Cyryx Labs
Applied Research

Research for systems that must leave the lab.

Cyryx investigates the engineering and operating questions that appear when AI is expected to support real products, workflows, and decisions. The purpose is practical: better architectures, better evidence, and clearer limits.

Published research

Public records, not presentation claims.

Released work is listed with its public identifier, source record, publication date, and license so readers can verify and cite it independently.

GovernanceCC BY 4.0June 29, 2026

CGP: Cyryx Governance Protocol for Agentic AI Execution

Existing AI governance frameworks — the EU AI Act, the NIST AI Risk Management Framework (AI RMF), and ISO/IEC 42001 — were designed for AI systems operating under continuous human supervision: classifiers, recommenders, and single-turn generators. None were designed for agentic AI systems that autonomously decompose goals into multi-step plans, execute sequences of environment-modifying actions, coordinate multiple specialized sub-agents, and maintain state across sessions. Singapore's Model AI Governance Framework (January 2026) is the only published governance document that acknowledges this gap, identifying three unaddressed risks: cascading failure propagation, emergent scope expansion, and attribution gaps across agent chains. This document introduces the Cyryx Governance Protocol (CGP) v1.0, a technical framework that fills these gaps with seven control domains and twenty-eight normative controls (MUST/SHOULD/MAY). CGP is designed as an extension to existing frameworks — not a replacement — with explicit mapping to EU AI Act Articles 9, 12, 13, 14, and 15; NIST AI RMF functions GOVERN, MAP, MEASURE, and MANAGE; and ISO 42001 Clause 6, 7, 8, and 9 controls. Every control in CGP v1.0 has a reference implementation in MAAX Studio by Cyryx Labs. CGP is published under Creative Commons Attribution 4.0 (CC BY 4.0) for open community adoption and review.

Research directions

Six questions behind one operating system.

01

Execution architecture

How AI, deterministic software, tools, state, and people coordinate across a real task.

02

Context intelligence

How systems select, structure, constrain, and attribute the information used for a decision.

03

Evaluation

How representative cases, human judgment, and system signals can support release and change decisions.

04

Authority & governance

How action boundaries, review, escalation, evidence, and ownership become part of system design.

05

Cost intelligence

How model, provider, infrastructure, and human effort can be interpreted at the workload level.

06

Human-system interaction

How interfaces communicate uncertainty, evidence, control, failure, and recovery to operators.

Research discipline

Evidence before publication.

Public claims, publication records, identifiers, control mappings, and maturity statements are withheld until the underlying evidence and release approval are complete.

  1. 01

    Investigate

    Frame a precise question from product or system work.

  2. 02

    Prototype

    Build the smallest instrumented environment that can produce useful evidence.

  3. 03

    Evaluate

    Test representative behavior, failure modes, limitations, and competing explanations.

  4. 04

    Integrate

    Feed relevant findings back into product, advisory, engineering, and operating decisions.

  5. 05

    Publish selectively

    Release public material only after its evidence, attribution, limitations, and approval are ready.

From research to practice

Findings matter when they improve a product or operating decision.