Fetching from the wire…
Public story · 2026-07-27 · high
The proof shows an agent's authority can't grow past its original ceiling, even as it gains skills or delegates tasks, under four stated conditions.
Why now: The paper is dated to July 2026, right as agent deployments increasingly let bots gain tools and delegate tasks after launch, the exact drift its ceiling is designed to survive.
A new paper argues AI agent permissions shouldn't assume the agent you approved is still the agent running your tasks, per arXiv 2607.23586.
The paper identifies six ways an agent's behavior can drift after a grant. Current permission systems miss all six, whether the agent picks up new tools, rewrites its own workflow, or delegates work to other agents.
Their fix is a state-bound model. At the moment authority is granted, the system locks in two things. One is a transition envelope for how the agent's state can evolve. The other is an effect ceiling on what it's allowed to do, and that ceiling doesn't move afterward. Below it, authority can contract on its own as the agent specializes. It only expands back when the system has specific evidence for it, not just a request from the agent.
The authors prove this holds under four conditions. Every agent action has to pass through the system, what they call complete mediation. The system's abstraction of what an action does can't undercount the real effect. Delegation can only narrow authority, never widen it. And the monitor enforcing all this can't be fooled. If all four hold, no sequence of changes to the agent, however long-running, can push its effects past the ceiling set at the start.
That's the whole guarantee: four conditions, proven mathematically, none of them a description of a system that's already running. Anyone building agents that pick up tools and hand off tasks over time has a spec for what to check. It's not a tool they can install yet.
Each link below shares sources, entities, or timing with this story.
arXiv 2608.02764 targets agents that issue refunds, reserve inventory and move money, where budgets and approval status change between authorization and effect. The authors define policy-state serializability: committed effects must be explainable as authorized against the pol...
Ockhamareto (arXiv 2608.24473) reinforces a unit-test rollout only when it's non-dominated on both mutation-killing and test count, then ties each test's killing power back to specific source tokens. Against MIST-RL that's a 3.4x better per-test trade-off, plus 30 to 35 percen...
Thinkingbox is an MCP-compatible sandbox with isolated sessions, full execution traces, and outcome evaluation against terminal backend state, carrying 507 policy-conditioned workflows across retail, hospitality, auto insurance, neobank internal IT and consulting support (arXi...
arXiv 2608.13030 points out existing agent protocols specify message exchange but not how an agent proves identity, authorization, advertised capabilities, or accountability after delegation. It adds Persistent Identity, Discovery, Trust Negotiation and Accountability layers v...
arXiv 2608.06370 evaluated models emitting code that calls tools against JSON-schema tool calling on BFCL v4. PTC matched or exceeded the baseline in 11 of 14 models, with the GPT-5.6 family up 10.6%, and held stable under parallel execution in 13 of 14. Under context degradat...
ScrambleToolBench strips semantic cues from tool schemas, then injects mapping drift, stochastic failures, and temporal execution windows. Frontier models discover the initial mapping fine but show belief inertia or fall back to exhaustive search under structural change, and i...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.