Skip to content
Sprint projectSep 14, 2026Colombia

Minimum Viable Cross-Border Response Protocol for Agentic AI Incidents (MVCRP)

Andrés Mogollón, Isabel Salazar · Team Borderless

Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.

Read the report

Report: Minimum Viable Cross-Border Response Protocol for Agentic AI Incidents (MVCRP)

Code (opens in new tab)
Share

When an autonomous AI agent escapes containment and its effects spread into infrastructure governed by a different country, there's often no single authority in charge, no one holding the complete evidence, and no agreement on what actually happened. Using the real July 2026 OpenAI–Hugging Face incident as a starting point, we built a counterfactual scenario propagating the same class of attack across the US, Colombia, and China, three jurisdictions with very different legal systems, and tested whether a coordination protocol could hold up as authority, evidence, and each country's ability to act all shifted at once. The result, MVCRP, doesn't create new legal authority or force anyone to share evidence. It gives existing responders a shared way to track what's confirmed, what's disputed, who can act, and why an incident is or isn't ready to close, so a disagreement in one country doesn't block a justified response in another.

Reviews

Judging this Sprint?

Review this project

Your public critique appears on this page without your name. Your private critique is not published; only the Apart team reads it. If you agree below, we share your review with grantmaking.ai (opens in new tab) and the Transformative AI Fund so strong projects can be funded.

Not shown on this page.

Shown on this page, without your name.

Only the Apart team reads this, and funders if you agree below.

Share my name publicly on grantmaking.ai *
Share my private critique with funders *

How much would this matter for AI safety if it worked? How innovative is it? For scores of 4-5: is this actually new to the field, or replicating recent work?

Scoring guide
  1. 1Negligible. No clear problem addressed, or no meaningful novelty.
  2. 2Limited. Addresses a real problem but with a generic or well-trodden approach. Incremental at best.
  3. 3Moderate. Clear problem with a reasonable approach; some novelty in framing or method beyond routine application of existing tools.
  4. 4Significant. Important problem with an original approach, or identifies a neglected problem area. A valuable contribution others could build on.
  5. 5Exceptional. Tackles a critical AI safety problem with a genuinely novel approach, or opens a new research direction. Clear theory of change. You'd be excited to share this with researchers in the area.

How sound are methodology, implementation, and findings?

Scoring guide
  1. 1Seriously flawed. Methodology broken, results uninterpretable, or implementation doesn't work.
  2. 2Weak. Approach has significant gaps: missing validation, flawed experimental design, or incomplete implementation.
  3. 3Competent. Technically solid given the short duration. Methodology makes sense, results are interpretable, limitations acknowledged, work builds toward clear conclusions.
  4. 4Strong. Thorough methodology with convincing validation. Results clearly support conclusions. Immediately useful for future work.
  5. 5Exceptional. Ambitious scope executed rigorously. Surprising findings, novel methods, or unusually robust validation.

How clearly are work, findings, and impact potential communicated?

Scoring guide
  1. 1Incomprehensible. Cannot determine what the project is actually claiming or doing.
  2. 2Hard to follow. Key information buried, missing, or diluted by excessive length. Significant effort to extract main points.
  3. 3Clear enough. Can understand the problem, approach, and results without undue effort. Core content clearly present: problem, method, findings, limitations.
  4. 4Well presented. Easy to follow, well-structured, appropriate level of detail. Target audience would get it quickly.
  5. 5Exceptionally clear. A pleasure to read. Complex ideas made accessible. Could serve as a model for how to present this type of work.

  1. I am honestly unsure what this project accomplishes, and I think the authors may have relied too heavily on AI tools.

  2. Most work on AI incidents concerns reporting. This paper takes up what comes after a report, which is how independently governed parties coordinate a response when an incident crosses borders. That is a useful problem to work on. The paper also observes that legal assistance operates over weeks, while agents in the source incident moved from credential discovery to remote code execution in about thirty hours. That observation is a valuable point. My concerns are with whether the report can be evaluated on its own and with what the stress test is able to show.

    The report does not contain the protocol. The six components are named and never specified, and the values of the three status dimensions are never given. The text refers to Section 2, Section 3.2 to 3.4, and Section 5, yet the report has no numbered sections. Terms such as “L3 evidence” and “NO_ROUTE” appear without definition. The specification sits in a separate seven-page document in the project repository, and the report cites that document’s sections without naming it. The companion defines the state values, the evidence levels, and the record fields. A reader of the report alone sees only the names of the parts.

    The stress test cannot fail. The same team abstracted the events, built the scenario, designed the protocol, and judged each outcome. This is like a student who writes the exam, sits the exam, and grades it. A passing mark tells us little. The pass criterion adds to the problem. It asks whether the protocol can represent a situation. Representing a situation means the protocol has a place to record it. Resolving a situation means responders using the protocol reach a better outcome. The test addresses only the first, and the situations were written by the people who chose what the protocol records. Thus, each “Holds” in Table 2 restates a design feature. Whether an event requires a seventh component is also a judgment made by the designers, so the stated failure conditions are less objective than they appear. The authors acknowledge much of this in their limitations. The conclusion nonetheless says the protocol held at every event.

    The protocol is not specific to agentic AI. It would apply unchanged to any propagating cyber incident. Agentic incidents differ in ways that matter for containment. For example, the originating developer can often shut down the model or revoke its access. Conventional malware offers no comparable lever at the source, and the distributed containment analysis does not use it.

    Two claims lack support. The paper states that separating the status dimensions costs nothing. Three dimensions plus confidence on every claim is more for responders to maintain under time pressure, and no usability evidence is offered. Additionally, the legal readings for all three jurisdictions had no practitioner review, and the routing results depend on them.

    The reference list and the text do not match. Many entries are never cited or mentioned. The EU AI Act is discussed in the text and does not appear in the list. Several entries point to an organization’s home page with no date. The entries I checked are real works and are described accurately, so this is a matter of reconciling the list with the text.

    Read full reviewShow less

Cite this project

@misc{mogollon2026minimum,
  title = {{Minimum Viable Cross-Border Response Protocol for Agentic AI Incidents (MVCRP)}},
  author = {Andrés Mogollón and Isabel Salazar},
  year = {2026},
  month = sep,
  note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
  howpublished = {\url{https://apartresearch.com/sprints/projects/minimum-viable-crossborder-response-protocol-for-agentic-ai-incidents-mvcrp-qsj8}},
  url = {https://apartresearch.com/sprints/projects/minimum-viable-crossborder-response-protocol-for-agentic-ai-incidents-mvcrp-qsj8}
}

Build something like this at the next Sprint

AI Collusion Research Sprint · Oct 23 - 25, 2026