AI RESEARCH

Before the Tool Call: Deterministic Pre-Action Authorization for Autonomous AI Agents

arXiv CS.AI

ArXi:2603.20953v1 Announce Type: cross AI agents today have passwords but no permission slips. They execute tool calls (fund transfers, database queries, shell commands, sub-agent delegation) with no standard mechanism to enforce authorization before the action executes. Current safety architectures rely on model alignment (probabilistic