Recoverability as a System Primitive for Long-Horizon AI Agents

| Source: arXiv AI

Tags: AI-agents, safety, fault-tolerance, agentic-systems, alignment

A new paper argues that resuming interrupted AI agents is not a checkpoint/restore problem but a recoverability problem — requiring explicit policies that specify which starting points are valid and which recovery actions are permitted, with independent evidence to enforce them.

Details

Long-horizon AI agents editing files, calling APIs, or running multi-step tasks can be interrupted at any point. Current practice either restarts from scratch (wasting completed work) or resumes from the last saved state (potentially propagating earlier errors). Neither is safe by default.\n\nThis paper introduces recoverability as a first-class system primitive: a behavioral contract that makes resumption a deliberate decision. A valid recovery requires selecting a supported starting point, a permitted recovery action, and independent evidence validating that choice. The architecture binds these through complementary runtime instances testing distinct responsibilities.\n\nFour deterministic and 20 paired file challenges demonstrate a counterintuitive finding: accurate state restoration and successful task completion can both occur even when the starting point is not a valid resume point. Success metrics alone cannot validate recovery decisions.\n\nProgress controls attribute retained work to a shared restoration mechanism. Event-time tests show that permission must constrain the action specifically — not just the starting point — and that independently held policy evidence can expose violations even after an effect has occurred.\n\nFor teams building production agentic systems, the contribution is a testable interface specification for recovery decisions, not just a technique for checkpointing. The work is particularly relevant as multi-step AI agents move into enterprise workflows where partial execution has real consequences.