Authority versus Authorization develops a definitional framework for distinguishing five concepts that are often treated as interchangeable in discussions of AI governance: authority, delegation, policy, authorization, and enforcement. The paper’s central claim is that authority is a property of actors, while action-level authorization is a property of proposed actions. Authority determines who may authorize. Authorization determines whether a specific proposed action is permitted. Enforcement determines whether that authorization governs execution. The paper explains why these concepts were historically treated as interchangeable. In human-operated systems, the same person often held authority, applied policy, authorized the action, and executed it. Autonomous AI systems separate those roles across boards, compliance functions, software components, and agents. Once the roles separate, the vocabulary must separate with them. The framework distinguishes: Authority: the legitimate power of an actor to make, delegate, or override decisions within a defined domain. Delegation: the assignment or transfer of that authority, in whole or in scoped part. Policy: the constraints governing the exercise of authority. Authorization: the pre-execution determination that a specific proposed action is permitted under applicable policy. Enforcement: the mechanism that ensures execution cannot proceed without a valid authorization determination. The paper also distinguishes capability authorization, such as whether a subject may invoke an operation over a resource, from effect-bearing action authorization, which evaluates whether a specific proposed action may proceed in its full policy context. The two are complements, not competitors, and neither substitutes for the other. Four application settings are examined: identity and access management, corporate approvals, autonomous agents, and regulatory oversight. A worked procurement example shows how the framework can be used to review an architecture through five separate questions: who holds authority, how it was delegated, which policy applies, whether the specific action was authorized before execution, and whether the action could proceed without that determination. No implementation or product architecture is proposed. The purpose of the paper is to provide a precise, vendor-neutral vocabulary for evaluating AI governance designs and identifying cases in which credentials, policy documents, approval workflows, or retrospective records are incorrectly treated as substitutes for pre-execution authorization and runtime enforcement. This paper is part of the FERZ research program on deterministic AI governance. The full corpus is available at https://zenodo.org/communities/ferz/.
Meyman et al. (Mon,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: