arXiv AI

A Theory of Least Autonomy in AI

arXiv:2607. 09744v1 Announce Type: new Abstract: Least privilege, the principle that an identity should hold only the permissions strictly required for its task, has been a foundational primitive of access control for decades.

arXiv AI
Sep 15

Empirical Evaluation of Task-Based Permission Scoping Architecture for AI Agents

The paper evaluates a task-based permission scoping architecture for AI agents, comparing a fine‑tuned RoBERTa‑large encoder to few‑shot Claude Haiku 4.5 on a 600‑prompt dataset. It shows the new system achieves comparable macro‑F1 (0.881 vs. 0.886) and higher precision (0.897 vs. 0.842), while reducing severity‑weighted residual risk from 1.12 to 0.63. The study also introduces an attack‑surface elimination metric, demonstrating that task‑granular control can close 84.4% of the severity‑weighted surface, far surpassing role‑based ceilings alone.

By Halil Burak Noyan
arXiv AI
Jul 28

Intent-Governed Tool Authorization for AI Agents

arXiv:2606. 22916v2 Announce Type: replace Abstract: AI agents increasingly act through external tools: they read private data, construct structured payloads, submit write requests, export records, and coordinate workflows across application boundaries.

By Genliang Zhu, Chu Wang
Hugging Face Trending Papers
Jun 22

Intent-Governed Tool Authorization for AI Agents

AI agents increasingly act through external tools: they read private data, construct structured payloads, submit write requests, export records, and coordinate workflows across application boundaries. Existing authorization mechanisms usually ask whether an integration credential, app, or token can call a tool.