虎嗅

New term emerging in the context of AI agent security: “Authority”

原文:AI Agent 安全正在出现一个新的词:Authority

Summary of Key Points

This article focuses on the security challenges posed by AI Agents, which are capable of executing tasks autonomously. Traditional methods of authentication (verifying “who you are”) and permission management (verifying “what you can do”) are no longer sufficient to address scenarios where AI Agents directly interact with operating systems to perform actions such as making payments, modifying data, or controlling servers. Even if the user’s identity and permissions are legitimate, a single action by an AI Agent may deviate from the user’s intended purpose. As a result, the industry is beginning to emphasize a new concept in security called “Authority,” which complements existing systems by focusing on whether a particular action is allowed to occur. This concept is crucial for ensuring that AI Agents transition from being auxiliary tools to being used in production-level applications.

1. The Blind Spots in Traditional Security Models: Only Recognizing “Qualifications,” Not the “Correctness of Actions”

Traditional security systems are like company-issued access cards: they confirm that someone is an employee and grant them access to specific areas, regardless of the purpose of their visit (whether for work or other reasons). With the emergence of AI Agents, this flaw is amplified. For example, an AI Agent with payment permissions might, due to a programming error, mistakenly transfer 30,000 units to the wrong supplier instead of the intended one. Although the user’s identity and permissions are valid, the action is incorrect, and traditional security systems would not detect this error.

2. Authorization vs Authority: The Difference Between “What You Can Do” and “Whether You Are Allowed to Do It”

Many people confuse these two terms, but they have distinct meanings:

  • Authorization: This refers to the list of tasks or actions that a user is allowed to perform (e.g., a finance department has permission to use the payment interface, or an engineer has permission to operate servers).
  • Authority: This refers to the specific permission for a particular action at a given time (e.g., a finance AI Agent can only make a payment if the user explicitly instructs it to do so; otherwise, the attempt will be denied).

In simple terms, authorization is like a “certificate of eligibility,” while authority is like a “pass for a single action.”

3. Why AI Agents Exacerbate Security Issues?

AI Agents eliminate the “human buffer” that used to exist between permissions and actual execution. For instance, before the advent of AI, financial staff would verify invoices, amounts, and recipients before making a payment. This human step prevented many errors. However, AI Agents automate this process, eliminating that buffer, which means that errors (such as incorrect transfers or service interruptions) can occur directly.

4. The Essence of Authority: Shifting from “Trusting People” to “Trusting System Rules”

In the past, decisions about whether an action was allowed were based on human judgment and common sense. Now that humans are no longer directly involved in the execution process, these decisions must be encoded into rules that the system can understand:

  • Task Binding: AI Agents can only perform tasks explicitly authorized by the user (e.g., processing invoices for a specific supplier).
  • Real-time Context Checks: During payments, the system verifies that the recipient is the intended one, the amount matches the invoice, and there are no expiration issues.
  • Reversibility: Users can terminate an AI Agent’s actions at any time if they discover an error.

This shift means that security measures rely on system rules rather than on the assumption that individuals will not misbehave.

5. Authority as a Critical Barrier for AI Agents Entering Production Environments

Many AI Agents are still in an auxiliary role (e.g., generating reports or checking data), and errors can be easily corrected. However, when they are used for production-level tasks (e.g., automatic payments, managing cloud servers, or controlling physical devices), the consequences of errors can be severe (e.g., transferring a large amount of money incorrectly or shutting down an entire system). In such cases, the presence of a robust Authority mechanism is essential. Companies must ensure that every action by an AI Agent is scrutinized to ensure it is appropriate before granting them operational control. Authority thus marks the threshold for AI Agents to move from a laboratory setting to a production environment.

Conclusion

Although the term “Authority” may not become the industry standard, the concept it represents is crucial. The ultimate goal of security is not to determine what permissions a system has but to ensure that specific actions are allowed to occur. The widespread adoption of AI Agents is forcing us to shift our focus from identifying qualified users to verifying the rationality of their actions. This represents one of the core directions for future AI security strategies.