INVARIANCE | Arc
MenuClose
AI Systems

Keep AI-driven results within the authority the organization has established.

New models, agents, and tools can change quickly. The organization still decides which results they may create on its behalf. Authority Control applies that authority before a consequential result takes effect.

An AI agent can use approved tools and valid access to create a result outside organizational authority.

Scale, scope, and pace

AI accelerates Scale, Scope, and Pace.

Organizational authority remains the reference for the consequential result.

The pressure in AI terms
What stays stable

Pace

New models, agents, tools, and routes arrive continuously, and each one can reach a consequential result a different way.

What stays stable

A new model, agent, or route does not expand organizational authority.

Scope

One agent workflow can cross systems, vendors, identities, and data domains, while each control governs its own part.

What stays stable

A result may span several systems and still meet one authority question. Each execution path requires its own coverage.

Scale

One person can direct many agents. That additional capacity does not multiply the person’s delegated authority.

What stays stable

More agents multiply the activity, not the authority behind it.

One result, many paths

Different paths can lead to the same result.

Illustrative scenario: an agent assigned to analyze customer data proposes releasing protected data to an external recipient. An export API, collaboration workspace, or another agent could offer different routes to that result. Each route needs its own coverage assessment.

Bulk-export API call
Repeated smaller queries
Collaboration workspace upload
Write to an external repository
Delegation to another agent
The proposed consequence Release protected customer data to an external recipient.
Authority evaluation returns Permit Defer Block

The teal line is the commitment boundary, the point where a proposed result would take effect.

Authority Control applies the organization’s authority to that result and returns Permit, Defer, or Block before it takes effect. Each determination leaves a durable record.

Authorized objective, separate authority

An authorized objective does not make every consequential result authorized.

OpenAI’s September 2026 model-misalignment reporting framework includes individual training and evaluation cases in which models used exposed credentials, uploaded files to public services, or created unsanctioned communication paths while pursuing assigned objectives.

The authority question

While pursuing an authorized task, a system may still propose a consequential result that falls outside organizational authority. Technical capability and task assignment do not by themselves establish authority for that result.

Models, agents, frontier systems

More capable AI. Authority that remains organization-defined.

New AI capability does not itself expand what the organization has authorized. Authority Control applies the organization’s current authority before consequential results take effect.

Models

Where may this model and version be deployed and used?

Agents

What consequential results may this agent create on the organization’s behalf?

Frontier systems

Which consequential results require additional authority or review as AI use expands?

Cybersecurity agencies from five allied countries · June 2026

Five Eyes cyber leaders warned that AI is increasing the speed, scale, and sophistication of cyber threats and shortening the interval between vulnerability discovery and exploitation. Read the joint statement →

Where Authority Control fits

AI security and Authority Control work at different parts of the problem.

Model evaluation

helps the organization understand model capability and behavior.

Identity and access

govern who or what can reach systems and tools.

Security controls

manage operating conditions, manipulation, and technical risk, including prompt injection and unsafe tool use.

Authority Control

evaluates whether the result is within organizational authority before it takes effect.

Together, these controls address technical risk and organizational authority as AI capability grows.

Evidence

Disclosed 2026 evaluations show where capability and authority diverge.

The linked cases separate reported facts, the authority question, and the limits of the analysis. They do not demonstrate Authority Control’s effectiveness in those incidents.

Design partners

Start with one AI workflow that can create a material result.

Choose an AI workflow that can move money, release data, change production, or create an external obligation. Map the result and its applicable authority, then observe proposed results before choosing enforcement.

New technology changes how work gets done. The organization still decides what it may commit to.

Related solution

When the result concerns data.

Explore authority for consequential data use, movement, release, and deletion.

Explore Data ↗