Who Authorized This?
Responsibility in a world of delegated agents
by Sasha Shilina
In July 2026, AI agents used during OpenAI’s internal cybersecurity evaluations escaped the boundaries intended for them. According to OpenAI’s incident report, the models found ways around isolation controls, reached the public internet, exploited vulnerabilities and compromised parts of Hugging Face’s infrastructure. OpenAI later described actions that had departed from the goals of the evaluation, including unauthorized communication and attempts to gain broader access.
Anthropic has documented related cases in its own cybersecurity evaluations, including instances in which Claude models gained unauthorized access to third-party systems.
A quieter version of the same problem is already emerging in ordinary software: a travel agent may search flights, change reservations and pay deposits; a coding agent may inspect a repository, call external tools and deploy changes; a financial agent may move between market data, lending protocols and wallets while pursuing a goal expressed in a few sentences. By the time an action reaches the outside world, the original request may have passed through several systems. Logs can show which component executed the final step. They are often less useful for reconstructing who initiated the process, what authority was granted, how that authority was delegated and whether those limits still applied at the moment of execution.
Current permission models were built around users, applications and credentials. Autonomous agents stretch the path from instruction to execution.
The distance between permission and action
Traditional software usually acts within permissions defined in advance. Access to a folder, a database, an API or an account can be traced to a credential and a specific capability.
Agents complicate that structure. They receive goals in natural language, infer intermediate steps, choose tools and decide how to pursue the task. The authority granted at the beginning is translated through a sequence of judgments before it becomes an action.
A human may write:
Fix the deployment.
Find me the best deal.
Investigate the vulnerability.
Reduce our infrastructure costs.
The details emerge later. The agent chooses tools, defines intermediate steps and decides when another service should be involved. A short instruction can generate dozens of actions the person never described individually.
Write access to a repository may be necessary for routine maintenance. The same credential can permit changes to deployment configuration, deletion of files or exposure of secrets. A browser-enabled research agent may authenticate to another service and continue acting there while the person at the beginning sees only the result.
What the credential usually fails to preserve is the reason the capability was granted and the boundaries attached to that reason.
By September 2026, this had become concrete enough to enter standards work.
On September 29, the U.S. National Institute of Standards and Technology published the results of a consultation on software and AI-agent identity and authorization. More than 600 responses came from government, academia and industry. NIST selected software development as the first environment for demonstrating how agents can be identified, authenticated and authorized, and included auditing and non-repudiation in the same program.
A system can know exactly which agent acted and still have an incomplete record of why the agent was allowed to act.
An old problem called agency
Law has had a vocabulary for this for centuries: principal, agent, authority, delegation. In agency law, a principal authorizes another party to act on their behalf. What follows depends heavily on the boundaries of that authority. What was explicitly granted? What could reasonably be inferred from the assignment? What could an outside party reasonably believe the agent was entitled to do?
The distinctions between express, implied and apparent authority exist because delegation is rarely clean.
The same problem appears almost immediately when software begins acting on someone’s behalf. Tell an agent to arrange a trip to Mumbai. Booking the flight is clearly part of the assignment. Choosing a sensible connection probably is too. A first-class ticket is more questionable. Extending the trip by three weeks is harder to defend. Signing a lease in Mumbai would be harder still.
The edges are familiar. The speed and scale are new.
Human institutions can spend months arguing over whether someone acted within a mandate. Software may cross the same boundary in seconds, through several systems, before anyone notices.
What did I actually authorize?
One can recall G. E. M. Anscombe’s work on intention here. In Intention, she argued that one event can fall under several descriptions, and an action may be intentional under some of them while unintended under others. Her account pays close attention to the reasons an actor can give when asked why they acted.
Suppose I ask an agent to reduce my cloud bill by 20 percent. It finds unused infrastructure and deletes it. One of the deleted resources contains an archive that later turns out to be important.
Several descriptions fit the sequence:
I asked for lower infrastructure costs.
The agent removed an unused resource.
The deletion destroyed an important archive.
My instruction started the process that destroyed it.
The causal history is easy to reconstruct. Intention is less clear.
Most software permissions would tell us whether the agent had the capability to delete the archive. They would preserve far less information about the purpose attached to that capability.
Now add another layer. I authorize Agent A to optimize infrastructure. Agent A calls Agent B to clean up storage. Agent B invokes a tool that deletes the archive.
The log can be complete while the mandate becomes difficult to recover.
Delegation has a shape
The Agent Passport System draft published on September 28 tries to make some of these relationships explicit. It remains an individual IETF submission, but its architecture is revealing: agent identity, principal, delegated authority, policy approval, execution and observed result are treated as distinct things.
Authority can also narrow as it moves.
A travel agent might receive permission to spend $2,000 over seven days on flights and hotels. If it delegates the hotel search, the second agent may receive an $800 ceiling, permission to book hotels only and the same dates.
It sounds simple when written out like that.
In a working system, those conditions may be scattered across prompts, API credentials, policy engines and application code. A restriction may be inherited by one component and disappear in another. An upstream grant may be revoked while a downstream system still appears able to act.
At that point, it is no longer enough to know who executed the request. You need the history of the authority behind it.
The sub-agent problem
Agentic systems encourage decomposition. One agent discovers another with a useful capability, sends it a task and incorporates the result. That second agent may call a third.
Human organizations have lived with comparable structures for a long time. A CEO delegates to an executive, who delegates to a manager, who assigns work to an employee, who may hire a contractor. Contracts, budgets, internal policies and liability rules surround those relationships.
Delegation across organizational boundaries makes the gap especially visible. An agent run by one company may invoke an external agent from another provider. Instructions and credentials move into a system the original principal cannot inspect. That agent may then call additional services.
An audit record has to preserve the path by which the action became authorized: who initiated it, what scope was granted, which restrictions travelled downstream, when they changed, whether they were still valid at execution time and what could have been revoked.
That record forms a delegation lineage: the history of a mandate as it moves through different actors.
Without it, ‘the user approved it’ says very little.
A human at the beginning of the chain
In some systems, the first actor in the delegation chain needs to resolve to a unique human.
Humanode’s ecosystem Agentlink connects agents to people who have completed uniqueness verification through Biomapper. One verified person can operate several agents while a service retains a way to resolve them to the same human origin when its rules require that information.
The immediate applications are: a service that gives one free allowance per person needs a defense against thousands of disposable agents controlled by one operator; a work platform may need to know whether a group of agents ultimately belongs to the same participant; governance can permit substantial automation while keeping membership attached to verified people.
The same human anchor can also sit at the root of a delegation chain:
human → agent → sub-agent → tool
The proof establishes the origin of the branch. Scope, permissions and revocation still need their own records.
Responsibility without constant supervision
Human oversight cannot mean approving every move an agent makes. If the system is expected to act with any real autonomy, much of the responsibility has to be expressed before the action begins: what the agent may decide for itself, which actions require escalation, how long the mandate lasts and what happens to those limits when part of the task is delegated.
A financial agent may have a spending ceiling. A deployment agent may be free to modify code while production changes require another approval. A sub-agent may receive only a narrow slice of the authority held by the agent that invoked it.
Those boundaries also need to remain visible later. If something goes wrong, it should be possible to tell whether the agent stayed inside its mandate, interpreted an ambiguous instruction aggressively, or crossed a limit that should have stopped it.
Who authorized this?
By the time an autonomous system acts, the person who initiated the process may be several steps away. One agent had an identity, another inherited part of its task, a policy engine approved something in between, and a tool eventually executed the command. Calling the whole arrangement “the user” erases most of what we would want to know afterward.
Humanode can provide one piece of that chain: a persistent human principal beneath multiple computational actors, with Agentlink preserving the connection between that person and the agents that originate from them. The rest has to survive elsewhere: the permissions, the delegation, the conditions attached to it and the points at which those conditions changed.
That record starts to look like a genealogy of authority. Where did the mandate begin? Who received it? What travelled with it? What was lost?
When an agent causes damage, the machine that issued the final command may be the least interesting part of the story.