Large language model triggered ephemeral directive
View Patent ↗A computer-implemented method is disclosed for dynamically controlling operations of computing resources in an environment using artificial intelligence. A large language model (LLM) analyzes data associated with the computing resources, each governed by a default directive controlling their functional behavior. The LLM identifies suspicious usage patterns within the analyzed data. In response to such detection, the system generates an ephemeral machine-executable directive tailored to address the specific suspicious activity. This ephemeral directive temporarily supersedes the default directive and is enforced to gate or modify the resource's function, thereby mitigating potentially harmful or unauthorized operations. The approach enables responsive, automated, and context-aware modification of system behavior, leveraging AI-based detection and just-in-time directive generation to enhance operational security and adaptability.
1 . A computer-implemented method, comprising:
employing a large language model (LLM) to scan data associated with one or more computing resources of an environment, the one or more computing resources being associated with a default directive that controls a function of the one or more computing resources;
receiving, from the LLM, a detection of suspicious usage within the data;
responsive to the detection of the suspicious usage, dynamically generating an ephemeral machine-executable directive based on the suspicious usage, wherein the ephemeral machine-executable directive is generated in response to an event trigger corresponding to the suspicious usage and is configured to temporarily supersede the default directive during persistence of the event trigger;
assigning, to the ephemeral machine-executable directive, a priority tag having a higher enforcement priority than the default directive; and
enforcing the ephemeral machine-executable directive in a runtime request flow to gate the function of the one or more computing resources by temporarily superseding the default directive with the ephemeral machine-executable directive based on the priority tag, and reverting to the default directive when the event trigger no longer persists.
2 . The method of claim 1 , wherein the environment comprises: an operating system, an operating system application, an endpoint computing device, a network appliance, a cloud service, a software as a service platform, or an AI or an AI agent service.
3 . The method of claim 1 , wherein the data comprises Internet of Things (IoT) device logs.
4 . The method of claim 1 , wherein the data comprises operating system or endpoint telemetry data, and the telemetry data comprises process, file access, network, or API call events.
5 . The method of claim 1 , wherein gating the function comprises denying access to the one or more computing resources or denying a data streaming service associated with the one or more computing resources.
6 . The method of claim 5 , wherein the data streaming is denied based on a determination that a user identity attribute does not satisfy a verified owner criterion for accessing the one or more computing resources.
7 . The method of claim 1 , wherein enforcing the ephemeral machine-executable directive comprises runtime hooking or policy injection that intercepts user actions or resource creation calls without system downtime or redeployment.
8 . The method of claim 1 , wherein enforcing the ephemeral machine-executable directive comprises:
persisting the ephemeral machine-executable directive during partial or full offline states of the one or more computing resources by:
locally merging ephemeral machine-executable directive and the default directive; and
synchronizing updates upon reconnection.
9 . The method of claim 1 , wherein generating the ephemeral machine-executable directive is triggered by at least one of: time of day, device posture, a SIEM alert, or external threat intelligence.
10 . The method of claim 1 , further comprising:
assigning a priority to the ephemeral machine-executable directive; and
overriding the default directive with the ephemeral machine-executable directive during a triggering condition.
11 . The method of claim 1 , wherein the ephemeral machine-executable directive is removed, expires, or is downgraded responsive to a resolution of the suspicious usage.
12 . The method of claim 1 , further comprising:
automatically applying the ephemeral machine-executable directive to newly detected computing resources within the environment.
13 . The method of claim 1 , wherein dynamically generating the ephemeral machine-executable directive comprises:
retrieving a source directive; and
translating the source directive to the ephemeral machine-executable directive using a platform capability database to generate a platform specific enforcement rule for the environment.
14 . The method of claim 13 , wherein translating the source directive to the ephemeral machine-executable directive comprises retaining compliance attributes including regulatory tags preserved in a common intermediate representation (CIR).
15 . The method of claim 1 , further comprising:
presenting the ephemeral machine-executable directive for a human-in-the-loop review prior to enforcement.
16 . The method of claim 1 , wherein gating the function of the one or more computing resources comprises denying resource creation or modification operations including at least one of: container creation, virtual machine instantiation, firewall rule changes, or file write operations.
17 . The method of claim 1 , wherein the detection of the suspicious usage within the data comprises:
evaluating whether the data meets a predefined pattern that describes the suspicious usage.
18 . The method of claim 1 , wherein the detection of the suspicious usage within the data comprises:
evaluating whether the data meets an anomalous usage pattern that defines the suspicious usage.
19 . The method of claim 1 , further comprising cryptographically logging enforcement outcomes to a tamper evident ledger.
20 . A directive-management system, comprising:
one or more processors; and
memory configured to store code comprising instructions, wherein the instructions, when executed by the one or more processors, cause the one or more processors to:
employ a large language model (LLM) to scan data associated with one or more computing resources of an environment, the one or more computing resources being associated with a default directive that controls a function of the one or more computing resources;
receive, from the LLM, a detection of suspicious usage within the data;
responsive to the detection of the suspicious usage, dynamically generate an ephemeral machine-executable directive based on the suspicious usage, wherein the ephemeral machine-executable directive is generated in response to an event trigger corresponding to the suspicious usage and is configured to temporarily supersede the default directive during persistence of the event trigger;
assign, to the ephemeral machine-executable directive, a priority tag having a higher enforcement priority than the default directive; and
enforce the ephemeral machine-executable directive in a runtime request flow to gate the function of the one or more computing resources by temporarily superseding the default directive with the ephemeral machine-executable directive based on the priority tag, and reverting to the default directive when the event trigger no longer persists.
21 . A non-transitory computer-readable medium configured to store code comprising instructions, wherein the instructions, when executed by one or more processors, cause the one or more processors to:
employ a large language model (LLM) to scan data associated with one or more computing resources of an environment, the one or more computing resources being associated with a default directive that controls a function of the one or more computing resources;
receive, from the LLM, a detection of suspicious usage within the data;
responsive to the detection of the suspicious usage, dynamically generate an ephemeral machine-executable directive based on the suspicious usage, wherein the ephemeral machine-executable directive is generated in response to an event trigger corresponding to the suspicious usage and is configured to temporarily supersede the default directive during persistence of the event trigger; assign, to the ephemeral machine-executable directive, a priority tag having a higher enforcement priority than the default directive; and
enforce the ephemeral machine-executable directive in a runtime request flow to gate the function of the one or more computing resources by temporarily superseding the default directive with the ephemeral machine-executable directive based on the priority tag, and reverting to the default directive when the event trigger no longer persists.