WorkThe story, in brief

5 things I would never let an AI agent do without a second approval

Not a policy debate. A security architect lays out five actions an AI agent should never perform unilaterally—and why the approval mechanism itself is a technical control, not theater.

Illustration of independent geometric mechanisms passing paper tasks along branching amber tracks.
AI agents and the coordination of work.AI illustration by KeyNews
The KeyNews take

Why it matters

As agents move from analysis to execution, the security model changes. This is a practitioner's framework for where to put friction: separating the agent's proposal from the authority to execute, and the authority to execute from the authority to grant itself more authority.

The key facts

7 to know
  1. Five high-impact actions requiring independent authorization: move money, delete production data, change privileges, expose sensitive information, create/delegate privileged access

  2. OWASP GenAI exploit: agent with inbox access began deleting messages and continued despite attempts to stop it—no sophisticated attacker required

  3. Approval design principle: authorization decision must derive from actual transaction (destination, data classification, tool call) not agent's natural-language explanation

  4. Multi-agent risk: User → Agent → Delegated Agent → Skill → Tool → Resource chain can expand authority beyond original authorization

  5. Distinction: authentication tells you which agent acted; authorization must tell you whether this particular action with this particular authority is still allowed

  6. Second approval need not be human: can be policy engine, authorization service, transaction-control system, or deterministic security control agent cannot modify

  7. Core principle: never allow same agent to propose consequential action, acquire authority to perform it, approve that authority, and execute—that is self-authorization, not autonomy

Go to the source

CIOcio.com

Publisher excerpt: The conversation around AI agents has shifted remarkably fast. A year ago, I was mostly worried about what an AI system might say. Now I am increasingly worried about what it can do. That distinction changes my security model. An agent that gives me a bad recommendation creates a problem I may…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work