Skip to content
Preprint

BEGIN AI TRANSACTION: Semantic Isolation for Durable AI Workflows

Aug 2026 · 1 citation · 21 references
Computer Science

TL;DR

The prototype, SemIso, propagates semantic context and blocks incompatible resources and branch merges with microsecond-scale checks and shows that these guarantees can be checked and enforced efficiently in middleware.

Abstract

An AI execution can now outlive the environment in which it began. What once fit inside one model call increasingly unfolds across pauses, retries, branches, subagents, and model-selected tools. Meanwhile, prompts, model aliases, indexes, policies, and tools are deployed independently: stable names can acquire new behavior, and workflows can discover resources only after they start. The workflow can therefore combine saved state with changed assumptions, producing an internally inconsistent result even when every call succeeds. This is an isolation problem: database transactions constrain concurrent data updates, but workflow checkpointing provides no corresponding contract for concurrent changes to an AI workflow's semantic environment. We define four automatically detectable anomalies: semantic read skew, compatibility skew, context escape, and merge skew. To control which anomalies are allowed, we derive a partial order of isolation levels, from Semantic Read Committed to Semantic Snapshot Isolation, by combining three independent guarantees: resource stability, cross-resource compatibility, and continuation inheritance. In a conservative source audit of the 100 most-starred public repositories with executable LangGraph code, we find that 7.4 percent of codebases with durable workflows resolve live or dynamically selected semantic resources within the same workflow, without an evident immutable binding. We show that these guarantees can be checked and enforced efficiently in middleware. Our prototype, SemIso, propagates semantic context and blocks incompatible resources and branch merges with microsecond-scale checks.

View source

Similar papers

Preprint Aug 2026

When"Must"Becomes"Maybe": Constraint Weakening in LLM Agent Workflows

This work identifies a state-transmission failure between information extraction and action in large language model agents, and shows how handoff transformations can retain state content while weakening its constraints on downstream action.

Yi-Heng Sun, Huifei Wang, Yan-Cheng Zhu et al. · 2 citations
#artificial intelligence Preprint Sep 2026

CordisBench: Can Language Models Reason About Component Lifecycles in Dynamic Agent Harnesses?

CrisBench, a 1,200-question benchmark of lifecycle reasoning that combines a controlled formal setting with programs executed against Cordis, a runtime that manages component dependencies and cleanup, and asks models to identify affected components, predict state after a specified teardown order, and determine which co...

Damien Sileo, Dimitri Kachler · 0 citations
#artificial intelligence Preprint Sep 2026

REVISE: Validity-Guided Recovery for Online Revisions in Agent Workflows

This work presents \textsc{Revise}, a validity-guided runtime for fine-grained recovery in structured agent workflows, a validity-guided runtime for fine-grained recovery in structured agent workflows that matches a latest-version oracle with no stale outputs or effects.

Ruoling Qi, Xuan'er Wu, Peng-Hang Liu et al. · 0 citations
#artificial intelligence Preprint Sep 2026

Fresh Memory, Stale Plans: Dependency-Scoped Validation for Distributed LLM-Agent Memory

Distributed LLM-agent teams can read the latest shared facts and still act on an obsolete plan. A planner may derive an action from requirement $r_3$, another agent may commit $r_4$, and an executor may receive $r_4$ without replacing the plan derived from $r_3$. We call this \emph{stale-plan execution}: state freshnes...

Evan Chen, Shi-Qiang Wang, Christopher G. Brinton · 0 citations
Preprint Jul 2026

PULSE: An Executable Contract Language for Spatiotemporal Knowledge Graph Engineering

This work presents PULSE, an Object-Process-Methodology-inspired language that localizes four operational roles and their write effects in one typed runtime, here, modes denote operational roles rather than modal or deontic logic.

Dongxu Yang, Zi-Yi Liang · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.