Authorization was built for a different kind of actor.
Software authorization was designed around three kinds of principal:
Humans
Services
Deterministic programs
Each is either accountable in person or predictable by construction. A role granted to them means roughly the same thing tomorrow as it does today.
AI agents are different.
- They interpret.
- They plan.
- They choose tools.
- They process untrusted information.
- They act probabilistically.
- They learn from context.
- They may operate continuously.
- They may modify their own workflows.
The same agent can be reliable at 9:00 and compromised by a document at 9:04. Its model can be swapped for a cheaper one without anyone updating its permissions. A static grant can’t see any of this.
Static IAM alone is insufficient.
Identity and access management remains necessary. But agents need a layer that decides, at the moment of action, how much of that access should be exercised without a human.
What the next layer requires.
- 01Identity
- 02Policy
- 03Context
- 04Evidence
- 05Risk
- 06Dynamic authority
- 07Human escalation
- 08Verification