AI RESEARCH

The Authorization-Execution Gap Is a Major Safety and Security Problem in Open-World Agents

arXiv CS.AI

ArXi:2605.11003v1 Announce Type: cross This position paper argues that the Authorization-Execution Gap (AEG) is a major safety and security problem in open-world agents. The AEG is the divergence between what a principal intends to authorize and what an open-world agent ultimately executes. Because such agents act autonomously across tools, persistent state, and multi-agent handoffs, even small instances of authorization divergence can cause harm that is difficult or impossible to undo.