Intelligence

Governance & Policy

Regulation, standards bodies and the internal policies organisations write for autonomous systems. What is actually enforceable, what is aspiration, and where the two are being confused.

Foundational reading

40 pieces
15 August 2026

The Agent Never Escaped the Sandbox. It Still Reached the Real World.

AISI ran one cyber challenge 122 times across seven models. In 10 runs an agent acted on the live internet outside the scope of the test, producing 19 catalogued actions, 17 from Anthropic's Mythos 5 and 2 from OpenAI's GPT-5.6 Sol with cyber classifiers disabled. The containment boundary held. The question Moona Intelligence takes from it is different: once a channel as broad as the internet is legitimately open, what decides which people and systems it may be used against?

Incidents11 min read·Moona Intelligence

More in this topic

28 August 2026

CEOs Own the AI Budget. Who Owns the Agent's Actions?

A LinkedIn post citing a 72% figure and an unverifiable 14% figure sent me looking for the research behind it. BCG's AI Radar 2026, a survey of 640 CEOs among 2,360 executives across 16 markets and nine industries, is the real source of the 72% figure. The same survey shows CEOs committing over 30% of 2026 AI investment to agents, and its most aggressive adopters already running agents end to end. Nowhere in it does anyone ask who authorizes what one of those agents is actually allowed to do.

Agent Authority6 min read
28 August 2026

SARC Shows Why Remediated Agent Actions Need to Be Re-Evaluated

SARC Suite One-Pass, Gaston Besanson's artifact for the paper One Gate Is Not Enough, composes three governance engines at a single pre-action control point and adds a Remediate-Regate protocol: evaluate the evidence gate first, recompute context after substitution, then re-evaluate every gate on the remediated action. I reproduced its 207 reported tests from a clean clone, then added 8 adversarial tests of my own without changing any existing code or scenario. All 215 passed. The reauthorization holds for the two properties its authority policy actually reads, role and order value. Six other properties the action context carries, including which resource is targeted, which agent is acting, and when the action happens, are present in the data but never reach the authority decision.

Agent Authority14 min read
28 August 2026

Drata Used to Help You Prove the Control Existed. Now It Wants to Enforce It Before the Agent Acts.

On 4 August 2026, Drata opened Limited Availability for AI Agent Governance, a product built on three components it calls Sensor, Mission Control and Chain of Custody. Drata's own material states that Mission Control evaluates every agent action against approved policy in real time and blocks violations inline, before they execute, using policies a team writes in plain English and Drata compiles into enforceable rules. The release covers agents running on Anthropic today, with OpenAI, Google Vertex AI and AWS Bedrock described as in active development. Drata is a compliance evidence company. What it just tried to ship is not another audit report. It is a claim to sit at the moment an agent is about to act and decide whether it may.

Agent Authority12 min read
26 August 2026

Ask DataHub Requires Human Approval. One Setting Decides Whether It Still Does.

DataHub Cloud v2.1 made Ask DataHub generally available on the strength of one claim: the chat agent pauses for human in the loop approval before applying a metadata edit on the web. DataHub's own release notes document the control underneath that claim directly, an environment variable called DATAHUB_AI_TOOL_APPROVAL_ENABLED, default true, re read per chat turn, that switches every mutating tool from paused to auto applied. Moona Intelligence reads that as two separate authority questions stacked on top of each other. The first is whether one write gets a human's yes. DataHub answers that one. The second is who is allowed to decide that future writes stop needing a yes at all, and on the evidence available, that decision sits outside anything DataHub's own permission model documents.

Agent Authority11 min read
25 August 2026

Your Admin Can Change It. Does That Mean Their AI Agent Should?

OpenAI's 25 August 2026 announcement describes an Admin plugin that lets a workspace administrator review activity and credit usage, add or remove members, update groups, adjust usage limits and approve or deny spending requests, entirely from a ChatGPT Work or Codex conversation. The plugin's own documented boundary is that it operates within each user's existing role and permissions, does not grant broader access, and maps administrator instructions to supported read or write actions. OpenAI describes pending usage requests routed to Slack or Microsoft Teams for an authorized reviewer to approve or deny, feature access requests granted automatically when predefined criteria are met with exceptions routed for review, and broader impact changes admins can review before they are applied. Moona Intelligence verifies that architecture against OpenAI's supporting plugin and admin control documentation, and separates four things this record keeps distinct: the administrator's own workspace role, the workspace's decision to install and configure the plugin and its underlying app, the specific operations the plugin currently supports, and the review step that applies to some of those operations and not others.

Agent Authority16 min read
25 August 2026

If You Can Do It in Salesforce, Your AI Agent Can Do It Too

Salesforce's Headless 360 MCP Server has run in open beta since July 2026, and a 19 August 2026 expansion, republished to Salesforce's Asia Pacific newsroom on 25 August, layers new Data 360, Slack and skills capability around it at varying maturity levels. The server's own documentation states plainly that every transaction executes as the authenticated user, scoped through an External Client App carrying a dedicated mcp_api scope, with object permissions, field level security, sharing rules, profile permissions and permission sets all applying before the Dispatch tool is allowed to run. If a person cannot perform an action in Salesforce, their agent cannot perform it through the MCP server either. Moona Intelligence verifies that claim precisely, narrows what inherited trust actually composes to, and finds a real, working boundary for technical permission sitting directly beside an undocumented one for organizational mandate: nothing in the architecture establishes that a user who can deactivate a colleague, deploy an Apex trigger or assign a permission set was ever asked whether an AI agent should be allowed to do the same thing on their login. Updated 28 August 2026 with Salesforce and Anthropic's 26 August 2026 Claudeforce announcement: Salesforce in Claude, a Plugin shipping to pilot customers with 37 prebuilt sales skills, calls the same Salesforce MCP architecture this record already verified, with Salesforce's own language stating explicitly that no new permissions model needs to be built.

Agent Authority28 min read
25 August 2026

The Dealer Had Permission to Hedge. Your Bourse Let an AI Agent Use It Too.

Your Bourse, the FX, CFD and crypto trading infrastructure provider, published a content hub piece on 18 August 2026 describing MCP for Trade Server, a connection that lets a broker link a compatible AI assistant to its Trade Server backend. Finance Magnates corroborated the same day that broker staff can query live data and initiate permitted hedges or position closures. Your Bourse's own material states the assistant inherits the permissions attached to the connected user's existing Trade Server credentials, that instructions affecting positions or funds return a preview before anything executes, and that execution follows only after a person approves it and is then recorded in Trade Server the same way as an action taken through the ordinary interface. Moona Intelligence verifies each part of that claim separately, keeps the employee's technical login permission apart from any organizational mandate to delegate it to software, and finds Your Bourse has not documented whether the confirmation step is enforced inside Trade Server itself or depends on the connected AI client honoring it.

Agent Authority15 min read
24 August 2026

Google Can Now Prove Which Agent Acted. Proving It Was Allowed To Is a Separate Question.

Google Cloud gives an AI agent a first class IAM identity of its own, a strongly attested, SPIFFE based cryptographic identity tied to the lifecycle of the resource hosting it, distinct from a human identity or a shared service account. Agent Identity reached general availability on 14 August 2026, according to Google's own IAM documentation, with Auth Manager, the centralized credentials vault and authentication broker that sits alongside it, still in preview that same day. Auth Manager and its two supporting APIs reached general availability on 22 August 2026. Google's own material states plainly that agent identities are not shared by multiple workloads by default, cannot be impersonated and do not let a developer generate a long lived service account key, and that when an agent acts for a person, Google's own audit logs can carry both identities. Moona Intelligence verifies each claim against Google's own documentation, narrows what is not established, and separates identity proof, credential access and proof that a specific consequential action belonged to the mandate a person or organization actually granted.

Agent Authority30 min read
24 August 2026

NIST Wants an Identity for the Agent. Authorization Is a Separate Question.

The NCCoE's concept paper, published 5 February 2026 with public comment open through 2 April 2026, proposes a practical demonstration project applying identity and access management standards including OAuth, OpenID Connect, SPIFFE and SPIRE, SCIM and Next Generation Access Control to software and AI agents in enterprise settings. Moona Intelligence verifies what the paper actually establishes: a draft proposal exploring a demonstration project, not a finished standard, not enacted policy, and not a completed practice guide. Its most useful contribution is not a technical answer but a structural one, that an agent's identity, its authorization to act, the human authority it acts under, and the record of what it did are four separate things a system has to get right, and having one does not prove the others.

Governance & Policy10 min read
24 August 2026

Your Employee Has Access. Whether an Agent Inherits It Is Not Their Call.

Okta's Cross App Access did not launch today. It was announced 23 June 2025, expanded to a 25 plus partner ecosystem on 23 June 2026, and given Auth0 implementation guidance on 6 August 2026 that named 24 August 2026, the current radar date, as when integrations including Anthropic, Asana, Canva, Cloudflare, Cursor, Datadog, Docker, Figma, VS Code and Zoom were expected to reach the Okta Integration Network. Two days before that, on 22 August 2026, the Model Context Protocol's own Lead Maintainers published a new roadmap making agent identity and enterprise ready security one of five top level protocol priorities, naming cloud workload agents, absent users and subagent delegation as cases the current browser consent model does not serve, and pointing at DPoP, Workload Identity Federation and the ID JAG grant behind Enterprise Managed Authorization as the intended path. Moona Intelligence verifies each stage of that chronology separately, reads the protocol's own mechanics and its own roadmap post directly, and separates what is confirmed stable today from what remains directional specification work. The distinct question underneath all of it: Cross App Access moves the decision to let an AI agent inherit an employee's application access from a consent screen the employee clicks through to a policy an administrator configures once, and the employee whose access is exercised is not necessarily the actor who was organizationally entitled to make that decision, a question the new roadmap now extends to cloud workloads and to agents acting for other agents.

Agent Authority29 min read
23 August 2026

The Agent That Wrote the Code Cannot Approve It

The AI-native SDLC playbook describes six stages, Plan, Design, Build, Test, Deploy and Maintain, run as a loop rather than a line, with AI embedded at each point. The part worth reading closely is not the stages. It is what Anthropic puts at the seam between them: a hook, described as the deterministic control behind an advisory instruction, that can allow, ask or block before Claude acts, a production deploy hook that holds a release until a named release manager authorizes it, and a rule that a non interactive agent run carries its own identity so a pipeline log can tell what the agent did from what the engineer did.

Agent Authority11 min read
23 August 2026

Your Agent Has a Certificate. Now the Certificate Wants to Prove Where Its Authority Came From.

Draft wei aic identity cert 00, AI Agent Identity Certificate (AIC) Extension for X.509 v3, was posted to the IETF Datatracker on 19 August 2026 by Jijie Wei as an individual Experimental Internet Draft. It proposes a certificate extension binding an agent's identity to a principal, carrying capability and constraint fields and a signed delegation record, alongside a companion PrincipalAuthorization extension in the principal's own certificate. Moona Intelligence reads it against the harder question underneath: can a relying party establish not only that a principal delegated a capability, but that the principal was itself certified as holding authority that included it.

Agent Authority16 min read
22 August 2026

The Agent Has a Credential. x401 Asks Who Actually Gave It the Authority.

Proof launched x401, the HTTP Proof Requirement Protocol, on 25 June 2026. The specification now published as version 0.2.0 has changed materially since that launch: Agent binding, required in version 0.1.0, is now explicitly optional, and a delegation evidence mechanism that version 0.1.0 left as an open question is now named and specified. Moona Intelligence reads the current draft directly against a strict Agent Authority and Authority Provenance standard, distinguishing what the generic protocol establishes from what only Proof's own implementation, a human verified to IAL2 signing a scoped mandate, actually does.

Agent Authority15 min read
22 August 2026

Estonia Wants an Identity for the Agent. The Human's Authority Is a Separate Question.

Estonia's Eesti.ai advisory board agreed on 17 June 2026 that the country should build AI ID codes, a digital identity distinct from the human, company or organization an agent acts for, so that an agent can be given limited and controllable powers instead of inheriting a principal's full access to accounts, services and data. Prime Minister Kristen Michal backed the proposal directly. This is a government backed proposal and development direction, not enacted law, a published technical standard, an operational credential or demonstrated enforcement. Moona Intelligence reads it against the Authority Provenance question the primary material does not answer: even once an agent's identity and its delegated scope are established, what proves the person who granted that scope was actually entitled to grant it.

Governance & Policy14 min read
22 August 2026

Visa and Mastercard Joined the Same Room. They Still Have to Decide Who Authorized the Agent.

Rain convened 26 companies, among them Visa, Mastercard, Fiserv, Circle, Fireblocks and Coinflow, into the Agentic Payments Alliance on 18 August 2026. Rain describes it as a coalition run collectively by its founding members, with early work expected to include shared research, testing emerging standards for agent identity and authorization, and advocacy on regulatory questions. Moona Intelligence reads the announcement against what it actually establishes: a formal industry recognition that agent payment authority has to travel across organizations that never participated in the original delegation, and no published answer yet for how a downstream participant verifies that authority.

Agent Authority21 min read
22 August 2026

The Agent Has Authority. Nuggets Wants Proof of Who Gave It.

Nuggets announced its Authority Control Plane on 22 July 2026, describing an enforcement point that evaluates an agent's identity, authority, organizational policy, intent and runtime context before an action proceeds, then issues a cryptographically signed Action Receipt for the decision. Moona Intelligence reads that claim against Nuggets' own documentation and against langchain nuggets, its public open source integration, to separate what is independently verified from what is Nuggets describing its own system. The distinct question this record tracks is not whether the action was allowed. It is whether anyone can show who gave the agent its authority in the first place, and whether that person was actually entitled to give it. Updated 23 August 2026 with the Fintech Times' corroborating coverage of the same launch and with Forrester's own, earlier research on the broader agent control plane category this launch sits inside.

Agent Authority14 min read
22 August 2026

China Just Drew Three Lines Around AI Agent Authority

The Cyberspace Administration of China, the National Development and Reform Commission and the Ministry of Industry and Information Technology jointly issued the Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents on 8 May 2026. Its sixth item asks operators to sort agent decisions into three classes: decisions limited to the user personally, decisions requiring the user's authorization, and decisions the agent may make autonomously. It then adds the sentence that matters most for anyone building agents: operations executed by the agent must not exceed the scope the user authorized. This is national policy guidance, not a statute and not a technical standard, and it is worth reading for the allocation it describes rather than for any enforcement it demonstrates.

Governance & Policy12 min read
22 August 2026

The Agent Has Permission. Can It Prove Who Gave It That Authority?

Joseph Geo Benjamin, Anil K. Jain and Karthik Nandakumar propose BIND, a framework that binds a human's biometric to an AI agent's identity and a task specific authority scope at the moment authority is delegated, producing a delegation token an Identity Auditor can later use to recover who authorized what. arXiv lists the paper, submitted 4 August 2026, as accepted for an IJCB 2026 session. Their face biometric prototype reports 96 percent True Match Rate at zero False Match Rate in the paper's own experimental setting, with 1024 bit agent tokens. This is a research proposal and a prototype evaluation, not a deployed system, and no independently reproduced or publicly available implementation was found.

Research & Architecture18 min read
22 August 2026

The Agent Does Not Get the Permission Until It Tries to Act.

Rubrik unveiled Agent Identity at Black Hat USA on 4 August 2026, describing it as available within Rubrik Agent Cloud. Rubrik's own material states that every supported MCP tool call clears three checkpoints before it runs: a semantic intent check by Rubrik's SAGE engine, an infrastructure level access decision by Rubrik's MCP Gateway enriched with that intent context, and only then a scoped, short lived token minted for that one call. Rubrik federates the acting identity with Okta and Microsoft Entra ID so the token is issued on behalf of a specific human rather than a shared service account. Moona Intelligence reads what Rubrik documents precisely, narrows what its own material does not establish, and separates this from Rubrik's own Agent Rewind, a different product answering a different question.

Agent Authority8 min read
22 August 2026

You Can Approve Every Trade. Or You Can Delegate the Subaccount in Advance.

Binance introduced Agent OS on 20 August 2026 as a developer platform linking compatible AI applications, including ChatGPT, Codex, Claude Code and Cursor, to Binance trading, market data, wallet, payment and onchain capabilities, gated by user configured permissions. TechCrunch's reporting, built on an interview with Binance VP of Product Jeff Li, describes the primary constraint as a dedicated subaccount with withdrawals blocked by default, and quotes Binance describing a genuine choice between per order approval and autonomous execution once permissions are configured. Binance's own MCP Server documentation, modified the next day, describes something narrower: every order, cancellation and transfer inside that subaccount confirmed by the user before it executes, with no autonomous mode documented alongside it. Moona Intelligence reads this against what a human can delegate in advance, where that delegated envelope actually ends, and what is vendor statement rather than documented enforcement. Updated 23 August 2026 with the MCP Server's own confirmation requirement, the subaccount's empty starting balance, the absence of a withdrawal scope, an itemized revocation path and a direct comparison against Robinhood's bounded autonomous execution, on top of the 22 August Authority Provenance ledger verifying who is documented as entitled to grant an agent trading authority. Updated again 25 August 2026 after Moona Intelligence's radar flagged further Binance explanatory material on the same permission and approval model. That specific material could not be independently reached in this environment. This update instead adds a second, independent secondary account of the confirm before execute pattern, and records plainly that the underlying findings, and their open questions, are otherwise unchanged.

Agent Authority28 min read
21 August 2026

The Agent Has an Identity. So Does the Person Behind It. GitLab Requires Both.

GitLab 19.3, dated 20 August 2026, is being covered as the release where GitLab scaled agentic AI across trusted delivery workflows. Read against GitLab's own documentation, the more precise finding is narrower and more interesting. Composite identity, the mechanism that authorizes a Duo Agent Platform action only when both a service account and the human who triggered it have access, was introduced in GitLab 18.3 a year earlier, made generally available in 18.8, and automatic since 18.9. What 19.3 actually did was remove the last feature flag around it and add an explicit audit field naming the human who authorized a service account's action, on a mechanism that GitLab's own documentation says does not apply to every agent surface it ships. Updated 27 August 2026: GitLab's patch releases 19.3.1, 19.2.5 and 19.1.7, dated 26 August 2026, fix CVE-2026-18252, in which an authenticated Developer role user could, under certain conditions, cause the Duo Claude agent to execute arbitrary commands in a CI context after it processed configuration from a user-controlled source. This record adds a dedicated Authority Provenance ledger for that vulnerability. It does not describe composite identity itself as bypassed; GitLab's advisory does not say that, and the failure it does describe sits downstream of the identity mechanism this record verifies above.

Agent Authority17 min read
21 August 2026

People Are Already Giving AI Authority. Who Decides Where It Stops?

EY's 2026 Global AI Sentiment Study finds that 16% of 18,152 people surveyed across 23 markets used AI systems that acted on their behalf without human intervention in the previous six months, including 10% who used an AI agent to buy something and 11% who let AI manage banking tasks unattended. Moona Intelligence reads that as evidence that decision making authority is already moving from people to systems, before almost anyone has defined where that authority stops.

Agent Authority10 min read
21 August 2026

Singapore Listed Ten Ways to Control an Agent. Human Approval Is Only One of Them.

The Singapore AI Safety Institute published a Companion Report on Agentic Risk Management alongside the 2026 Singapore Consensus on Global AI Safety Research Priorities in July 2026. It sets out ten foundational principles across the agentic lifecycle: least privilege, traceable identity and auditability in design and development; validated deployment, adversarial resilience and multi agent stability in testing and deployment; runtime assurance, interruptibility, legibility and human oversight in operation and monitoring. The interesting structural fact is not that human oversight appears. It is that it appears once, in the last group, next to a separate principle covering the ability to stop the agent. Approving an action and being able to halt one are being treated as different controls held by different parts of the system.

Governance & Policy9 min read
21 August 2026

Slack Put the Approval Where the Conversation Is. It Did Not Put the Enforcement There.

On 20 August 2026 Slack, a Salesforce company, launched Slack Code: a new channel type that partner coding agents create through a Slack API, carrying a plan, a repository and branch, code diffs and a live preview. Slack documents that anyone in the channel can pause, redirect or stop an agent mid task, that agents inherit Slack's permissions and admin controls so no new identities are provisioned, and that the channel archives itself into an audit log when the task ends. Slack also says that for high stakes moves, like pushing code to production, the agent packages its work for an expert to sign off on, right in the channel. That is a description of a workflow, not of an enforcement mechanism. Slack states plainly that Slack Code is not a coding model, a harness or an agent runtime, which means the code does not execute in Slack and neither does the deployment. Nothing published establishes who counts as an expert, whether a sign off binds to a specific diff, commit or deployment, whether an agent can proceed without one, or what downstream system enforces the decision. Moona Intelligence reads the launch as the approval moment moving onto a general purpose chat surface while the enforcement point stays somewhere Slack does not document.

Agent Authority10 min read
21 August 2026

TrueFoundry Put the Approval Decision Where an Agent Builder Cannot Skip It

On 19 August 2026, TrueFoundry published TrueForge, an open source, MIT licensed agent runtime available on GitHub and npm, describing it as the harness the company runs in production. Separately, on 13 August 2026, TrueFoundry published an architecture writeup called The Human Gate, describing how its commercial MCP Gateway holds a matched tool call at the network boundary, returns a pending result rather than an error, and releases execution once a human approves or lets the request lapse on denial. Those are two different things carrying the same word. TrueForge's own tool approval checkpoint is configured inside each agent build. The MCP Gateway's approval policy is documented as sitting in front of the tool call itself, independent of which harness or client issued it, which is the structural difference between an approval a builder can forget to add and one a shared boundary enforces regardless.

Agent Authority6 min read
20 August 2026

Watching the Agent Is Not the Same as Stopping It

Guidelight AI Standards, an independent nonprofit founded by two former OpenAI safety staff, published its first assessment of frontier AI developers against its Control standard in August 2026. Anthropic and OpenAI led with a C+. Google scored a D+, xAI a D minus, and Meta an F. No company fully implemented any of the six practices Guidelight checked. The grades are getting the attention. The more durable part of Guidelight's standard is a line it draws inside the word control itself: monitoring an AI system after it acts is not the same as being able to stop it before it acts, and for a defined category of actions, Guidelight says only the second one counts.

Agent Authority7 min read
17 August 2026

The Agent Did Not Make the Payment Alone. It Passed Your Authority Down a Chain.

Alipay announced a full stack agentic commerce platform and the AHA cross agent protocol system at its AI Ecosystem Partner Conference in Hangzhou on 17 August 2026, with more than 20 device makers, automakers and model companies joining an interconnection plan. Alipay's own documentation reports 300 million agent payments and 100 million users across 12 commercial scenarios, and describes several distinct authorization modes. Moona Intelligence reads the launch as an authorization propagation problem: when one instruction crosses several agents before producing a real payment, connectivity between those agents is not the same thing as inherited authority. Updated 23 August 2026 with newly surfaced evidence from Uber Engineering, published 21 May 2026, describing a production actor chain architecture that carries a human user's identity and every intermediate agent's identity through a chain of short lived tokens, verified against a strict Authority Provenance ledger. Updated again 24 August 2026 with the AI AGENT Act, introduced in the Senate as S.5051 on 21 July 2026 and now referred to the Committee on Commerce, Science, and Transportation, and with Aashis Luitel's 13 August 2026 analysis in The Conversation of a cross system evidence gap: an agent provider, a merchant and a payment provider can each hold an individually accurate record of one transaction while none of them, alone, can show the user authorized that specific action as part of that specific task. Updated again 26 August 2026 with this desk's own independent verification of S.5051: the bill's own official short description at Congress.gov, the precise scope of the redelegation restriction, the duties a permitted downstream delegate keeps, the FTC's registration process and its authority to set specialized terms for particular commercial settings, what a large online platform may do on its own side of a revocation, and the exact capabilities the bill directs NIST to identify or build standards for, with introduction date, sponsor and committee status confirmed unchanged as of 26 August 2026. Updated again 29 August 2026 with the Payment & Clearing Association of China's Self-Regulatory Convention on Agent Payment Applications, issued 24 August 2026 under People's Bank of China guidance: an industry self-regulatory instrument, not a statute or a PBOC regulation, that asks member institutions to sort out an authorization boundary between a user and an agent payment application, sign clear authorization agreements, verify transaction intent, protect a user's right to revoke, cap standing authority through transaction limits, and explore both a Know Your Agent mechanism built on top of KYC and a trusted evidence mechanism spanning user authorization, model decision, payment instruction and risk control, read against the same distinctions between authentication, agent identity, authorization and intent this record has kept separate throughout, and against PBOC Vice Governor Lu Lei's 27 August 2026 public call for market participants to actively implement it.

Agent Authority55 min read
17 August 2026

The Code Needed a Human Approval. GitHub Let the Agent Give It.

In v0.87.0 of github/gh-aw, marked pre release, an experimental safe output named approve-workflow-run lets an agent ask for a blocked fork pull request workflow run to be approved, with deterministic eligibility checks in front of the GitHub API call. This is not default GitHub Actions behaviour and it is not enabled unless a repository opts in. What changed conceptually is that the approval step itself, the thing a maintainer used to perform by clicking Approve and run, is now an operation software can perform.

Agent Authority9 min read
17 August 2026

The Agent Paid. Now Prove That Payment Was Authorized.

AWS and Solv Labs describe a governed agent payments workflow on Amazon Bedrock AgentCore payments in which a proposed transaction is evaluated against policy before it can settle, and each governed payment carries a signed record of that evaluation. AWS and Solv Labs are explicit about what the record does not prove. Moona Intelligence reads what is left: whether evidence for a consequential financial action can be produced at the same boundary where it is authorized, not reconstructed afterward.

Agent Authority36 min read
16 August 2026

When the Model Is Allowed to Think About the Exploit, Who Authorizes the Action?

OpenAI expanded its Daybreak cybersecurity program on August 10, 2026 into Daybreak Blue and Daybreak Red, and introduced GPT-5.6-Cyber, a model OpenAI says is purpose trained for advanced cybersecurity work and designed to reduce refusals for certain higher risk dual use tasks. In the same announcement, OpenAI says it is strongly encouraging Daybreak customers who use Codex to move from full access mode to auto review mode, which evaluates actions that need elevated permissions before they execute and can block requests that pose a significant risk of destructive behavior. Moona Intelligence reads the two decisions together: OpenAI lowered a model level refusal for trusted defenders and, in the same breath, pushed harder on an independent, execution level check that does not depend on the model refusing anything at all. Updated August 26, 2026 with BreachLock's Breach360, an autonomous penetration testing product whose own documentation asks for a fresh, explicit human approval specifically when the agent discovers a path that could mean lateral movement or privilege escalation, on top of the reconnaissance, enumeration and exploitation the engagement already authorizes it to run without asking again.

Agent Authority25 min read
16 August 2026

The Agent Created Another Agent. Which Permissions Came With It?

Anthropic's changelog says subagent forking is on by default and that a fork inherits the full conversation and prompt cache. The subagent documentation says a fork sees the same system prompt, tools, model and message history, and that a subagent inherits the main conversation's permission mode when its own is unset. Moona Intelligence reads this as a distinct governance question we call Authority Inheritance: when one agent creates another, which parts of the first agent's authority should automatically survive that handoff? Updated 23 August 2026 with newly surfaced evidence about Grantex, a specification frozen in February 2026 and a related Internet Draft submitted to the IETF in March 2026, which answers the same question with an opposite default: bounded, attenuating delegation rather than full inheritance. Updated again 27 August 2026 with a second individual Internet-Draft, draft-asor-wimse-agent-delegation-chain-00, targeting the WIMSE working group and authored by Rafael Asor of Attenu, whose contribution is narrower and different from Grantex's: an offline, enforcement-point-verifiable way for the resource receiving a delegated agent's final action to cryptographically confirm that authority narrowed at every hop of the chain, without proving who was entitled to grant the root authority in the first place.

Agent Authority36 min read
15 August 2026

Every Action Was Allowed. The Sequence Was Not.

AWS says traditional access controls treated each action as an independent event, and that agents break that assumption because they decide at runtime which tools to call, with which arguments, and in what order. Temporal policies evaluate the current AgentCore Gateway request against prior events in the agent's trajectory. Moona Intelligence reads this as evidence of a distinct problem: whether a consequential action is authorized can depend on the actions that preceded it. Updated 19 August 2026 with an arXiv preprint, Bounded Agents, that formalizes prohibited combinations of individually permitted actions and evaluates a session level authorization model across 3,154 benchmark instances, along with its limitations and its measured cost to task completion. Updated again on 20 August 2026, when AWS published how a written policy document becomes the formal policy the runtime enforces, and said plainly that validation cannot confirm the policy says what its author meant. Updated again on 23 August 2026 after reading the Bounded Agents paper's LaTeX source and its reference implementation's Python source directly, rather than the summaries: what the composition, budget, approval and evidence mechanisms actually do, and a provenance reading of what the Agentic Principal Chain can and cannot establish about who was entitled to grant authority in the first place.

Agent Authority28 min read
15 August 2026

The AI Agent Was Allowed to Submit the Decision. AWS Says That Does Not Mean It Should.

On August 14, 2026, AWS published a HIPAA focused reference architecture for AI agents in healthcare, illustrated with a lumbar MRI prior authorization workflow. AWS states that role based access control establishing an agent can call a submission tool does not establish that the agent should autonomously execute the consequential decision behind it. Its governed design adds a separate control, Consequential Action Approval, that pauses high risk writes for explicit human confirmation. AWS is careful to say the architecture does not create new compliance requirements. Moona Intelligence reads it as a clear statement of a distinction that outlasts this one AWS post: permission to reach an action and authority to take it are not the same question.

Agent Authority11 min read
14 August 2026

You Authorized the Goal at 9 AM. What Is the Agent Allowed to Do Until 5 PM?

WRITER announced Palmyra X6 on 13 August 2026 and says it can hold a single objective for up to eight hours without supervision, planning, executing, verifying its own output and correcting its work. WRITER Agent batches tasks, delegates to sub agents, calls MCP tools and connectors, and recovers from errors with fewer interruptions. Every one of those is a real improvement. Together they also mean that one authorization at the start of the day can sit behind a very long sequence of decisions nobody sees until the work comes back.

Agent Authority11 min read
14 August 2026

The AI Security Agent Found the Problem. Now It Has Authority to Fix It.

IBM and OpenAI announced an expanded cybersecurity partnership on August 13, 2026. IBM describes its Autonomous Defense Agents as providing automated policy enforcement and rapid remediation across IT and security tools, and its Autonomous Threat Operations Machine as orchestrating multiple AI agents and executing remediation at machine speed. When a security agent can take that kind of action, the transition from detection to remediation is also a transition in authority. The question is what governs what the agent is permitted to do at the moment it decides to change something in a live environment. Updated 27 August 2026 with Mate Security's Gamebooks, an independently built architecture that separates an organization's investigative mandate from the path an AI agent chooses and from the execution layer that reaches a real system. Updated the same day with Visa's Vulnerability Agentic Harness (VVAH), a shipped, open-source implementation that predates the day's corporate announcement by two months. Verified directly against the repository's current main: the shipped default profile runs remediation and validation automatically after every scan, the remediation stage can write a candidate fix into the target's actual working tree using only Read/Glob/Grep/Edit/Write with Bash denied on every shipped profile, and no commit, push or merge call exists anywhere in the codebase. A second, read-only panel scores the candidate without touching the target. Visa's own account, corroborated by VentureBeat, places human review before the tool runs, on the specific patch, and again before anything merges. That is evidence that mutation authority and adoption authority are separate transitions, not one boundary.

Agent Authority19 min read
14 August 2026

Your AI Agent's Permissions Did Not Change. Its Authority Still Did.

Google announced Gemini 3.7 Flash on 13 August 2026 and said Gemini Spark would start using it the same day. Google describes better multi step planning, better tool calls, better recovery from roadblocks, fewer retries and less manual oversight. Spark's permission surface, the connected apps, the local and remote browser, the confirmation prompts, is unchanged. That is the part worth thinking about. Effective authority can move without a single permission being edited.

Agent Authority22 min read
14 August 2026

Claude Code Just Automated the Decision to Ask You for Permission

Anthropic has made auto mode the default permission mode for new Claude Code sessions on Pro, Max and Team plans, starting 14 August 2026. Auto mode is not unrestricted execution: a separate classifier reviews each tool call, deny and explicit ask rules still fire first, and repeated blocks fall back to manual prompts. The interesting shift is architectural. The decision about when a human is needed has moved up a layer. Updated 26 August 2026: Anthropic says Claude in Chrome, generally available on every paid plan, now decides the same question for actions Claude takes inside a browser, through websites a person is already logged into. The classifier moved from a terminal to a browser tab. What it is actually deciding, and what it cannot decide, did not move with it. Updated 28 August 2026: Claude Code v2.1.248 adds a --restricted launch mode that removes the built-in tools that run commands or code and WebFetch by default, confines file tools to the working directory, refuses bypassPermissions, and loads only managed settings, leaving project, local and user settings files unread. Where auto mode decides whether an available action may proceed, restricted mode decides which actions are available to the session at all, and this record reads what Anthropic's own current documentation does and does not establish about that difference. Updated 29 August 2026: v2.1.251 narrows the gap between a permission decision and the resource it actually reaches, fixing a symlink that could be swapped after a file tool's permission check, a matching gap in Grep and Glob's deny rules, a Workflow tool script path read before its own permission check, and consolidating Claude in Chrome onto Claude Code's own permission checks, while server managed settings that weaken the sandbox boundary now require the developer's approval before they apply.

Agent Authority35 min read
13 August 2026

AI Agents Are Getting Flight Recorders. That Tells You Where the Real Problem Is.

The Open Secure AI Alliance published a request for comments on SAFE, a proposed framework for reporting AI agent security incidents. The proposal would require preserving prompts, agent traces, tool calls, identities, permissions, and credentials. That is not a server log. It is the beginning of a theory of agent accountability.

Governance & Policy10 min read
13 August 2026

Robinhood Didn't Just Add a Chatbot. It Authorized Software to Move Your Money.

On 27 May 2026 Robinhood opened Agentic Trading and the Agentic Credit Card to third-party AI agents, letting a connected agent place real trades and real purchases inside a customer's account. The safeguards Robinhood built are real. The harder question is what execution-time control means once software, not a person, decides whether an action actually runs.

Agent Authority9 min read

Where to go next

All topics →