Runtime Authorization for Resources Acquired by AI Agents
cs.AI, cs.CR
Submitted: 2026-09-13
Updated: 2026-09-18
Comments: 54 pages, 1 figure, 9 tables, 4 algorithms. Preprint
Code: https://github.com/google-gemini/gemini-cli
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- Beyond the Mandate: A Systematic Security Analysis of the Agent Payments Protocol (AP2)
- RepliBench: Evaluating the Autonomous Replication Capabilities of Language Model Agents
- Agent Capability Negotiation and Binding Protocol (ACNBP)
- A Formal Analysis of Agent Payment Protocols
- Zero-Trust Runtime Verification for Agentic Payment Protocols: Mitigating Replay and Context-Binding Failures in AP2
- From Tool Connection to Execution Control: Benchmarking Security Invariants in MCP-Style Agent Runtimes
- Signing the Transaction but Not the Decision: Whisper Attacks and a Binding Defense for AP2
- Decentralized Granular Access Control for Agentic AI Systems in Critical Infrastructure
- SoK: Security of Autonomous LLM Agents in Agentic Commerce
- AIP: Agent Identity Protocol for Verifiable Delegation Across MCP and A2A
- Beyond OAuth: Task-Scoped Authorization for AI Agents via Natural Language Slices
- Before the Tool Call: Deterministic Pre-Action Authorization for Autonomous AI Agents
- From Intent to Execution Grant: An Execution-Boundary Conformance Profile for High-Risk AI Actions
- Agent Contracts: A Formal Framework for Resource-Bounded Autonomous AI Systems
- Darwin Godel Machine: Open-Ended Evolution of Self-Improving Agents
- Separating Capability from Permission: A Governance Framework for Agentic AI Autonomy Levels
- Governing Dynamic Capabilities: Cryptographic Binding and Reproducibility Verification for AI Agent Tool Use
- Intent-Governed Tool Authorization for AI Agents
- OpenPort Protocol: A Security Governance Specification for AI Agent Tool Access
Related papers
- MAVEN-T: Reinforced Heterogeneous Distillation for Real-Time Multi-Agent Trajectory Prediction
- Model Discovery Agent: LLM-assisted Bayesian experiment design for data-efficient discovery of mechanistic world models
- The Clinician's Veto: Navigating Trust, Liability, and Uncertainty in Autonomous AI Prescribing
- MindHelper: Closed-Loop Embodied Mental-State Reasoning for Precision Intervention
- Incumbent Advantage: Brand Bias and Cognitive Manipulation Dynamics in LLM Recommendation Systems
- VSAL: A Vision Solver with Adaptive Layouts for Graph Property Detection