Preprint · 2026-10-03
VAPF: A Vendor-Neutral Specification for Real-Time Conversational Agent Pipelines
A contract-based specification unifying transport, speech, tool calling, memory and adaptive safety behind versioned interfaces.
- 28
- sections, contracts and conformance
- 26
- works cited
- 0
- implementations, stated plainly
Voice agent pipelines are built the same way repeatedly and described differently every time. Each implementation names its own shapes for the same ideas, so a component cannot be swapped and a safety claim cannot be compared.
VAPF specifies the contracts instead of the implementation. Transport over WebRTC or WebSocket, speech processing, tool calling, tiered memory and guardrails all sit behind versioned interfaces, with RFC 2119 conformance language so a requirement is a requirement rather than an emphasis.
The architectural contribution is the part that is not a survey. An adaptive guardrail escalation ladder, a cross-vendor self-reporting contract grounded in the autonomic computing MAPE-K loop, a law-based kill switch aligned to EU AI Act Article 14 human-oversight requirements, and an independent-review layer that forbids a component reviewing its own output.
Crisis and emergency assistance is the running use case, chosen because it stresses every control the framework defines: response accuracy is safety-critical, and the published clinical evaluations show general-purpose models are not yet reliably safe there.
It is a design specification and says so. No reference implementation has been built or tested, and the final section enumerates the implementation, adversarial testing and clinical validation that would be required before any conformance or safety claim could be substantiated. It is published at this stage because that is when implementation feedback is worth having.
Open questions
What it did not settle.
Each of these is a limitation the paper states plainly. They are here because they are what the next piece of work is about, and because a method that only ever works is a method nobody has tested.
Does the framework survive its first implementation?
Every contract here is argued rather than exercised. A specification with no implementation has not met the cases that force the awkward decisions, and the versioning section reserves explicit slots for benchmark data and conformance results precisely because none exist yet.
Is the self-reporting schema one a second vendor would adopt?
The self-healing work it builds on validates the monitor and plan loop, but neither proposes a cross-vendor reporting schema. A standard that only its author implements is a document, not a standard, and nothing here tests whether the shape is acceptable to somebody who did not write it.
Can a kill switch be specified without the law moving under it?
The control is aligned to a current reading of EU AI Act Article 14. That reading will change, and a specification that bakes in one interpretation inherits every revision of it.
The source
Read it, or run it.
Open for comment. No DOI yet, so it cannot be cited.