Which Agent-level adversarial distinctions survive after mature security capability is imported?
Separate the Security-owned semantics that remain decision-relevant after ordinary scanners, fuzzers, execution carriers, defensive mechanisms, providers, Host, Harness, and Runtime are consumed directly.
01 / Current position
A hypothesis is not the current judgment.
The dossier preserves the live research position. Dated articles preserve the complete evidence and argument that changed it.
Exact Range/Scenario authority, asymmetric observation, independent truth/evidence, effect/recovery identity, and bounded evaluation remain Security-owned; the first Agent-level behavioral residual is conditional capability selection and replanning against current evidence/counterplay rather than a new tactical-state or Campaign subsystem.
Answered for the CA0–CA7 capability programme. CA6 showed a fixed script fail three of four held-out worlds while both a generic observation-driven deterministic adaptive policy and the canonical Harness/model Actor succeeded all four with the same oracle-regret vector; P1 reproduced the core adaptive-selection result under real provider/authority friction. The model did not establish a stronger residual than the thin adaptive policy. CA7 therefore closed by contraction: Campaign, Organization, persistent OpponentModel, coevolution, provider gateway, and cross-fidelity strategic law are not admitted by current evidence.
02 / Decision boundary
What keeps this Question alive?
Agent security research can easily rebrand classical capability, or overpromote persistent Campaign/Opponent/Organization machinery merely because adaptive opposition sounds complex. The residual should survive comparison with thin deterministic policies and mature mechanisms.
Use current-observation selection/replanning as a bounded standing, not a universal law. Reopen a stronger strategic abstraction only when an independent authorized consumer produces one of CA7's exact failures—cross-mission obligation, team benefit, opponent-history gain, held-out coevolution transfer, or higher-fidelity failure that ordinary trajectory/current evidence cannot explain.
Mature range/simulation authority plus ordinary Host, Harness, Runtime, provider-native evidence, and thin current-observation decision logic express the same retained distinctions with fewer Security-specific contracts, or a future higher-order consumer forces a different residual than current conditional selection/replanning.
03 / Supporting publications
Complete arguments connected to this Question.
1 dated publication currently document this research line.
04 / Source discipline
The dossier is an index, not the evidence authority.
Owns the current judgment, next test, and deletion condition.
Own complete dated arguments, limitations, comparisons, and source links.
Own exact code, tests, releases, receipts, and machine evidence.