@techreport{das-enterprise-ai-output-finality-00, number = {draft-das-enterprise-ai-output-finality-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-das-enterprise-ai-output-finality/00/}, author = {Sangam Das}, title = {{A Compromised AI Server Must Not Become a Map of the Enterprise: Non-Joinable Vaults and Output-Release Finality}}, pagetotal = 26, year = 2026, month = aug, day = 26, abstract = {Past cyber theft stole files. Present theft steals live sessions and SaaS tokens. The next theft does not need a dump. A frontier enterprise assistant that can see mail, tickets, code, finance, and memory can join those fragments into a meaning that was never stored as one record, then act. That is enterprise-future mapping: reconstruction of strategy, relationships, and probable next moves, followed by send, write, or tool invoke {[}DAS-ISOLATION{]}. IAM, DLP, clean rooms, TEEs, and output filters still answer who may touch a store. They do not answer whether separately lawful fragments may be joined into a new protected meaning, or whether that meaning may leave through Claude, ChatGPT Enterprise, a computer-use agent, or an MCP tool. This profile keeps identity, content, and association under independently controlled vaults, joins them only under a session- bound Reconstruction Authorization Object, seals the Candidate Output, commits a receipt before release authority exists, and completes send, render, store, or invoke only at an Output Release Boundary. Compromise of the model host is not reconstruction. Reconstruction is not release.}, }