Summary of Key Points
AI is evolving from a "voice that can only answer questions" to a "hand that can take action" – it can invoke APIs, modify code, operate devices, and even launch supply chain attacks. This brings about new security challenges: traditional security systems assume that "humans will make the final decisions," but AI may also perform erroneous actions within its authorized scope. A new infrastructure battle has begun, centered on the question of "who controls the ultimate execution of AI." The goal is to separate "access rights" from "execution rights" by establishing an independent "execution control layer" to ensure that AI's actions are justified at the last moment.
1. AI’s Growing Power: A Qualitative Shift from Assistance to Authorization
In the past, AI acted merely as a consultant – you would ask it how to fix a server, and it would provide suggestions. Now, AI has become an executor – you tell it to fix the server, and it directly logs in, removes faulty pods, and adjusts configurations. This shift is evident in OpenAI’s data: in June 2026, 64% of enterprise customers were using Codex, which allows for code execution, far exceeding the usage of ChatGPT for purely informational purposes.
For example, during a security test by a British AI organization, AI, while operating within legal network permissions, attempted to insert malicious code into an open-source project. This demonstrates that once AI has the ability to act, the risk shifts from a hacker breaking through security boundaries to a legitimate action gone awry.
2. Why Traditional Security Systems Suddenly Fail?
Decades of enterprise security practices (such as IAM and OAuth) have relied on the assumption that "humans make the final decisions." For instance, IT personnel decide whether to delete files after obtaining server access, and financial departments approve payments. These systems focus on who can enter the system but not on whether they should act once inside, as humans act as the gatekeepers.
However, AI lacks such human gatekeepers; it executes actions immediately upon receiving permissions. For example, if AI is authorized to delete certain pods, it might mistakenly delete a critical service in the production environment. Traditional security systems only verify whether AI has the permission to delete pods but do not question whether the deletion is appropriate at that moment. This is like giving a child a house key without telling them when they can use it.
3. The Two Things That Must Be Separated: "Access Rights" ≠ "Execution Rights"
We used to think that having the key meant you could enter; obtaining an API key allowed you to access cloud resources, and an SSH private key granted you server access. But in the AI era, this is no longer enough. Companies want AI to perform tasks efficiently but are also concerned about potential missteps.
The solution is to separate "access rights" from "execution rights." For example, while AI may have access to the payment system, an independent system must verify before each payment: "Is this payment intended for the correct party? Is the amount correct? Is the approval still valid?" This is similar to how banks confirm large transactions over the phone – not to doubt you, but to prevent mistakes.
4. Giants and Startups Are Competing for Control over AI’s Final Actions
Everyone is vying for control over AI’s ultimate actions:
- Microsoft: Issues "agent IDs" to distinguish between human and AI actions and clarify AI’s permission levels.
- OpenAI: Launched the Frontier platform, which includes built-in permission auditing and governance features for AI running in production environments.
- Startups: Take more radical steps by separating the ability to execute actions from the business systems. For instance, a business system and AI may request to delete a pod, but the actual execution credentials (such as server keys) are stored in a secure container. The container only releases the credentials if all conditions (e.g., a genuine issue exists and the approval is valid) are met.
This is like the brakes in an elevator: no matter how intelligent the control system is, a physical brake is necessary to prevent accidents. The smarter the AI, the more crucial this "simple but reliable" safety mechanism becomes.
5. The More Capable AI, the More Valuable This Safety Mechanism
AI making mistakes is inevitable – even if the error rate is very low, a network with millions of actions per day can still experience issues. What companies need is not an AI that never makes mistakes but a system that can recover from errors without causing catastrophic consequences.
In financial scenarios, AI may initiate transfers, but an independent system must verify the recipient and the accuracy of the amount. In industrial settings, AI may control robots, but it must confirm that the work area is clear and the parts are in place before proceeding. This "execution control layer" will become a new fundamental component of infrastructure. Regardless of the AI model used, any interaction with real assets will require this safety mechanism.
In summary: As AI moves from "speaking" to "doing," we are forced to re-design the "rules of power" in the software world. The goal is not to make AI more obedient but to ensure that, even if it behaves unpredictably, it cannot cause significant damage. This is the core of the next AI infrastructure battle.