.
Cite this project
@misc{yang2026bp3,
title = {{BP3 Precedent Gates for AI Incident Response}},
author = {Alan Yang},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/bp3-precedent-gates-for-ai-incident-response-q7uy}},
url = {https://apartresearch.com/sprints/projects/bp3-precedent-gates-for-ai-incident-response-q7uy}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …