Sondera Compiles Natural-Language Rules into Provable Control Over AI Agent Actions
Sondera's autoformalization research was accepted at ICML 2026's Agents in the Wild workshop and at FLoC 2026's LLM-Solve workshop, with a related tool demo at
The paper, "Autoformalization of Agent Instructions into Policy-as-Code," by Sondera's
In peer-reviewed research using MedAgentBench, an independent benchmark for clinical AI agents published in
Autoformalization is critical for enforcing agent policies because real policy and business logic live in natural language — in documents like a HIPAA manual, FINRA guidelines, a standard operating procedure, or an agent's own instructions. Traditionally, turning natural-language policies into something a machine can enforce has meant hand-coding rules one at a time, which does not scale to how fast agents are being deployed.
Sondera's pipeline reads the natural language and compiles it directly into formally verified Cedar policy-as-code, with a theorem prover checking every rule and adversarial simulation stress-testing it before production, both to find edge cases and to confirm that legitimate work is still permitted. The approach is neurosymbolic: neural classifiers such as LLMs-as-judges evaluate what an agent is doing probabilistically, while symbolic rules decide deterministically what the agent is allowed to do.
At runtime, a verified deterministic rule returns a decision (such as allow, deny, or escalate) for each agent action. Because the policy-as-code is enforced deterministically outside the context window, rather than relying on an AI-as-judge, issues such as prompt injection, emergent behavior, and model drift cannot talk the policy enforcement layer out of its rules. And because enforcement is stateful, tracking the agent's full trajectory and the flow of information across it, the same action can be allowed or denied depending on what the agent did earlier in the run.
"The agent incidents we see today aren't from prompt injection and hijacking. They're from authorized humans asking authorized agents to do legitimate tasks, like analyzing a financial file or configuring a server. Along the way, the agent reaches the goal with unintended behavior, like leaking or destroying data," said
Sondera's policy and agent control plane is currently in private beta. Teams interested in participating can visit sondera.ai.
The full paper "Autoformalization of Agent Instructions into Policy-as-Code" is available at arxiv.org/abs/2606.26649.
Sondera's open-source harness and SDKs are at github.com/sondera-ai.
About Sondera
Sondera gives enterprises provable control over AI agents, in natural language. Its approach is neurosymbolic: neural classifiers detect what an agent is doing, symbolic rules decide what it is allowed to do. Through a process called autoformalization, Sondera compiles an organization's natural-language rules into formally verified Cedar policy-as-code, checked by a theorem prover and enforced on every action an agent takes, on any agent runtime or harness. Because symbolic enforcement runs outside the model and across the full run, prompt injection and drift can't bypass it, and the same action can be allowed or denied based on what the agent did before it.
Teams use Sondera to apply complex business logic, security, and compliance rules to coding agents, the agents they build, and the agents they sell. Open-source harness at github.com/sondera-ai. Learn more at sondera.ai.
Contacts
Media Contact
[email protected]
View original content to download multimedia:https://www.prnewswire.com/news-releases/sondera-compiles-natural-language-rules-into-provable-control-over-ai-agent-actions-302814775.html
SOURCE Sondera, Inc.
Serious News for Serious Traders! Try StreetInsider.com Premium Free!
You May Also Be Interested In
- Extra Space Storage Inc. Announces Date of Earnings Release and Conference Call to Discuss 2nd Quarter Results
- DELETED: Teremana® Tequila Unites Fans from Around the World for a Record-Breaking Foosball Experience
- Nexera Announces Closing of Private Placement of Units (Under Partial Revocation Order)
Create E-mail Alert Related Categories
PRNewswire, Press ReleasesSign up for StreetInsider Free!
Receive full access to all new and archived articles, unlimited portfolio tracking, e-mail alerts, custom newswires and RSS feeds - and more!



Tweet
Share