e007
OpenID Foundation advances authorization for the agent era with new AuthZEN Working Group Drafts
Permalink- Source
- OpenID Foundation
- Source type
- standard
- Primary or secondary status
- Primary
- Domain
- Identity
- Published
- 2026
- Claims
- AC, EL
- Conditions
- 3.2, 3.4
- Stance
- supports
- Relation
- complements
- Strength
- supporting
- Overlap flag
- absorption
AuthZEN Final in January 2026. New AARP draft addresses what happens when policy cannot authorize yet because a prerequisite — approval, consent, delegated authority, attestation, risk assessment, or justification — must first be satisfied. Supports the claim that the gap is upstream of the decision point; also shows the gap being actively closed.
Original linke008
Prompt injection still drives most agentic AI security failures in production
Permalink- Source
- Help Net Security / OWASP
- Source type
- press
- Primary or secondary status
- Secondary
- Domain
- Runtime
- Published
- 2026-06-11
- Claims
- EL
- Conditions
- 3.5
- Stance
- supports
- Relation
- supports
- Strength
- supporting
- Overlap flag
- none
OWASP-sourced. Prompt injection lands on roughly one in three deployed agents; 88 percent of enterprises deploying agents reported at least one agent-linked security incident. Direct empirical support for Causal Integrity as a live failure mode rather than a hypothetical.
Original linke009
awesome-ai-agent-attacks — sourced timeline of real AI agent security incidents 2024-2026
Permalink- Source
- Community timeline
- Source type
- incident
- Primary or secondary status
- Primary
- Domain
- Runtime
- Published
- 2026
- Claims
- EL, AC
- Conditions
- 3.5, 3.2
- Stance
- supports
- Relation
- supports
- Strength
- supporting
- Overlap flag
- none
Dated and sourced incident corpus. Includes the Copilot email-summarization case (hidden instructions ingested during summarization, exfiltration from OneDrive/SharePoint/Teams via a trusted Microsoft domain), CVE-2025-6514 MCP RCE, CVE-2025-59536 hooks injection, postmark-mcp supply chain, and GTG-1002. The Copilot case is a close real-world analogue of Appendix C.1.
Original linke010
Authorization Propagation in Multi-Agent AI Systems: Identity Governance as Infrastructure
Permalink- Source
- arXiv 2605.05440 (Tallam)
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Identity
- Published
- 2026-05
- Claims
- AC
- Conditions
- 3.2
- Stance
- supports
- Relation
- supports
- Strength
- supporting
- Overlap flag
- none
Examines how authorization propagates across multi-agent systems and frames identity governance as infrastructure rather than policy. Consistent with the delegation-propagation reading in Appendix A. Cited in the thesis reference list. Bears on AC and condition 3.2.
Original linke011
AI Identity: Standards, Gaps, and Directions
Permalink- Source
- arXiv 2604.23280
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Identity
- Published
- 2026-04-28
- Claims
- AC
- Conditions
- 3.2
- Stance
- supports
- Relation
- supports
- Strength
- supporting
- Overlap flag
- none
Finds OAuth 2.0 handles one-hop delegation well but lacks multi-hop chaining, cross-domain asynchronous flows, and any mapping between OAuth scopes and agent capabilities; cross-organizational log correlation unsolved. Independent corroboration of the Appendix A reading of RFC 8693 and RFC 9396.
Original linke013
EU AI Act Article 12 logging obligations reach full enforcement August 2, 2026
Permalink- Source
- Salt Security / EU AI Act
- Source type
- regulatory
- Primary or secondary status
- Secondary
- Domain
- Regulatory
- Published
- 2026
- Claims
- GE, MKT
- Conditions
- EV, MKT
- Stance
- supports
- Relation
- supports
- Strength
- supporting
- Overlap flag
- none
Article 12 mandates automatic logging of events relevant to traceability; logs must be tamper-evident, retained six months minimum. No finalized technical standard yet — prEN 18229-1 and ISO/IEC DIS 24970 still in draft. Demand-side support for the decision receipt and for stating an assurance level explicitly.
Original linke014
Okta transmits only two outbound CAEP event types as of early 2026
Permalink- Source
- Andrew Doering
- Source type
- practitioner
- Primary or secondary status
- Secondary
- Domain
- Identity
- Published
- 2026
- Claims
- AD
- Conditions
- 3.3
- Stance
- supports
- Relation
- supports
- Strength
- emerging
- Overlap flag
- none
Okta does not emit risk-level-change, device-compliance-change, or assurance-level-change outbound. Sharpens the Appendix A argument that expressibility is not standardization — the deployed vocabulary is narrower than the specified one, well before reaching matter closure or contract expiry.
Original linke015
Compositional agent harm — individually authorized sub-actions yielding harmful sequences
Permalink- Source
- arXiv 2604.23338
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Runtime
- Published
- 2026-04
- Claims
- EL, AC
- Conditions
- 3.4, 3.2
- Stance
- supports
- Relation
- supports
- Strength
- supporting
- Overlap flag
- none
Systematic survey establishing that multi-step chains compose individually benign invocations into harmful sequences, and that the security property of a composition cannot be derived from its steps. Stateless per-request engines cannot enforce properties depending on execution history. Direct support for Appendix C.4.
Original linke016
GitGuardian / Veza — non-human identity sprawl and over-permissioning at scale
Permalink- Source
- Security Boulevard / GitGuardian / Veza
- Source type
- analyst
- Primary or secondary status
- Secondary
- Domain
- Market
- Published
- 2026-07
- Claims
- MKT, AC
- Conditions
- MKT, 3.1
- Stance
- supports
- Relation
- supports
- Strength
- emerging
- Overlap flag
- none
Reports non-human identity to human ratios between 45:1 and 144:1 depending on environment, 73 percent of NHI-held secrets carrying excessive permissions, over 5.5 percent of AWS machine identities holding full administrative privilege, and 92 percent of organizations stating current IAM tooling cannot manage AI agent identities. Aggregated vendor and analyst reporting rather than peer-reviewed measurement. Bears on MKT and, indirectly, condition 3.1.
Original linke017
The Non-Human Identity Governance Vacuum
Permalink- Source
- Cloud Security Alliance
- Source type
- industry_standard
- Primary or secondary status
- Primary
- Domain
- Identity
- Published
- 2026
- Claims
- MKT, AC
- Conditions
- MKT, 3.1
- Stance
- supports
- Relation
- supports
- Strength
- supporting
- Overlap flag
- none
CSA whitepaper framing NHI and agentic AI governance as a vacuum. Institutional corroboration that the gap is recognized, from a body that predates the thesis.
Original linke021
Described vs. Established Governance in Agentic AI: Closing the Gap Between Policy and Enforcement
Permalink- Source
- SSRN (Cavallo)
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Policy
- Published
- 2026
- Claims
- PE, GE
- Conditions
- EV
- Stance
- supports
- Relation
- supports
- Strength
- supporting
- Overlap flag
- none
Frames the gap between governance as described in policy and governance as operationally established in the execution path. Bears on Section 3.8's distinction between security correctness and governance legitimacy, and on the Section 4.4 observation that controls are often described as audited at assurance levels they do not meet.
Original linke022
State-Aware Runtime for Long-Horizon LLM Agents: A Conceptual Framework and Research Agenda
Permalink- Source
- Cambridge Open Engage
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Memory/State
- Published
- 2026
- Claims
- AD, CD, RA
- Conditions
- 3.3
- Stance
- supports
- Relation
- complements
- Strength
- emerging
- Overlap flag
- none
Conceptual framework and research agenda for state-aware runtime across long-horizon agent operation. Bears on AD and on the Section 6.1 assumption that business systems can be consulted at execution latency. CD tag is provisional: the source addresses state persistence, and qualifies for CD only where it substantively treats capability evolution.
Original linke023
Agency doctrine: actual authority, apparent authority, and ratification
Permalink- Source
- Oxford Business Law Blog
- Source type
- legal_doctrine
- Primary or secondary status
- Primary
- Domain
- Legal
- Published
- 2025-04
- Claims
- EL, AC
- Conditions
- 3.2, 3.4
- Stance
- supports
- Relation
- complements
- Strength
- foundational
- Overlap flag
- none
Governance analogue and legal foundation rather than a doctrinal conclusion about software agents. Actual authority, apparent authority, and ratification establish that possession of apparent permission does not prove actual authority; that third parties may act on authority that is operationally credible but institutionally defective; and that later acceptance of an act differs from prior legitimacy. Apparent authority resembles the structure of Appendix C.1, though prompt injection and delegated software action are not doctrinally identical to it absent jurisdiction-specific authority. Ratification is the closest legal analogue to Section 5.2 post-hoc attestation, including its all-or-nothing character.
Original linke024
Mission command doctrine: commander's intent and disciplined initiative
Permalink- Source
- US Air Force AFDP 1-1
- Source type
- doctrine
- Primary or secondary status
- Primary
- Domain
- Ops Doctrine
- Published
- 2023-08-14
- Claims
- EL, AC
- Conditions
- 3.4
- Stance
- supports
- Relation
- supports
- Strength
- foundational
- Overlap flag
- none
Mission command combines centralized intent with decentralized execution. Commander's intent is doctrinally defined as a concise expression of purpose, method, and end state, including constraints, limitations, assumptions and resources, and is stated as a necessary condition without which mission command cannot be exercised. Subordinates exercise disciplined initiative within it. Establishes an institutional precedent for delegated autonomy bounded by represented intent; does not address machine-readable intent binding. Bears on condition 3.4 and Section 6.2.
Original linke025
Runtime verification and monitorability of safety properties
Permalink- Source
- Springer / RV literature
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Verification
- Published
- 2023
- Claims
- RA, GE
- Conditions
- EV, OBJ
- Stance
- supports
- Relation
- supports
- Strength
- foundational
- Overlap flag
- none
Monitorability is defined as the ability to return a positive or negative verdict after a finite execution prefix, with the field concentrating on safety properties because violations are always detectable in finite time. This supplies formal grounding for Section 2.2's claim that the evaluable tuple is only complete at execution, and a rigorous way to state which legitimacy conditions are monitorable at all. Also gives Section 4.3's determinism requirement an existing literature to stand on.
Original linke026
Verified runtime validation for partially observable hybrid systems
Permalink- Source
- arXiv 1811.06502
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Verification
- Published
- 2018
- Claims
- RA, AD
- Conditions
- 3.3, EV
- Stance
- supports
- Relation
- supports
- Strength
- foundational
- Overlap flag
- none
Synthesizes runtime monitors from provably safe hybrid system models, robust to partial observability arising from sensor uncertainty and partial controllability arising from actuator disturbance. Establishes what guarantee survives when a monitor cannot observe full system state. The partial-observability treatment corresponds to the Section 6.1 assumption that contextual validity may proceed on cached state, and to the signal-freshness requirement in Section 4.2.
Original linke027
Saga pattern, compensating transactions, and durable execution
Permalink- Source
- Azure Architecture Center / long-running transaction literature
- Source type
- architecture
- Primary or secondary status
- Primary
- Domain
- Distributed Systems
- Published
- ongoing
- Claims
- RA, PE, OBJ
- Conditions
- OBJ
- Stance
- supports
- Relation
- adjacent
- Strength
- foundational
- Overlap flag
- none
Long-running transactions abandon locks on non-local resources and use compensating transactions that semantically undo rather than restore prior state, typically coordinated by a durable state machine. Establishes an existing engineering distinction between operations that can be compensated and those that cannot. Bears on the reversibility-based allocation in Section 5.3.
Original linke029
Authenticated Delegation and Authorized AI Agents
Permalink- Source
- arXiv 2501.09674
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Identity
- Published
- 2025-01
- Claims
- AC
- Conditions
- 3.2
- Stance
- supports
- Relation
- complements
- Strength
- supporting
- Overlap flag
- none
Earlier work connecting agency-law delegation concepts to authenticated agent authorization. Useful bridge between the Legal domain entries and the identity standards track, and evidence that the legal framing is already being imported by researchers.
Original linke037
From Audit to Admissibility: Why AI Governance Must Move Into The Execution Boundary
Permalink- Source
- Medium
- Source type
- practitioner
- Primary or secondary status
- Secondary
- Domain
- Runtime
- Published
- 2026
- Claims
- RA, OBJ, PE
- Conditions
- OBJ, EV
- Stance
- supports
- Relation
- supports
- Strength
- emerging
- Overlap flag
- naming_collision
Practitioner argument that model outputs are not admissible actions but proposals, and that if a proposal can directly mutate system state without boundary evaluation, the model becomes a source of authority. Uses admissibility and execution boundary framing. Bears on OBJ, RA, and PE.
Original linke043
Responsibility for operational control and dispatch release: joint authority, continuous re-release, and non-delegable dispatch
Permalink- Source
- eCFR - 14 CFR 121.533, with 121.663 (US Federal Aviation Administration)
- Source type
- regulatory
- Primary or secondary status
- Primary
- Domain
- Aviation
- Published
- 1964-12-31, as amended 1996-01-26
- Claims
- EL, AC, GE
- Conditions
- 3.1, 3.3
- Stance
- supports
- Relation
- supports
- Strength
- foundational
- Overlap flag
- none
Governance analogue from aviation regulation, not a doctrinal claim about software agents. The certificate holder is responsible for operational control; the pilot in command and the aircraft dispatcher are jointly responsible for preflight planning, delay, and dispatch release, and under 121.663 both must sign the release and may do so only if both believe the flight can be made with safety. Authority is not settled at release: the dispatcher must monitor the progress of each flight, issue information necessary for its safety, and cancel or redispatch if either the dispatcher or the pilot in command judges that the flight cannot continue to operate safely as planned or released. 121.663 further provides that a dispatcher may delegate authority to sign a release for a particular flight but may not delegate the authority to dispatch. Establishes a long-standing regulatory precedent separating conferred authority, delegable and non-delegable components, evaluation against current conditions, continuing responsibility after release, and a signed record of the determination. Bears on EL, AC, and the grant-to-effect interval; the signed release is an evidence artifact bearing on GE.
Original linke044
Principles for financial market infrastructures - Principle 8: Settlement finality
Permalink- Source
- CPSS-IOSCO / CPMI-IOSCO, PFMI (CPMI Papers No 101)
- Source type
- standard
- Primary or secondary status
- Primary
- Domain
- Financial Systems
- Published
- 2012-04-16
- Claims
- EL, RA
- Conditions
- 3.5
- Stance
- supports
- Relation
- complements
- Strength
- foundational
- Overlap flag
- none
Governance analogue from financial market infrastructure standards, not a doctrinal claim about software agents. Principle 8 requires that an FMI provide clear and certain final settlement, at a minimum by the end of the value date, and intraday or in real time where necessary or preferable. The accompanying legal-basis discussion states that there should be a clear legal basis regarding when settlement finality occurs, in order to define when key financial risks are transferred, including the point at which transactions are irrevocable, and treats settlement finality as a building block for risk management rather than a bookkeeping detail. Establishes an existing international standard requiring that the moment at which an action becomes irrevocable be defined ex ante and be legally determinate, including under participant insolvency. The standard governs the determinacy of the finality boundary; it does not specify evidence of a governance determination, and the entry is therefore not tagged GE. Bears on the reversibility-based allocation in Section 5.3 and on the treatment of the consequence-formation boundary; complements the compensating-transaction material catalogued at e027.
Original link