The model can request an action. The authorization system decides.
Prompt injection is not a bug you patch in the prompt. It is the reason agent actions must be authorized outside the model.
Read moreResearch
Original analysis of how machine identities, credentials, access and AI agents fail — and the models that make them governable. Every position shows its working.
All research
2 papers, newest first.
Prompt injection is not a bug you patch in the prompt. It is the reason agent actions must be authorized outside the model.
Read moreA conceptual framework for scoring machine-identity risk that a human can audit — and why a score without evidence is worse than no score.
Read moreStart here
Primers and reference pages that define the vocabulary, the relationship model and the frameworks the research papers assume.