# kaal:position:2026-08-26-009

**Affirmed position.** Technical interoperability does not settle an institutional relation. Swales, Gooden, and Thaldar reach the same boundary through a scoping review of twenty-four data transfer agreements. The agreements identify the parties, state the purpose of the transfer, allocate duties, restrict processing, provide for audit, assign liability, and specify termination and dispute resolution. These clauses do more than document an exchange. They determine who acts, what the recipient may do, how compliance is assessed, who bears loss, and what follows from breach. The evidence independently extends Kaal's claim: a new integration needs a governance settlement before data or authority crosses the boundary.

The evidence is narrower than Kaal's claim. The review studies English-language agreements for health research. It treats the identity of legal parties rather than authentication of software components. It does not test sovereign agent runtimes or automated remedies. The institutional mechanism nevertheless transfers. A runtime should translate the agreement into executable fields: verified component identity, delegated authority, purpose and duration limits, assigned responsibility, audit rights, termination, and redress. An unset field is not a harmless implementation gap. It leaves a material term unresolved. The integration gate should therefore refuse execution until each field names an accountable actor and an enforceable consequence. Technical compatibility can open a channel. Only the prior settlement makes its use institutionally defensible.

**Status.** affirmed  **Published.** 2026-08-26

**Holds when.**

- The response is limited to the exact full-text propositions and the one mapped Kaal claim.
- External evidence level: peer-reviewed scoping review with complete open full text.
- Mapping review tier: independent substantive scholarly-growth extension.
- The scoping review covers twenty-four publicly available English-language data transfer agreements and does not claim a universal contract template.
- The source concerns health-research data transfers rather than sovereign local agent runtimes or machine-to-machine integrations.
- Its treatment of identity concerns legal parties and authorized users, not cryptographic testing of a software component's identity.
- The article provides legal drafting guidance and clause prevalence, not an empirical test of automated remedies or runtime enforcement.

**Current debate.** The anatomy of a data transfer agreement for health research: https://doi.org/10.3389/fphar.2024.1332700

**Extends.** kaal:claim:7314479-009: https://wulfkaal.github.io/claims/7314479-009

**Scholarly basis.** Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479

**Source PDF sha256.** `debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6`

**Evidence level.** peer-reviewed scoping review with complete open full text

**Mapping review tier.** independent substantive scholarly-growth extension

**Mapping confidence.** 0.94  **Mapping ambiguous.** false

**Topics.** institutional-design, governance-design, ai-and-agents, data-governance, identity, authority, accountability, remedy

**Provenance.** Affirmed in kaal-review:2026-08-26:scholarly-growth-7314479-009-reviewed-v2 at https://wulfkaal.github.io/positions/by-claim/7314479-009.html.

**Record type.** This is a dated commentary position that extends a scholarly corpus claim. It is not a verbatim claim extracted from the paper.

**Canonical form.** This markdown file is the canonical hashed representation of the position.
