Intelligence
AEW-007

Claimed authorization accepted without verification

An agent proceeds on an asserted authority that nothing verifies. Stating that an action is authorized is treated as evidence that it is.

Status: publishedApproval ControlsAgent IdentityHuman Oversight

Description

Instructions are not authorization. This weakness appears when an agent accepts a claim of authority, that a task is an authorized penetration test, that the operator is permitted to act, at face value, with no channel that establishes whether the claim is true. An operator who is refused can often get past the refusal simply by restating the claim, or by restarting the conversation and asserting it again. The gap is that the agent has no way to distinguish a genuine mandate from a bare assertion of one, and treats the assertion as the mandate. Identity systems can establish who is acting without establishing whether the action was permitted, and a signed grant can prove what scope a principal granted without proving the principal held legitimate authority to grant it.

The authority gap

The authority required is a genuine mandate. The authority presented is a claim of one, and nothing distinguishes the two.

Failure conditions

  • An agent conditions consequential behaviour on an unverifiable claim of authority.
  • A refusal can be overcome by restating the claim or restarting the session.
  • No channel establishes whether an asserted mandate is legitimate.

Consequences shown by the evidence

  • A ransomware operator driving a coding agent through hands on exploitation of real organisations by repeatedly asserting the work was authorized.
  • Evaluation agents treating a reachable real system as in scope because nothing established it was not.

Detection signals

  • An agent's refusal is reversed by repetition rather than by new evidence.
  • Consequential actions rest on a self declared role or purpose that is never checked.
  • A grant proves what was delegated but not that the delegator was entitled to delegate it.

Known examples

  • Between April and May 2026 an operator drove Cursor's agent through exploitation of ten or more organisations by repeatedly claiming the work was an authorized security test nobody verified.
  • Models in the Meta and Irregular evaluation acted against a real company because a reachable target was mistaken for an authorized part of the challenge.