Key points are not available for this paper at this time.
This paper defines the authorization boundary for agentic AI systems operating in regulated environments. As AI agents transition from generating text to producing side effects (writing to databases, submitting regulatory filings, executing transactions), the governance question shifts from "did the agent connect correctly?" to "was the agent's output authorized under governing policy, and can that authorization be independently reconstructed?" The paper introduces a distinction between access authorization (identity and scope verification, addressed by OAuth 2.1 and MCP authentication) and action authorization (evidence that a specific output complies with the specific policy version governing it at the time of the event). It argues that the MCP gateway ecosystem, while solving real problems of interoperability, traffic management, and operational control, does not necessarily produce pre-execution authorization artifacts sufficient for independent reconstruction of a specific verdict. The failure it identifies is the authorization artifact gap: the condition in which observability or access control is relied upon to satisfy a requirement for pre-execution authorization evidence. The product label is not dispositive in either direction: a gateway-labeled product may participate in or implement authorization where the demonstrated architecture satisfies the applicable requirements. The paper describes four implementation requirements for the boundary: deterministic evaluation within a declared decision state, binding to the applicable policy and version state, pre-execution emission, and state freshness with release binding (the governed state must remain valid at release, and the action released must be canonically equivalent to the action authorized). These describe the implementation model; they are not a standalone completeness test. Completeness is assessed through the corpus hierarchy: the Authorization Artifact Test as threshold (pre-execution verdict plus independent reconstruction from the artifact and its authenticated bound materials under a declared replay mode), the Authorization Boundary Integrity Model (ABIM) for Output, Input, and Replay Integrity, the Five Tests Standard (5TS) for the normative control vocabulary (Stop, Ownership, Replay, Escalation, Provenance; 5TS supersedes the earlier Four Tests Standard), and the ABIM Evidence Requirements for what the evidence permits a reviewer to conclude: for each claimed property, the evidence supports the claim, a failure witness defeats it, or the claim is not established. Input Integrity is treated as a decision-time admissibility inquiry rather than a provenance-only concept. A minimum anti-laundering screen, drawn from the Expanded Anti-Laundering Protocol (EALP), supports rapid buyer evaluation, and the Composition Test of the Closed-World Bargain applies where authorization-infrastructure claims are made. Version 3.0.0 (August 2026) retitles the paper from "Why MCP and AI Gateways Are Necessary but Not Sufficient for Regulated Agentic AI" to "What MCP and AI Gateways Do Not Establish for Regulated Agentic AI," reflecting that a runtime authorization boundary may be implemented through topologies other than gateways; aligns the paper with the Authorization Artifact Test v1.2, ABIM v1.1, 5TS v1.2.0, and the ABIM Evidence Requirements v3.5; corrects the ABSTAIN resolution semantics (an unresolved ABSTAIN remains ABSTAIN and blocks execution); supersedes the release-condition formulation so that a release condition validates, and cannot substitute for, a completed authorization artifact; scopes interception and mediation claims to declared topology and declared covered-effect profiles; adds decision-time admissibility treatment from the published corpus; updates the regulatory discussion per Regulation (EU) 2026/1744; and embeds verified primary-source citations. It supersedes Version 2.0 (July 2026). The companion paper, Execution-Time Authorization for AI Agents, develops the formal architecture of the boundary. Intended audience: infrastructure architects, compliance officers, and policy makers evaluating governance requirements for enterprise agentic AI deployments. Keywords: AI governance, agentic AI, Model Context Protocol, MCP, authorization, authorization artifacts, proof-carrying decisions, deterministic governance, regulatory compliance, Five Tests Standard, ABIM, Authorization Artifact Test, AI safety
Edward Meyman (2026) studied this question.