Skip to content
InfoResearchPreprintLLM-specific

NOMOS: Compiling Written Policies into Statically Verified Tool-Call Gates for LLM Agents

Published
Record updated
View JSON

Summary

NOMOS is a four-pass compiler that turns a natural-language policy into a deterministic tool-call gate for LLM agents. Static verification using only tool-schema checks repairs or rejects 37% of candidates on airline and 13% on retail, and the gate cuts violations of reference-encoded clauses on state-changing calls from 66.3% to 2.6% (airline) and 30.8% to 6.9% (retail). On AgentDojo's banking suite it reaches a zero attack success rate, and on the other three suites its ASR is at most 3.6%.