The New Authorization Problem Created by AI Agents 

Last updated

AI agents introduce a new wrinkle into digital trust: a legitimate user can direct a legitimate agent to take an action that either falls outside the user’s own authority or exceeds the authority delegated to the agent. 

That creates a problem authentication alone cannot solve.. Verifying the person behind an interaction is still essential, and businesses increasingly need to know whether an AI agent has permission to act on that person’s behalf. But neither tells us whether the person had the authority to request a particular action in the first place.

As agents gain the ability to navigate websites, interact with applications and complete tasks across multiple services, that distinction becomes increasingly important. The challenge is no longer simply authenticating the human or the agent. It is understanding the chain of authority connecting the person, the agent and the action being taken.

Authentication isn’t the same as authorization

We already spend considerable effort determining whether a person is who they claim to be online. The industry is rapidly developing ways to identify and authenticate AI agents as first-class digital actors. But authenticating the agent is only one part of the problem. Businesses also need to know whose authority the agent is exercising, what was actually delegated, and whether that authority covers the action being attempted.

But even that doesn’t solve the whole problem. A person can be authentic. An agent can genuinely belong to that person. And the requested action can still be illegitimate.

This is why we believe agentic interactions require an actor assurance approach. We think of actor assurance as establishing confidence in four connected things: the identity of the human principal, the identity of the agent acting for them, the authority that was delegated, and whether the specific action falls within that authority.

هل ترغب في معرفة المزيد؟
اتصل بنا اليوم للتحدث إلى أحد خبراء Microblink المتخصصين في مكافحة الاحتيال وحماية الهوية

Consider an authenticated customer who instructs an authorized AI agent to access an account that belongs to someone else. Proving the identity of the customer doesn’t establish that they have authority over the target account. Likewise, proving that the agent was legitimately delegated by that customer doesn’t make the requested action legitimate.

That creates several distinct questions: Who is the person behind the request? Which agent is acting for them? What authority has been delegated to that agent? And does that authority actually extend to the action being attempted?

These questions become especially important when agents can act across multiple services. Authentication and authorization are no longer confined to a single interaction between a person and a business. They can become distributed across the person, the agent, the platform powering it and the organization receiving the request.

A lesson from online payments

The payments industry has long treated authentication and authorization as separate decisions. In an online card purchase, EMV 3-D Secure helps the issuer assess whether the person making the purchase is the rightful cardholder. The issuer then decides whether to authorize the transaction, considering the account and the transaction itself. A successful identity check does not mean every payment must be approved. Visa describes the two steps separately.

The analogy becomes more interesting when an agent acts for someone. In the familiar flow, the person attempting the action can be authenticated directly. In an agentic flow, the person who has the authority may be elsewhere, while the agent presenting the request authenticates to the service. The service has to connect them.

Suppose you authorize an agent to find flights and book one under $500. The airline may authenticate the agent perfectly. That answers which software sent the booking request. It does not answer whether you were genuinely the person who granted the mandate, whether the mandate is still valid, or whether a $1,200 booking is within its limits. The airline or its partners must evaluate the requested action against the authority behind it.

This idea is already emerging in agentic-commerce standards. Rather than treating the agent’s identity as sufficient authorization, these models use verifiable mandates to express what a person authorized the agent to do and the constraints under which it can act. The principle extends beyond payments: the agent needs not only an identity, but evidence of bounded authority for the action it is attempting.

Authority also has a lifecycle. A person may revoke an agent’s permission, an authorization may expire, or changing circumstances may require the human to approve an action again. Establishing that authority existed once isn’t enough; businesses also need confidence that it remains valid when the agent acts.

The chain also needs to be auditable. For consequential actions, businesses may need evidence of who granted the authority, which agent received it, what constraints applied, whether those constraints were still valid, and what action ultimately occurred.

There are therefore three decisions, often made at different times: establish and, when needed, reauthenticate the human; establish what that human is permitted to do and has delegated; then authenticate the agent and authorize its specific action. For a higher-risk request, the system may need to bring the human back into the loop. The order can vary by workflow, but the questions cannot be collapsed into one agent credential.

Persistence changes the equation, too

Delegated authority also has to account for how agents behave over time, not simply whether an individual request falls within a defined permission. For example, a human trying to complete a task might give up after several failed attempts. An agent can continue trying, adjust its approach and work through multiple steps without becoming tired or frustrated. Different agents will have different levels of autonomy and persistence, creating another variable businesses will have to account for.

That doesn’t make persistence inherently malicious. In fact, persistence is one reason agents can be useful. An agent that patiently finds an appointment, resolves a customer-service issue or completes a complicated booking can save someone considerable time.

But the same capability changes the economics of abuse. Actions that once demanded sustained human effort can increasingly be delegated to software. For fraud and identity teams, that means activity cannot always be evaluated solely by asking whether an individual request looks legitimate. They also need context around the actor, the authority behind the action and patterns that emerge across repeated interactions.

Trust has to account for the actor

This is part of the reason Microblink has developed the idea of Know Your Actor.

Traditional identity verification establishes an important foundation: who is this person, and does the evidence support the identity they are presenting? That remains essential. But agentic interactions add actors between the verified person and the eventual action.

Businesses need to understand the relationship between a verified identity, an agent acting on that identity’s behalf, the authority delegated to that agent and the action being requested. Just as importantly, they need enough context to recognize when those pieces don’t line up.

The goal shouldn’t be to treat every AI agent as suspicious. Agents will increasingly become legitimate participants in digital commerce. The challenge is distinguishing legitimate delegation from abuse without creating unnecessary friction for either people or the agents acting for them.

AI is giving individuals access to capabilities that previously required considerably more expertise and effort. That’s a powerful development. But as the distance between a person and an action grows, identity and authorization have to evolve with it.

In the agentic era, authenticating the agent is only the beginning. Businesses will increasingly need a verifiable chain from person to agent to authority to action: who authorized the agent, what it was allowed to do, whether that authority is still valid, and whether the attempted action can be trusted.

اكتشف حلولنا

استكشاف حلولنا على بُعد نقرة واحدة فقط. جرّب منتجاتنا أو تحدث معنا مع أحد خبرائنا للتعمق أكثر في ما نقدمه.

المزيد من المعلومات

مواصلة القراءة

استكشاف المزيد
The New Authorization Problem Created by AI Agents 

The New Authorization Problem Created by AI Agents 

AI agents introduce a new wrinkle into digital trust: a legitimate user can direct a legitimate agent to take an action that…

اقرأ أكثر
ختام العام بالتطلع إلى المستقبل: لماذا أصبح المجتمع والتعاون أكثر أهمية من أي وقت مضى

ختام العام بالتطلع إلى المستقبل: لماذا أصبح المجتمع والتعاون أكثر أهمي…

مع اقتراب نهاية العام، وجدت نفسي أفكر في العوامل التي أحدثت فرقًا حقيقيًّا في عام 2025. ليس فقط من حيث التكنولوجيا أو مؤشرات…

اقرأ أكثر
لماذا يحتاج التحقق من الهوية إلى التحليلات، وليس الدقة فحسب 

لماذا يحتاج التحقق من الهوية إلى التحليلات، وليس الدقة فحسب 

لسنوات عديدة، ركزت المؤسسات التي تقيّم حلول التحقق من الهوية على مجموعة مألوفة من المعايير. فقد كانت معدلات الدقة، وتغطية الو…

اقرأ أكثر
لماذا يُحسّن التقاط الصور بدون إطار من أداء التحقق من صحة المستندات

لماذا يُحسّن التقاط الصور بدون إطار من أداء التحقق من صحة المستندات

لا تفشل عملية التحقق من الهوية بسبب عدم دقة الأنظمة. بل إنها تفشل عادةً لأن المستخدمين ينسحبون قبل أن يتمكن النظام من أداء مه…

اقرأ أكثر
لماذا يُعد كل من المقارنة المعيارية والقدرة على التفسير أمرين بالغين الأهمية في عملية التحقق من الهوية

لماذا يُعد كل من المقارنة المعيارية والقدرة على التفسير أمرين بالغين ا…

تناولت مدونة حديثة للرئيس التنفيذي لشركة Microblink، هارتلي طومسون، الكيفية التي يغير بها الذكاء الاصطناعي التوليدي (Gen AI)…

اقرأ أكثر
عندما تتصرف العناصر الذكية الاصطناعية (وربما تهاجم)

عندما تتصرف العناصر الذكية الاصطناعية (وربما تهاجم)

في الآونة الأخيرة، بدأ نوع جديد من القلق يظهر في أوساط التكنولوجيا. لا يتعلق الأمر بانتهاكات الأمن أو انقطاعات الخدمة، بل بال…

اقرأ أكثر
تقرير
تحديد ملامح تزايد حالات الاحتيال المتعلقة بالهوية المدعومة بالذكاء الاصطناعي

لم يقتصر دور الذكاء الاصطناعي على تسريع عمليات الاحتيال فحسب، بل جعلها نظامًا متكاملًا. فقد قمنا بتحليل ملايين التفاعلات المتعلقة بالهوية لرسم خريطة لكيفية تطور هجمات الهوية عبر المناطق وأنواع الهجمات ومستويات تعقيدها — وما يتعين على المؤسسات إعادة النظر فيه لمواكبة هذه التطورات.

اطلع على البيانات