From Implicit Trust to Continuous Verification: A Position on the Authorization of AI Agents in Production Services

Resumo


Production services increasingly receive requests from AI agents that act under delegated authority, live for minutes, and cross trust boundaries that were never mapped. We argue that admitting such requests safely requires abandoning implicit trust, so that every request is verified, every time. We describe an architecture of three conceptual layers that follow the life cycle of an agent request: cryptographic pre-authorization at the edge, workload identity attested by the execution platform, and contextual decisions externalized to a decoupled policy engine. We conclude with the field’s main open problem: reconciling the delegation asserted by the organizational plane with the identity attested by the infrastructure.

Referências

Campbell, B., Bradley, J., Sakimura, N., and Lodderstedt, T. (2020). Oauth 2.0 mutual-tls client authentication and certificate-bound access tokens. In RFC 8705. IETF.

Fett, D., Campbell, B., Bradley, J., Lodderstedt, T., Jones, M., and Waite, D. (2023). Oauth 2.0 demonstrating proof of possession (dpop). In RFC 9449. IETF.

IETF WIMSE Working Group (2026). Workload identity in a multi system environment (wimse) architecture. In Internet-Draft draft-ietf-wimse-arch-08, Work in progress. IETF.

Jones, M., Nadalin, A., Campbell, B., Bradley, J., and Mortimore, C. (2020). Oauth 2.0 token exchange. In RFC 8693. IETF.

Lodderstedt, T., Richer, J., and Campbell, B. (2023). Oauth 2.0 rich authorization requests. In RFC 9396. IETF.

OpenID Foundation (2026). Authorization api 1.0 — final specification. In OpenID AuthZEN Working Group. OpenID Foundation. Available at: [link].

South, T., Marro, S., Hardjono, T., Mahari, R., Whitney, C. D., Greenwood, D., Chan, A., and Pentland, A. (2025a). Authenticated delegation and authorized ai agents. In Proceedings of the 42nd International Conference on Machine Learning (ICML 2025), Position Paper Track. arXiv:2501.09674.

South, T., Nagabhushanaradhya, S., Dissanayaka, A., Cecchetti, S., Fletcher, G., et al. (2025b). Identity management for agentic ai: The new frontier of authorization, authentication, and security for an ai agent world. In OpenID Foundation Whitepaper. arXiv:2510.25819.

SPIFFE Project (2025). The spiffe identity and verifiable identity document (spiffe-id). In Cloud Native Computing Foundation. Available at: [link].

Syros, G., Suri, A., Ginesin, J., Nita-Rotaru, C., and Oprea, A. (2026). Saga: A security architecture for governing ai agentic systems. In Network and Distributed System Security Symposium (NDSS 2026). The Internet Society.

Tallam, K. (2026). Authorization propagation in multi-agent ai systems: Identity governance as infrastructure. In arXiv preprint. arXiv:2605.05440.
Publicado
01/09/2026
ARAUJO, Diego S.; QUINCOZES, Silvio E.; MANSILHA, Rodrigo Brandão. From Implicit Trust to Continuous Verification: A Position on the Authorization of AI Agents in Production Services. In: WORKSHOP DE CIBERSEGURANÇA EM IA - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 1044-1047. DOI: https://doi.org/10.5753/sbseg_estendido.2026.33837.

Artigos mais lidos do(s) mesmo(s) autor(es)

<< < 1 2 3 4