[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-researchers-patch-a-timing-gap-in-ai-agent-permissions":10,"sections":41},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":36,"feedback":40,"feedback_at":22,"cost_usd":40,"total_tokens":40},8522,"researchers-patch-a-timing-gap-in-ai-agent-permissions","Researchers Patch a Timing Gap in AI Agent Permissions","A new commit-time check closes the gap between when an AI agent decides an action is safe and when it actually executes it, though it is not foolproof.","A new paper proposes a fix for AI agents that approve a tool call, then execute it only after the permissions behind that approval have quietly changed.\n\nThe method, called BSC-R, locks a one-time commit authorization to both the specific action and the exact state of the world that justified it, so a stale or altered authorization cannot be reused. Tested on 2,847 attacked AgentDojo episodes, it preserved the agent's normal task performance (80.576% utility) while cutting successful attacks to 1.616%. Across 10,302 frozen proposals, it approved every legitimate unchanged commit and blocked all ten categories of altered or replayed ones. A separate boundary-drift test pushed further: it rejected all 4,403 invalid contexts while still approving all 5,899 valid ones.\n\nThis targets a specific, underappreciated failure mode. Agents with real tool access, like email, file systems, or payments, often check permissions once and then act on stale information, which is the agentic equivalent of a classic time-of-check-to-time-of-use bug. As more products hand language models write access to real systems, that gap between deciding and doing is exactly where an attacker would look to slip in a change.\n\nThe honest part is what happens next. On a prospective, independently run evaluation, the 3,460-scenario CONTINUITY suite, BSC-R handled the easy cases cleanly: all 700 benign runs, 1,200 of 1,200 non-replay attacks, and all 160 replay and 200 ambiguous cases. But across that suite's full 2,560 attacks, its invalid-effect commit rate was 25%, compared with 0% for CONTINUITY. A method that looks airtight on its own tests still let a quarter of bad commits through once it met a suite it did not build.","[\"ai-agents\",\"ai-security\",\"llm-safety\",\"research\"]","2026-09-30T04:00:00.000Z","2026-09-30T08:48:54.385Z","2026-09-30T08:49:00.690Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"The closing paragraph misattributes the CONTINUITY suite as 'the suite its own team built' when the source explicitly calls it a 'prospective external evaluation' suite — fix the framing so it doesn't invert which suite is internal versus external, since the source doesn't actually support that distinction.","resolved","security",[32,33,34,35],"ai-agents","ai-security","llm-safety","research",[37],{"name":38,"url":39},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2609.37475",0,{"sections":42},[43,47,50,54,59,64,69,74,79,84,89,94,99,104],{"name":44,"slug":45,"count":46,"latest_published_at":18},"AI","ai",5028,{"name":48,"slug":30,"count":49,"latest_published_at":18},"Security",780,{"name":51,"slug":52,"count":53,"latest_published_at":18},"Policy","policy",417,{"name":55,"slug":56,"count":57,"latest_published_at":58},"Deals","deals",284,"2026-09-29T21:00:00.000Z",{"name":60,"slug":61,"count":62,"latest_published_at":63},"Hardware","hardware",194,"2026-09-29T13:16:04.000Z",{"name":65,"slug":66,"count":67,"latest_published_at":68},"Science","science",154,"2026-09-28T13:19:18.000Z",{"name":70,"slug":71,"count":72,"latest_published_at":73},"Consumer Tech","consumer-tech",142,"2026-09-29T18:38:03.000Z",{"name":75,"slug":76,"count":77,"latest_published_at":78},"Software","software",91,"2026-09-25T20:55:00.000Z",{"name":80,"slug":81,"count":82,"latest_published_at":83},"Dev Tools","dev-tools",89,"2026-09-29T17:15:00.000Z",{"name":85,"slug":86,"count":87,"latest_published_at":88},"Startups","startups",83,"2026-09-29T21:51:36.000Z",{"name":90,"slug":91,"count":92,"latest_published_at":93},"General","general",49,"2026-09-28T16:44:57.000Z",{"name":95,"slug":96,"count":97,"latest_published_at":98},"Gaming","gaming",48,"2026-09-25T18:35:21.000Z",{"name":100,"slug":101,"count":102,"latest_published_at":103},"Reviews","reviews",31,"2026-09-28T14:31:34.000Z",{"name":105,"slug":106,"count":107,"latest_published_at":108},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]