cs.PLMay 13, 2026

Language-Based Agent Control

Authors: Timothy Zhou, Loris D'Antoni, Nadia Polikarpova

Abstract

This paper introduces language-based agent control (LBAC), a new programming model for agentic applications that brings techniques from programming languages and language-based security to the problem of agent control. In conventional programming, combinations of static typing and runtime enforcement have long been used to guarantee that well-typed programs satisfy user-specified policies, including policies for access control, information flow, data provenance, and more. The key idea behind LBAC is to extend these guarantees to agentic applications by requiring agents to generate programs that are themselves well typed in the context of the surrounding scaffolding code. Unsafe programs are rejected by the type-checker before execution, allowing policies to apply uniformly across the entire application, including both agent-generated behavior and developer-written scaffolding. At the same time, LBAC preserves substantial expressiveness: agents may perform arbitrary side-effect-free computation and recursively invoke subagents, which retain full tool access subject to the same -- or potentially more restrictive -- policies. We demonstrate LBAC with three case studies: I/O sandboxing via filesystem capabilities, data provenance, and information-flow control.

Explore similar work

CardsList
  1. LACUNA: Safe Agents as Recursive Program Holes

    May 27, 2026Yaoyu Zhao, Yichen Xu, Oliver Bračevac +3Runtime EnforcementCode Generation

  2. Agentic Permissions Policy Algebra for Taint Confinement in LLM Agents

    Jul 27, 2026Arseny Kravchenko, Vadim Liventsev, Innokentii Konstantinov +2Untrusted InputLarge Language Model Agents