[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-study-proposes-authorization-fix-for-ai-agent-delegation-risks":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},5228,"study-proposes-authorization-fix-for-ai-agent-delegation-risks","Study Proposes Authorization Fix for AI Agent Delegation Risks","A new framework called APC blocked every data-theft attempt in agent tests by tracking permissions across chained requests, not just one at a time.","A new authorization framework blocked every attempted data theft in simulated attacks on AI agents, by tracking what each agent was actually cleared to do across an entire session instead of checking each request in a vacuum.\n\nMost AI agents get their permissions once, at the start of a session, and each new request is checked in isolation, with no memory of what the agent already did - so it can act outside its assigned task, chain harmless-looking actions into something it shouldn't do, or hand a sub-agent authority with no limits. Researchers built the Agentic Principal Chain (APC) to close that gap: it tracks delegated authority as it passes from one agent to the next, runs six authorization checks against everything that happened earlier in the session, and enforces the verdict outside the model itself. Tested against 3,154 attack scenarios drawn from three existing benchmarks, APC cut AgentDojo's data-exfiltration success rate from 75-100% down to zero across all four domains and blocked all 544 data-theft attempts in InjecAgent. It also cut destructive actions from 38.6% to 4.0% and manipulation attempts from 90.5% to 12.1%.\n\nThe framing here is the useful part: prompt injection only causes damage if the agent already has the authority to do the damage, so this is an access-control problem, not just a model-behavior problem. Static, per-request permission checks miss attacks that unfold over several steps, which is how real agent workflows - the kind now wired into cloud services, internal tools, and other agents - actually run.\n\nThe fix wasn't free - task success rates on AgentDojo dropped 8.6 to 13.9 percentage points with APC running, and the paper doesn't say whether that tradeoff survives contact with a real production workload.","[\"ai agents\",\"prompt injection\",\"authorization\",\"multi-agent systems\"]","2026-08-18T04:00:00.000Z","2026-08-18T10:39:58.240Z","2026-08-18T10:40:09.993Z","published",null,[],"security",[26,27,28,29],"ai agents","prompt injection","authorization","multi-agent systems",[31],{"name":32,"url":33},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2608.15888",0,{"sections":36},[37,42,45,50,55,60,65,70,75,79,84,89,94,99],{"name":38,"slug":39,"count":40,"latest_published_at":41},"AI","ai",3293,"2026-08-20T04:00:00.000Z",{"name":43,"slug":24,"count":44,"latest_published_at":41},"Security",435,{"name":46,"slug":47,"count":48,"latest_published_at":49},"Policy","policy",210,"2026-08-19T09:32:27.000Z",{"name":51,"slug":52,"count":53,"latest_published_at":54},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":56,"slug":57,"count":58,"latest_published_at":59},"Hardware","hardware",140,"2026-08-19T18:25:42.000Z",{"name":61,"slug":62,"count":63,"latest_published_at":64},"Consumer Tech","consumer-tech",95,"2026-08-18T16:05:00.000Z",{"name":66,"slug":67,"count":68,"latest_published_at":69},"Science","science",90,"2026-08-19T18:41:02.000Z",{"name":71,"slug":72,"count":73,"latest_published_at":74},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":76,"slug":77,"count":78,"latest_published_at":18},"Dev Tools","dev-tools",69,{"name":80,"slug":81,"count":82,"latest_published_at":83},"Startups","startups",47,"2026-08-19T19:13:46.000Z",{"name":85,"slug":86,"count":87,"latest_published_at":88},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":90,"slug":91,"count":92,"latest_published_at":93},"General","general",33,"2026-08-18T22:18:13.000Z",{"name":95,"slug":96,"count":97,"latest_published_at":98},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":100,"slug":101,"count":102,"latest_published_at":103},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]