Conceptual framework demonstrates an intent-aware zero-trust architecture for autonomous agents, highlighting mechanisms to prevent unauthorized actions and intent drift.
Autonomous AI agents can hold a valid identity, a valid credential and a permission covering the operation they are about to perform — and still execute an action their principal never asked for. This paper names that residual space the Agentic Authorization Gap: the difference between what an agent is technically permitted to do and what remains legitimate under the intent it was actually delegated. It proposes Intent-Aware Zero Trust Architecture (I-ZTA), which keeps the Zero Trust principle that trust is never implicit but shifts its object from resource access to autonomous action. Five composed mechanisms are developed: the Verifiable Intent Object, a signed and bounded representation of delegated purpose that the agent can read but not rewrite; Intent Attestation, performed by a verifier independent of the agent; Action-Effect Verification, which authorises the expected state transition rather than the API call; Contextual Autonomy, six levels computed per action rather than assigned per agent; and Monotonic Agentic Delegation, under which permission, intent, effect ceiling, autonomy ceiling and validity may narrow across a delegation chain but never widen. The threat model includes a progressive Intent Drift Attack, in which locally plausible steps cumulatively escape the delegated objective while every cryptographic control remains intact. A falsifiable evaluation design and a metric set — principally the Harmful Authorized Action Rate and the Autonomy Preservation Rate — measure security and useful autonomy as two separate dimensions. Includes nine explanatory figures and a plain-language glossary of terms and concepts. No empirical results are reported; the evaluation is specified as a protocol.
No takes yet. Share an insight, caveat, or question.
Curca Mihaela (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: