Framework · Defense

Recursive Cyber Defense Framework

Defense fast enough to act below the human-latency wall — that never escapes human authority.

The Recursive Cyber Defense Framework (RCDF) is a framework for defending systems — and, increasingly, autonomous AI systems — against adversaries that operate faster than human reaction time, while keeping that defense under continuous human governance. It organises defense into five recursive functions and defines a maturity model along which an organisation progresses from reactive, human-paced response toward governed, predictive, machine-speed interdiction.

Its central tension, and the problem it is built to resolve: defense must become fast enough to act below the threshold at which a human can intervene — without removing human authority over what it does.

The human-latency wall

RCDF names the boundary at the heart of the problem the human-latency wall: the point — on the order of a few hundred milliseconds — beyond which only an automated responder can interdict in time. The framework's purpose is to let defense operate at and below that wall responsibly — under explicit policy, with human oversight retained, and with every autonomous action contained and accountable.

The five recursive functions

RCDF expresses defense as five functions arranged in a continuous, recursive loop. They are not phases performed once but capacities maintained always; the output of each cycle refines the next.

Govern — authority over the whole loop
Expresses accountability as enforceable policy and human-on-the-loop oversight. Every other function operates under Govern; every cycle returns to it so that improvement never escapes oversight.
Observe — continuous behavioural awareness
Maintains real-time awareness of what is happening, by which actors, in what sequence. RCDF reasons about what an action does, not merely whether it matches a known signature — so it remains effective against techniques never seen before.
Anticipate — predict the next move
Projects likely adversary behaviour ahead of it occurring, so defense can prepare and, where warranted, act before harm lands rather than after.
Disrupt — graduated interdiction
Intervenes in the path of an action to stop or contain it, at machine speed where necessary, with the degree of intervention graduated to the authority the capability has earned.
Adapt — the recursion
Closes the loop: learns from what was observed, anticipated and disrupted, and how well, and feeds that back into every function. Adaptation is what makes the framework recursive — the defense continually re-derives and improves its own posture.
Govern → Observe → Anticipate → Disrupt → Adapt → (Govern)

Maturity model and graduated autonomy

RCDF defines levels of maturity describing how far, and how safely, an organisation has progressed toward governed machine-speed defense. Maturity is not merely about speed; it is about earning the right to act faster by first demonstrating reliability and control. Autonomy is granted only as reliability is proven — moving through shadow mode, to approval, to supervised autonomous operation.

The framework distinguishes human-in-the-loop (a human approves each action) from human-on-the-loop (a human supervises an autonomous process and can intervene or halt it at any time). Below the human-latency wall, in-the-loop approval is impossible by definition; RCDF's answer is on-the-loop governance — autonomy that remains continuously supervised and instantly revocable.

Governance overlay and containment

Around the defensive loop, RCDF places a governance overlay: policy-as-code, validation gates, human-on-the-loop oversight, and a tamper-evident audit record — all within strict containment, so that any autonomous capability's only egress is a secure, accountable gateway.

Scope note. RCDF is a defense framework. Where it refers to an adaptive learning engine that may realise the Anticipate and Disrupt functions, that engine's internal mechanism is the subject of a separate, independently filed patent and is intentionally not described here. RCDF is the framework within which such an engine is governed, contained and held accountable; it stands independently of any particular engine and could govern more than one.

Relationship to the AI Control Architecture

In the AI context, RCDF is the enforcement counterpart to the AI Control Architecture (ACA), which establishes which controls an AI requires. The two compose:

AI Control ArchitectureRCDF
Classification — See / Decide / DoObserve — watches that surface behaviourally at runtime
Action controls (Pillars 4–6)Disrupt — enforces those constraints in the path of the action
Risk tiersMaturity & graduated modes — autonomy earned as reliability is proven
Human accountability (Pillar 7)Govern — accountability as enforceable policy, human-on-the-loop
Assurance & monitoring (Pillars 8–9)Adapt — evidence and results fed back to improve posture

The architecture proves the control; the framework learns from how it performs. Together they make governed, machine-speed defense possible.


See it on the Neo platform Read the AI Control Architecture →

The Recursive Cyber Defense Framework is an original work by Ankush Chowdhary, registered as a literary work; the registration protects this expression, not the underlying ideas or methods. Published by Neo (Neo Control Private Limited). · neocontrol.ai