[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-a-fix-for-ai-agents-that-have-too-much-access":10,"sections":36},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":24,"persona_id":22,"persona_name":22,"section":25,"tags":26,"sources":31,"feedback":35,"feedback_at":22,"cost_usd":35,"total_tokens":35},7126,"a-fix-for-ai-agents-that-have-too-much-access","A Fix for AI Agents That Have Too Much Access","A new authorization layer limits AI agents to only the tools a specific request needs, and testing found it blocks unsafe actions but not risky drafts.","A new arXiv paper proposes narrowing what AI agents are allowed to do down to exactly what a single request requires, instead of leaving them with broad, always-on permissions.\n\nThe system, called Intent-Governed Access Control (IGAC), sits between an AI agent and the tools it can call, converting each trusted request into a short-lived \"intent certificate\" that trims the agent's available tool list and checks a proposed action's real-world effects before letting it run. The researchers tested it on a platform called OpenPort across 176 synthetic tasks, pilot runs with real models, 306 end-to-end model trials, and a 36-trial external benchmark subset. In controlled tests, a composite risk score dropped from a maximum of 1.0000 to zero once IGAC applied. In the messier end-to-end trials with actual models, no unsafe action ever executed, though agents still drafted an unsafe action with excess authority in roughly 9 to 27 percent of cases - drafts that were never run.\n\nThis is the least-privilege problem the API and OAuth world dealt with years ago, resurfacing for AI agents that typically hold standing credentials to email, calendars, codebases, and payment systems far beyond what any single task needs. IGAC's numbers suggest a \"reduce, don't grant\" layer can catch most of that exposure without agents losing their credentials entirely. A stricter add-on tested in the paper wiped out even the residual drafting risk, but at what the authors call substantial cost to the agent's usefulness.\n\nThe tradeoff between safety and capability doesn't disappear here - it just moves further down the pipe, which is about as much progress as agent security has made lately.","[\"ai agents\",\"access control\",\"least privilege\",\"security research\"]","2026-09-21T04:00:00.000Z","2026-09-21T07:45:10.418Z","2026-09-21T07:45:23.472Z","published",null,[],"https:\u002F\u002Fcdn.xyz.onl\u002Farticle-images\u002Fa-fix-for-ai-agents-that-have-too-much-access.webp","security",[27,28,29,30],"ai agents","access control","least privilege","security research",[32],{"name":33,"url":34},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2606.22916",0,{"sections":37},[38,43,46,51,56,61,66,71,76,81,86,91,96,101],{"name":39,"slug":40,"count":41,"latest_published_at":42},"AI","ai",4175,"2026-09-21T10:30:00.000Z",{"name":44,"slug":25,"count":45,"latest_published_at":18},"Security",681,{"name":47,"slug":48,"count":49,"latest_published_at":50},"Policy","policy",352,"2026-09-21T10:18:06.000Z",{"name":52,"slug":53,"count":54,"latest_published_at":55},"Deals","deals",184,"2026-09-21T10:18:31.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Hardware","hardware",157,"2026-09-21T11:04:12.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Science","science",130,"2026-09-20T13:48:11.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Consumer Tech","consumer-tech",99,"2026-09-09T17:27:33.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":75},"Dev Tools","dev-tools",78,"2026-09-18T04:00:00.000Z",{"name":77,"slug":78,"count":79,"latest_published_at":80},"Software","software",75,"2026-09-10T20:41:21.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Startups","startups",55,"2026-09-09T23:14:29.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"Gaming","gaming",43,"2026-09-10T12:18:06.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"General","general",42,"2026-09-18T22:35:10.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":102,"slug":103,"count":104,"latest_published_at":105},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]