Framework · Defense
Recursive Cyber Defense Framework
Defense fast enough to act below the human-latency wall — that never escapes human authority.
The Recursive Cyber Defense Framework (RCDF) is a framework for defending systems — and, increasingly, autonomous AI systems — against adversaries that operate faster than human reaction time, while keeping that defense under continuous human governance. It organises defense into five recursive functions and defines a maturity model along which an organisation progresses from reactive, human-paced response toward governed, predictive, machine-speed interdiction.
Its central tension, and the problem it is built to resolve: defense must become fast enough to act below the threshold at which a human can intervene — without removing human authority over what it does.
The human-latency wall
RCDF names the boundary at the heart of the problem the human-latency wall: the point — on the order of a few hundred milliseconds — beyond which only an automated responder can interdict in time. The framework's purpose is to let defense operate at and below that wall responsibly — under explicit policy, with human oversight retained, and with every autonomous action contained and accountable.
The five recursive functions
RCDF expresses defense as five functions arranged in a continuous, recursive loop. They are not phases performed once but capacities maintained always; the output of each cycle refines the next.
Maturity model and graduated autonomy
RCDF defines levels of maturity describing how far, and how safely, an organisation has progressed toward governed machine-speed defense. Maturity is not merely about speed; it is about earning the right to act faster by first demonstrating reliability and control. Autonomy is granted only as reliability is proven — moving through shadow mode, to approval, to supervised autonomous operation.
The framework distinguishes human-in-the-loop (a human approves each action) from human-on-the-loop (a human supervises an autonomous process and can intervene or halt it at any time). Below the human-latency wall, in-the-loop approval is impossible by definition; RCDF's answer is on-the-loop governance — autonomy that remains continuously supervised and instantly revocable.
Governance overlay and containment
Around the defensive loop, RCDF places a governance overlay: policy-as-code, validation gates, human-on-the-loop oversight, and a tamper-evident audit record — all within strict containment, so that any autonomous capability's only egress is a secure, accountable gateway.
Relationship to the AI Control Architecture
In the AI context, RCDF is the enforcement counterpart to the AI Control Architecture (ACA), which establishes which controls an AI requires. The two compose:
| AI Control Architecture | RCDF |
|---|---|
| Classification — See / Decide / Do | Observe — watches that surface behaviourally at runtime |
| Action controls (Pillars 4–6) | Disrupt — enforces those constraints in the path of the action |
| Risk tiers | Maturity & graduated modes — autonomy earned as reliability is proven |
| Human accountability (Pillar 7) | Govern — accountability as enforceable policy, human-on-the-loop |
| Assurance & monitoring (Pillars 8–9) | Adapt — evidence and results fed back to improve posture |
The architecture proves the control; the framework learns from how it performs. Together they make governed, machine-speed defense possible.
See it on the Neo platform Read the AI Control Architecture →