• About
  • Privacy Poilicy
  • Disclaimer
  • Contact
CoinInsight
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining
No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining
No Result
View All Result
CoinInsight
No Result
View All Result
Home Regulation

When Two Authorized Agents Do Something No One Approved

Coininsight by Coininsight
September 17, 2026
in Regulation
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


by Rehan Kausar

Photo courtesy of the author

Photo courtesy of the author

In a multi-agent enterprise, the approval trail can be complete and correct — and still show that no one approved the outcome.

A bank deploys two AI agents. The first is authorized to analyze a customer relationship and recommend a retention offer. The second is authorized to amend certain account terms when it receives an approved business instruction. Both were risk-assessed. Both were approved by name in a governance forum. Both operate strictly inside the permissions they were granted.

The first agent concludes that a fee waiver is the right retention action and passes that conclusion downstream. The second treats that recommendation as satisfying its “approved business instruction” condition — because nothing in its permission set defines what makes an instruction approved, or who must have approved it — and executes.

Nothing was breached. No credential was stolen. Neither agent exceeded its permissions. And yet no one with authority to change that customer’s economic terms ever approved doing so.

A waived fee is a small thing. Now hold the same structure and change the action. A payment released. A credit decision issued. A customer’s rights altered. A representation made to a regulator. Nothing about the mechanism changes — only the size of what the institution has done without deciding to do it.

I have come to think of this as the compositional authority gap: the space between what each agent is permitted to do and what those agents, acting in sequence, can cause the enterprise to do. It is not a security failure. It is an authority failure, and the two are governed by different disciplines.

Compliance programs are built on the premise that documentation protects the institution. When something goes wrong, the firm produces the risk assessment, the approval minutes, the access reviews, and the audit log, and those artifacts demonstrate that the decision was made by someone entitled to make it.

Composition inverts that premise. The record is complete. Agent A’s authority is documented. Agent B’s authority is documented. Every API call is legitimate and logged. What the record establishes, with unusual clarity, is that the outcome the customer experienced was never the subject of an authorization decision by anyone with the standing to make it.

That is an uncomfortable evidentiary position. The institution has not lost the trail. It has a perfect trail to a gap.

Corporate authority doctrine assumes a human agent. A principal is bound by acts within actual or apparent authority;[1] where an employee acts outside it, the firm has arguments available to it — the act was unauthorized, it fell outside the scope of employment,[2] the counterparty could not reasonably have believed otherwise. Those arguments distribute responsibility between the institution and an individual who departed from instructions.

An AI agent offers no such distribution. It is not a legal person. It holds no authority of its own that it could exceed. It has no intent to disclaim and no employment to fall outside of. Whatever it does may ultimately be attributable to the enterprise — through a system the enterprise designed, permissioned, and deployed.

So the familiar defense becomes much harder to make. There may be no independent human actor to whom the unauthorized act can readily be attributed. Composition does not create a rogue agent. It creates an institutional act that no accountable human authorized — attributable to the enterprise, traceable to no one inside it.

Financial institutions already understand the underlying principle. One employee creates the vendor record. Another approves the invoice. A third releases payment. The separation exists because concentrating those authorities in one person creates a risk the institution has decided not to accept.

Now assign each task to a narrowly permissioned agent. Each passes its access review. Each satisfies least privilege. And an orchestrator — itself often modest in its permissions — coordinates all three toward a single objective.

Every local control holds. The global control does not. The institution can be simultaneously compliant at the level of each component and non-compliant at the level of the transaction, and standard control testing will not detect it, because standard control testing examines components.

The implication reaches internal control over financial reporting[3] and any framework built on separation of duties. A segregation control enforced per identity may not be enforced at all once identities can invoke, delegate to, or route work through one another — or through an orchestrator that holds no consequential permissions of its own.

There is a second exposure here, and it arrives quietly. Where an act is performed without authority, a principal that learns of it and knowingly accepts or retains its benefits may, depending on the circumstances, be treated as having ratified the act.[4]

Multi-agent systems will produce composed outcomes at volume. Most will be benign or beneficial. If an institution discovers that its agents are routinely producing outcomes no one authorized, and continues to accept the results because they are commercially useful, it may find that it has ratified the arrangement as a matter of practice — and with it, the authority structure that produced it.

The moment of discovery therefore carries obligations. An institution that identifies a compositional gap and does nothing has made a decision, whether or not anyone recorded it as one.

Conventional authorization asks a question about an actor: is this agent permitted to perform this action?

A multi-agent enterprise needs to ask a question about an outcome: should this institution permit this result to occur? Answering it means looking at what produced the proposed action. Who set the objective. Which agents took part. What authority passed between them. What the cumulative impact now is.

I would call the second question outcome admissibility. It is a governance test, not the evidentiary one that term usually signals, and it belongs before execution rather than after. The distinction matters because retrospective assurance, however rigorous, can only ever establish how the wrong thing happened. For consequential and irreversible actions — moving money, altering customer rights, making regulated representations — that is not a control. It is a reconstruction.

This is not an argument for human approval of every agent action; that would eliminate most of the value of autonomy and, worse, would produce the kind of ceremonial oversight that looks like a control and functions as an exposure. The principle is narrower: autonomy may scale with capability, but execution authority should scale with consequence.

In practice that means a gate the proposed action must pass before it executes — one that evaluates the combined permissions actually in play, the authority that passed between agents, and the cumulative impact, and routes anything above a consequence threshold to an independent control or a human.

Directors do not need to understand orchestration frameworks or agent protocols. They do need to understand concentration of autonomous authority. Delaware’s oversight jurisprudence provides a useful analogue: where a risk is mission-critical to the enterprise, boards are expected to ensure that appropriate reporting and monitoring systems exist.[5]

Five questions are enough to establish whether an institution has multi-agent governance or merely agent controls:

Can our agents invoke, delegate to, or route work through one another, or through an orchestrator?

Can individually permitted capabilities combine into a materially more powerful workflow?

Which business outcomes can now occur without any new authorization decision?

Where are segregation-of-duties boundaries enforced across autonomous workflows, rather than within individual agents?

Can we reconstruct not only what happened, but why the combined action was considered permissible before it executed?

An institution that cannot answer the fifth question has logging. It does not yet have governance.

The enterprise AI conversation has moved from models to data to responsible AI to agent identity and permissions. The next boundary is interaction. The question is no longer whether each agent is trustworthy. It is whether the system they form together stays inside what the institution intended.

Which leaves a question worth putting to management now, while the answer is still architectural rather than forensic:

If every agent involved was individually authorized, and the combined outcome was never approved, who authorized the enterprise to act?

That gap should be closed deliberately, before autonomous systems begin closing it on their own terms.

[1] Restatement (Third) of Agency, Sections 2.01 and 2.03 (Am. Law Inst. 2006) (actual and apparent authority).

[2] Restatement (Third) of Agency, Section 7.07 (Am. Law Inst. 2006) (respondeat superior; scope of employment).

[3] Sarbanes-Oxley Act of 2002, Section 404, 15 U.S.C. 7262; SEC Rule 13a-15, 17 C.F.R. 240.13a-15.

[4] Restatement (Third) of Agency, Sections 4.01 and 4.06 (Am. Law Inst. 2006) (ratification; knowledge of material facts).

[5] In re Caremark Int’l Inc. Derivative Litig., 698 A.2d 959 (Del. Ch. 1996); Stone v. Ritter, 911 A.2d 362 (Del. 2006); Marchand v. Barnhill, 212 A.3d 805 (Del. 2019).

Rehan Kausar is Chief AI Officer at AI Advantages.

The views, opinions and positions expressed within all posts are those of the author alone and do not represent those of the Program on Corporate Compliance and Enforcement (PCCE) or of the New York University School of Law. PCCE makes no representations as to the accuracy, completeness and validity or any statements made on this site and will not be liable any errors, omissions or representations. The copyright of this content belongs to the author and any liability with regards to infringement of intellectual property rights remains with the author.

Related articles

What’s new in Astute, September 2026 update (v3.6)

September 17, 2026

The First Rung Matters More Than the Ladder

September 15, 2026


by Rehan Kausar

Photo courtesy of the author

Photo courtesy of the author

In a multi-agent enterprise, the approval trail can be complete and correct — and still show that no one approved the outcome.

A bank deploys two AI agents. The first is authorized to analyze a customer relationship and recommend a retention offer. The second is authorized to amend certain account terms when it receives an approved business instruction. Both were risk-assessed. Both were approved by name in a governance forum. Both operate strictly inside the permissions they were granted.

The first agent concludes that a fee waiver is the right retention action and passes that conclusion downstream. The second treats that recommendation as satisfying its “approved business instruction” condition — because nothing in its permission set defines what makes an instruction approved, or who must have approved it — and executes.

Nothing was breached. No credential was stolen. Neither agent exceeded its permissions. And yet no one with authority to change that customer’s economic terms ever approved doing so.

A waived fee is a small thing. Now hold the same structure and change the action. A payment released. A credit decision issued. A customer’s rights altered. A representation made to a regulator. Nothing about the mechanism changes — only the size of what the institution has done without deciding to do it.

I have come to think of this as the compositional authority gap: the space between what each agent is permitted to do and what those agents, acting in sequence, can cause the enterprise to do. It is not a security failure. It is an authority failure, and the two are governed by different disciplines.

Compliance programs are built on the premise that documentation protects the institution. When something goes wrong, the firm produces the risk assessment, the approval minutes, the access reviews, and the audit log, and those artifacts demonstrate that the decision was made by someone entitled to make it.

Composition inverts that premise. The record is complete. Agent A’s authority is documented. Agent B’s authority is documented. Every API call is legitimate and logged. What the record establishes, with unusual clarity, is that the outcome the customer experienced was never the subject of an authorization decision by anyone with the standing to make it.

That is an uncomfortable evidentiary position. The institution has not lost the trail. It has a perfect trail to a gap.

Corporate authority doctrine assumes a human agent. A principal is bound by acts within actual or apparent authority;[1] where an employee acts outside it, the firm has arguments available to it — the act was unauthorized, it fell outside the scope of employment,[2] the counterparty could not reasonably have believed otherwise. Those arguments distribute responsibility between the institution and an individual who departed from instructions.

An AI agent offers no such distribution. It is not a legal person. It holds no authority of its own that it could exceed. It has no intent to disclaim and no employment to fall outside of. Whatever it does may ultimately be attributable to the enterprise — through a system the enterprise designed, permissioned, and deployed.

So the familiar defense becomes much harder to make. There may be no independent human actor to whom the unauthorized act can readily be attributed. Composition does not create a rogue agent. It creates an institutional act that no accountable human authorized — attributable to the enterprise, traceable to no one inside it.

Financial institutions already understand the underlying principle. One employee creates the vendor record. Another approves the invoice. A third releases payment. The separation exists because concentrating those authorities in one person creates a risk the institution has decided not to accept.

Now assign each task to a narrowly permissioned agent. Each passes its access review. Each satisfies least privilege. And an orchestrator — itself often modest in its permissions — coordinates all three toward a single objective.

Every local control holds. The global control does not. The institution can be simultaneously compliant at the level of each component and non-compliant at the level of the transaction, and standard control testing will not detect it, because standard control testing examines components.

The implication reaches internal control over financial reporting[3] and any framework built on separation of duties. A segregation control enforced per identity may not be enforced at all once identities can invoke, delegate to, or route work through one another — or through an orchestrator that holds no consequential permissions of its own.

There is a second exposure here, and it arrives quietly. Where an act is performed without authority, a principal that learns of it and knowingly accepts or retains its benefits may, depending on the circumstances, be treated as having ratified the act.[4]

Multi-agent systems will produce composed outcomes at volume. Most will be benign or beneficial. If an institution discovers that its agents are routinely producing outcomes no one authorized, and continues to accept the results because they are commercially useful, it may find that it has ratified the arrangement as a matter of practice — and with it, the authority structure that produced it.

The moment of discovery therefore carries obligations. An institution that identifies a compositional gap and does nothing has made a decision, whether or not anyone recorded it as one.

Conventional authorization asks a question about an actor: is this agent permitted to perform this action?

A multi-agent enterprise needs to ask a question about an outcome: should this institution permit this result to occur? Answering it means looking at what produced the proposed action. Who set the objective. Which agents took part. What authority passed between them. What the cumulative impact now is.

I would call the second question outcome admissibility. It is a governance test, not the evidentiary one that term usually signals, and it belongs before execution rather than after. The distinction matters because retrospective assurance, however rigorous, can only ever establish how the wrong thing happened. For consequential and irreversible actions — moving money, altering customer rights, making regulated representations — that is not a control. It is a reconstruction.

This is not an argument for human approval of every agent action; that would eliminate most of the value of autonomy and, worse, would produce the kind of ceremonial oversight that looks like a control and functions as an exposure. The principle is narrower: autonomy may scale with capability, but execution authority should scale with consequence.

In practice that means a gate the proposed action must pass before it executes — one that evaluates the combined permissions actually in play, the authority that passed between agents, and the cumulative impact, and routes anything above a consequence threshold to an independent control or a human.

Directors do not need to understand orchestration frameworks or agent protocols. They do need to understand concentration of autonomous authority. Delaware’s oversight jurisprudence provides a useful analogue: where a risk is mission-critical to the enterprise, boards are expected to ensure that appropriate reporting and monitoring systems exist.[5]

Five questions are enough to establish whether an institution has multi-agent governance or merely agent controls:

Can our agents invoke, delegate to, or route work through one another, or through an orchestrator?

Can individually permitted capabilities combine into a materially more powerful workflow?

Which business outcomes can now occur without any new authorization decision?

Where are segregation-of-duties boundaries enforced across autonomous workflows, rather than within individual agents?

Can we reconstruct not only what happened, but why the combined action was considered permissible before it executed?

An institution that cannot answer the fifth question has logging. It does not yet have governance.

The enterprise AI conversation has moved from models to data to responsible AI to agent identity and permissions. The next boundary is interaction. The question is no longer whether each agent is trustworthy. It is whether the system they form together stays inside what the institution intended.

Which leaves a question worth putting to management now, while the answer is still architectural rather than forensic:

If every agent involved was individually authorized, and the combined outcome was never approved, who authorized the enterprise to act?

That gap should be closed deliberately, before autonomous systems begin closing it on their own terms.

[1] Restatement (Third) of Agency, Sections 2.01 and 2.03 (Am. Law Inst. 2006) (actual and apparent authority).

[2] Restatement (Third) of Agency, Section 7.07 (Am. Law Inst. 2006) (respondeat superior; scope of employment).

[3] Sarbanes-Oxley Act of 2002, Section 404, 15 U.S.C. 7262; SEC Rule 13a-15, 17 C.F.R. 240.13a-15.

[4] Restatement (Third) of Agency, Sections 4.01 and 4.06 (Am. Law Inst. 2006) (ratification; knowledge of material facts).

[5] In re Caremark Int’l Inc. Derivative Litig., 698 A.2d 959 (Del. Ch. 1996); Stone v. Ritter, 911 A.2d 362 (Del. 2006); Marchand v. Barnhill, 212 A.3d 805 (Del. 2019).

Rehan Kausar is Chief AI Officer at AI Advantages.

The views, opinions and positions expressed within all posts are those of the author alone and do not represent those of the Program on Corporate Compliance and Enforcement (PCCE) or of the New York University School of Law. PCCE makes no representations as to the accuracy, completeness and validity or any statements made on this site and will not be liable any errors, omissions or representations. The copyright of this content belongs to the author and any liability with regards to infringement of intellectual property rights remains with the author.

Share76Tweet47

Related Posts

What’s new in Astute, September 2026 update (v3.6)

by Coininsight
September 17, 2026
0

Product updates now arrive inside Astute on a new News page. You can also set a Leave Date on a...

The First Rung Matters More Than the Ladder

by Coininsight
September 15, 2026
0

AI productivity gains are concrete and all signs point to this rising as the technology grows. But José Alberro of...

DOJ Announces Second DEI-Related False Claims Act Settlement

by Coininsight
September 14, 2026
0

by Debo Adegbile, Brenda Lee, Tania Faransso, and Kevin Lamb From left to right: Debo Adegbile, Brenda Lee, Tania Faransso and...

Third-party harassment: what employers need to know before 30 October

by Coininsight
September 13, 2026
0

The 30 October 2026 harassment reforms under the Employment Rights Act reforms have largely been discussed in terms of the...

Why Harassment Training Requires Reinforcement

by Coininsight
September 13, 2026
0

Every day, employees notice which comments are challenged, which concerns are dismissed and what behavior appears to be accepted. Those...

Load More
  • Trending
  • Comments
  • Latest
What’s Actually Going On With Ripple’s Blockchain?

What’s Actually Going On With Ripple’s Blockchain?

January 12, 2026
MetaMask Launches An NFT Reward Program – Right here’s Extra Data..

MetaMask Launches An NFT Reward Program – Right here’s Extra Data..

July 24, 2025
Finest Bitaxe Gamma 601 Overclock Settings & Tuning Information

Finest Bitaxe Gamma 601 Overclock Settings & Tuning Information

November 26, 2025
Easy methods to Host a Storj Node – Setup, Earnings & Experiences

Easy methods to Host a Storj Node – Setup, Earnings & Experiences

March 11, 2025
Kuwait bans Bitcoin mining over power issues and authorized violations

Kuwait bans Bitcoin mining over power issues and authorized violations

2
The Ethereum Basis’s Imaginative and prescient | Ethereum Basis Weblog

The Ethereum Basis’s Imaginative and prescient | Ethereum Basis Weblog

2
Unchained Launches Multi-Million Greenback Bitcoin Legacy Mission

Unchained Launches Multi-Million Greenback Bitcoin Legacy Mission

1
Earnings Preview: Microsoft anticipated to report larger Q3 income, revenue

Earnings Preview: Microsoft anticipated to report larger Q3 income, revenue

1

When Two Authorized Agents Do Something No One Approved

September 17, 2026

AutoZone (AZO) Q4 2026 Preview: EPS Est. $54.22, Reports September 22

September 17, 2026

MEXC Upgrades AI Across the Trading Journey

September 17, 2026

TREAD is available for trading!

September 17, 2026

CoinInight

Welcome to CoinInsight.co.uk – your trusted source for all things cryptocurrency! We are passionate about educating and informing our audience on the rapidly evolving world of digital assets, blockchain technology, and the future of finance.

Categories

  • Bitcoin
  • Blockchain
  • Crypto Mining
  • Ethereum
  • Future of Crypto
  • Market
  • Regulation
  • Ripple

Recent News

When Two Authorized Agents Do Something No One Approved

September 17, 2026

AutoZone (AZO) Q4 2026 Preview: EPS Est. $54.22, Reports September 22

September 17, 2026
  • About
  • Privacy Poilicy
  • Disclaimer
  • Contact

© 2025- https://coininsight.co.uk/ - All Rights Reserved

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining

© 2025- https://coininsight.co.uk/ - All Rights Reserved

Social Media Auto Publish Powered By : XYZScripts.com
Verified by MonsterInsights