Policy Is Not Proof: What Machine-Checked Declassification Changes for Security Teams
TL;DR for operators When software is intentionally allowed to disclose some sensitive information, a release rule and proof of compliance should not be the same object. David A. Naumann’s Assuming You Knew: Fixing an Epistemic Semantics for Flow Policies Using Agentic AI1 repairs an earlier framework by giving permitted information release an explicit meaning, then separately defining whether an observer learned more than that policy allows. ...