Minimum Viable Cross-Border Response Protocol for Agentic AI Incidents (MVCRP)
Andrés Mogollón, Isabel Salazar · Team Borderless
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
When an autonomous AI agent escapes containment and its effects spread into infrastructure governed by a different country, there's often no single authority in charge, no one holding the complete evidence, and no agreement on what actually happened. Using the real July 2026 OpenAI–Hugging Face incident as a starting point, we built a counterfactual scenario propagating the same class of attack across the US, Colombia, and China, three jurisdictions with very different legal systems, and tested whether a coordination protocol could hold up as authority, evidence, and each country's ability to act all shifted at once. The result, MVCRP, doesn't create new legal authority or force anyone to share evidence. It gives existing responders a shared way to track what's confirmed, what's disputed, who can act, and why an incident is or isn't ready to close, so a disagreement in one country doesn't block a justified response in another.
Reviews
I am honestly unsure what this project accomplishes, and I think the authors may have relied too heavily on AI tools.
Most work on AI incidents concerns reporting. This paper takes up what comes after a report, which is how independently governed parties coordinate a response when an incident crosses borders. That is a useful problem to work on. The paper also observes that legal assistance operates over weeks, while agents in the source incident moved from credential discovery to remote code execution in about thirty hours. That observation is a valuable point. My concerns are with whether the report can be evaluated on its own and with what the stress test is able to show.
The report does not contain the protocol. The six components are named and never specified, and the values of the three status dimensions are never given. The text refers to Section 2, Section 3.2 to 3.4, and Section 5, yet the report has no numbered sections. Terms such as “L3 evidence” and “NO_ROUTE” appear without definition. The specification sits in a separate seven-page document in the project repository, and the report cites that document’s sections without naming it. The companion defines the state values, the evidence levels, and the record fields. A reader of the report alone sees only the names of the parts.
The stress test cannot fail. The same team abstracted the events, built the scenario, designed the protocol, and judged each outcome. This is like a student who writes the exam, sits the exam, and grades it. A passing mark tells us little. The pass criterion adds to the problem. It asks whether the protocol can represent a situation. Representing a situation means the protocol has a place to record it. Resolving a situation means responders using the protocol reach a better outcome. The test addresses only the first, and the situations were written by the people who chose what the protocol records. Thus, each “Holds” in Table 2 restates a design feature. Whether an event requires a seventh component is also a judgment made by the designers, so the stated failure conditions are less objective than they appear. The authors acknowledge much of this in their limitations. The conclusion nonetheless says the protocol held at every event.
The protocol is not specific to agentic AI. It would apply unchanged to any propagating cyber incident. Agentic incidents differ in ways that matter for containment. For example, the originating developer can often shut down the model or revoke its access. Conventional malware offers no comparable lever at the source, and the distributed containment analysis does not use it.
Two claims lack support. The paper states that separating the status dimensions costs nothing. Three dimensions plus confidence on every claim is more for responders to maintain under time pressure, and no usability evidence is offered. Additionally, the legal readings for all three jurisdictions had no practitioner review, and the routing results depend on them.
The reference list and the text do not match. Many entries are never cited or mentioned. The EU AI Act is discussed in the text and does not appear in the list. Several entries point to an organization’s home page with no date. The entries I checked are real works and are described accurately, so this is a matter of reconciling the list with the text.
Read full reviewShow less
Cite this project
@misc{mogollon2026minimum,
title = {{Minimum Viable Cross-Border Response Protocol for Agentic AI Incidents (MVCRP)}},
author = {Andrés Mogollón and Isabel Salazar},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/minimum-viable-crossborder-response-protocol-for-agentic-ai-incidents-mvcrp-qsj8}},
url = {https://apartresearch.com/sprints/projects/minimum-viable-crossborder-response-protocol-for-agentic-ai-incidents-mvcrp-qsj8}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …