The gap
Identity, access, and runtime controls can all work as intended while the resulting action is still outside the authority the organization established.
The commitment boundary and organizational authority in machine-scale systems
In July 2026, roughly 1,200 AI agents that were intended to operate independently found a way to communicate through an unsanctioned message board during OpenAI cybersecurity evaluations. They exchanged more than 70,000 messages and files. Roughly 700 agents went on to participate in an attack on Hugging Face.1617
Identity, access, and runtime controls can all work as intended while the resulting action is still outside the authority the organization established.
The critical point is where technical activity becomes an organizational consequence. The authority question concerns whether that result may take effect, rather than every technical step that produced it.
More AI agents, tools, systems, vendors, execution paths, and technical reach can increase what is possible without increasing what the organization has authorized.
Organizations can continue to ask whether a consequential result is within established authority as actors, models, tools, and execution paths change.
The agents divided work, shared findings, and coordinated activity across the population.1617
Parallel agent use is also becoming ordinary work. OpenAI reported in June 2026 that its heaviest internal Codex users regularly generated more than 60 hours of agent work in a single day, distributed across multiple agents running in parallel. More than 70 percent of sampled individual users had asked Codex to perform work estimated to take a person more than one hour.13
Large organizations already operate across people, applications, vendors, and technical paths. Authority to approve, spend, release, or change is distributed across that environment. Keeping it connected to consequential activity becomes harder as activity grows and technology changes.
AI intensifies all three pressures. It increases scale by adding more actors and parallel activity. It expands scope by increasing the number of systems, tools, vendors, and paths through which work can occur. It increases pace because capability, operating patterns, and execution routes can change faster than organizations can continually redesign controls around each one.
That creates a control question that extends beyond AI: when consequential activity can form through many actors, systems, controls, and paths, what governs which results may take effect on the organization’s behalf?
Systems have long recognized points of commitment: where a database change becomes durable, a financial obligation becomes final, or a physical system changes state. The argument here extends that understanding to organizational consequence. It asks what authority should govern the result an institution is about to own, honor, execute, disclose, or absorb.
Enterprise systems are well developed at governing actors, resources, sessions, transactions, and local operations. Many domains also recognize points of commitment, where a proposed change becomes durable, final, or consequential. A further control problem appears when distributed activity produces a result for the organization that no single control evaluates as an organizational whole.
This essay extends the logic of commitment to organizational consequence. We use commitment for a specific proposed result that, if made effective, would create or change a consequence the organization is expected to own, honor, execute, disclose, or absorb. We use commitment boundary for the transition at which that proposed result takes organizational effect.
The structural problem predates AI. AI makes it harder to ignore because it increases scale, expands scope, and compresses the pace at which operational capacity changes. Actor populations, operational capacity, and execution paths can expand without expanding the organizational authority behind them. The commitment boundary provides a consistent place to ask the authority question as those actors and paths change. Authority Control is proposed as a complementary paradigm for evaluating consequential results against the authority the organization has established.
At the access boundary, existing controls answer a well-defined set of actor-and-resource questions. Who or what is acting? What resource is being requested? Under what conditions? Should the request be allowed?
A bank authenticates an employee before granting access to a payment system. A hospital authenticates a clinician before allowing access to a clinical system. An engineer holds defined administrative privileges over industrial infrastructure. In each case, the reference point is the actor’s relationship to a resource, session, or local operation.
NIST’s Zero Trust Architecture formalizes much of this logic. It moves security away from implicit network trust toward explicit decisions about users, assets, and resources before access is established.1 CISA extends the model across identity, devices, networks, applications and workloads, and data, supported by visibility, analytics, automation, orchestration, and governance.2
A different reference point appears when activity is about to become consequence. A payment may be technically valid and about to commit capital. A deployment may pass its technical controls and be about to change production. A data operation may be permitted and be about to create a disclosure. At that point, the relevant object is the result the organization is about to create.
We call that transition the commitment boundary.
A payment is released. Code reaches production. Data leaves an environment. A configuration becomes active. A physical process changes state. An obligation becomes binding. Before the transition, the enterprise is preparing, requesting, approving, validating, or executing steps toward a result. At the boundary, the result takes organizational effect.
In this essay, a result binds the organization when it becomes an operative organizational consequence. Binding here is organizational: the result has taken effect whether or not it is legally final or irreversible.
The underlying idea has precedents. IBM uses commitment boundary in database transaction control for the point established by a successful commit or rollback, after which changes are either made permanent or returned to the prior state.3 Financial market infrastructure uses the related concept of settlement finality. The CPMI-IOSCO Principles for Financial Market Infrastructures require systems to define the point at which settlement becomes final and the point after which obligations can no longer be revoked.4
Those concepts govern particular forms of technical or financial finality. The extension proposed here is to place organizational consequence at the center of the authority question at commitment.
A commitment is a specific proposed result that, if made effective, would create or change an organizational consequence: the payment about to be released, the deployment about to change production, the disclosure about to leave the organization, or the command about to alter physical state. The commitment boundary is the transition at which that proposed result takes organizational effect.
At this boundary, the primary question is:
May this result take effect for the organization?
Organizations already establish limits on who may approve, sign, spend, release, change, or otherwise create consequences on their behalf. Those limits may appear in policies, delegations, mandates, signing schedules, approval structures, contracts, or other authoritative sources.
We use organizational authority for the established institutional power to create or change specified consequences on an organization’s behalf, within defined scope, conditions, and limits. The concept is consistent with the rational-legal tradition associated with Max Weber, in which authority attaches to offices, rules, and defined jurisdictions that outlast the person holding them.5
That authority may attach to an office, be delegated to another actor, require several authorities to concur, or apply only under defined conditions. Delegation is one mechanism through which organizational authority is constituted and distributed.
Institutional practice makes the distinction concrete. The Federal Acquisition Regulation states that contracting officers may bind the U.S. Government only to the extent of the authority delegated to them and requires written limits on that authority.6
Access, capability, commitment, and authority describe different relationships. Access concerns what an actor can reach. Capability concerns what a person or system can technically do. A commitment is the proposed result about to take organizational effect. Organizational authority establishes whether that result falls within the institution’s power to bind itself.
A person, service, vendor, robot, or agent can hold broad access and substantial capability while holding much narrower authority to bind the organization.
The same authority question can still be asked as the technical environment changes: what result is proposed, and is it within the authority that applies now?
Enterprise security has become more capable through specialization. Identity systems establish who or what is acting. Access controls determine which resources that identity can reach. Endpoint controls assess the security posture of devices and workloads, while network controls govern which systems may communicate and under what network conditions. Data controls govern how sensitive information may be used or moved. Workflow systems route work through required approvals, sequencing, separation of duties, and exception paths. Runtime controls observe how applications, workloads, and processes behave while they execute. Detection platforms correlate signals across those systems to identify suspicious or harmful activity.
Specialization is a strength. It also makes enterprise control distributed.
A control can decide correctly within its own scope while the organization-level authority question remains unresolved. A service account can be valid and permitted to act. A device can be compliant. A workflow can satisfy its configured conditions. Those valid local decisions can still contribute to a result outside the authority the organization established.
The first gap therefore appears at the edge of a control’s scope: the control answers its own question correctly while the authority of the resulting organizational consequence remains unresolved.
A second form appears across controls. Several systems can each make a valid local decision while their combined activity produces a result that no single system evaluates against organizational authority as a whole.
In both cases, valid local decisions can leave authority for the organizational result unresolved.
Existing systems already enforce approval rules, transaction limits, separation of duties, safety interlocks, policy conditions, and other consequential restrictions. NIST’s security control catalog includes mature controls for least privilege, separation of duties, system integrity, and organization-wide risk management.7 Clark and Wilson’s commercial integrity model placed well-formed transactions and separation of duty at the center of protecting valid state in commercial systems.8
These are important antecedents. The remaining question concerns an organizational result assembled across actors, applications, vendors, controls, or time that were not designed as one transaction or one authority domain.
Better integration improves that environment. Shared telemetry, synchronized policy, stronger orchestration, and cross-domain analytics help controls form a more coherent picture. CISA treats visibility, analytics, automation, orchestration, and governance as cross-cutting Zero Trust capabilities for this reason.2
Integration improves the information available to local controls and cross-domain analysis. However, operational evidence shows how difficult coherence across distributed controls remains. CardinalOps’ 2025 analysis covered 13,000 production SIEM detection rules and more than 2.5 million log sources across enterprise environments, documenting substantial gaps between available telemetry and implemented detection coverage.9 Unit 42 reported in 2026 that critical evidence of initial intrusion was present in logs in 75 percent of investigated incidents but was not readily accessible or operationalized because of disjointed systems.10
These are detection findings. They measure the continuing operational cost of forming coherent judgments across distributed controls and stand separately from the authority gap described above. Authority Control evaluates whether the resulting organizational consequence falls within authority the institution has established.
The problem becomes harder as enterprise activity increases in scale, expands in scope, and changes at greater pace.
The enterprise already contains distributed actors, systems, controls, and paths. Three pressures increase the difficulty of keeping organizational limits connected to consequential activity. The controls hold constant across all three states of the figure; what changes is the number of actors and the number of paths that reach the same results.
Scale increases the amount of activity that can occur at once. More people, software, services, vendors, and machine actors can operate in parallel under the same organizational authority.
Scope increases the number of systems, control domains, organizations, and technical paths that can participate in the same consequential result.
Pace increases how quickly capabilities, integrations, operating conditions, and execution routes change.
Hundreds of people, applications, APIs, endpoints, data stores, vendors, and automated systems operate through different control capabilities, each scoped to the part of the operation it governs.
The controls remain specialized. The routes can multiply and re-form. The organizational result remains the point at which the enterprise must still answer whether the consequence is within the limits it established.
The structural problem predates AI. Trading systems, industrial controls, deployment pipelines, payment rails, APIs, cloud infrastructure, vendors, and workflow automation have long increased the amount of activity an organization can conduct. What is changing is the degree to which scale, scope, and pace are increasing together.
Automated execution has always increased capacity. Machine actors now make that capacity easier to multiply and direct in parallel.
OpenAI reported in June 2026 that its heaviest internal Codex users regularly generated more than 60 hours of agent work in a day, distributed across multiple parallel agents.13 Anthropic reported that the longest Claude Code sessions had nearly doubled in autonomous duration over three months.14
Google DeepMind describes a near future in which millions of agents built by different organizations may interact, communicate, negotiate, and transact across digital environments.15
The operating model is moving from one person using one software assistant toward a person, team, vendor, or objective coordinating a population of machine actors.
Scale matters because organizational authority does not automatically multiply with operational capacity. A manager’s spending limit does not increase because the manager can now direct twenty agents. A vendor’s mandate does not broaden because the vendor automates more of its work. The same or fewer human decision points can now generate substantially more activity.
The OpenAI and Hugging Face incident at the beginning of this essay is an early example of another change. Machine actors can divide work, share findings, specialize, hand work to one another, and continue a larger effort across systems after any individual agent stops.1617
Anthropic’s reward-seeking experiment shows a related pressure from a different direction. A model pursuing a trained objective can seek alternate routes when local controls interfere with that objective.25
Scope is not only the number of systems involved. It is the breadth of organizational consequence reachable through the operating environment. A single workflow can now touch applications, APIs, vendors, data stores, financial systems, cloud services, and physical infrastructure. Each participating control may remain valid within its own domain while the resulting organizational consequence spans them.
That makes the path less reliable as the sole organizing reference. The organizational authority question can be asked without first deciding whether the actor is trustworthy, compromised, aligned, or adversarial. It asks whether the particular result is authorized.
METR measures the duration of software tasks that frontier AI agents can complete at specified reliability levels, using the time a human expert would require as the benchmark.11 By early 2026, METR estimated that the task horizon at a given success rate had been doubling roughly every four months since 2023. The Bank of England also reported that the latest frontier models could complete software tasks with a 50 percent success rate that would take a human expert about 16 hours.12
Longer autonomous work gives software more opportunity to move through multi-step processes, recover from errors, use tools, and pursue objectives across several systems before a person intervenes. It also increases the amount of consequential work that can be assembled between human checkpoints.
The UK AI Security Institute reported in July 2026 that leading open-weight models in its cyber evaluations performed similarly to closed frontier models released roughly four to seven months earlier, narrowing from a six-to-ten-month gap measured through much of 2025. AISI cautions that this result does not predict how the future gap will develop.18
The current lag still matters. Open-weight models can be downloaded, modified, and operated outside the original provider’s monitoring, access controls, and revocation mechanisms. Capabilities first demonstrated in controlled proprietary systems can therefore become available in forms that the original provider cannot directly gate. The Bank of England reaches a related conclusion: restrictions on proprietary models may buy defenders time without preventing capable use indefinitely.12 The Financial Stability Board now describes frontier AI’s effect on cyber risk as an immediate financial-system concern and warns that frontier capability may materially alter the scale and economics of cyber risk.19
Existing cyber operations are already compressing response windows in some cases. Mandiant reported that the median time between an initial access event and handoff to a secondary threat group fell from more than eight hours in 2022 to 22 seconds in 2025.20
The practical issue for an enterprise is not simply that technology changes quickly. It is that capability, actors, integrations, and execution paths can change faster than organizations can continually redesign, validate, and synchronize controls around every route.
Scale increases coordination work. Scope adds interfaces between controls. Pace creates change faster than those controls may be updated. Together, they make it harder to keep established authority connected to consequential activity.
For the enterprise, the practical effect is straightforward: more consequential work can form through more routes before a person or single control sees the whole sequence.
The commitment boundary becomes more important under these conditions because the organizational question can remain stable even when the technical environment does not: what result is about to take effect, and is it within the limits the organization established?
One person may direct ten agents or one thousand. A vendor may replace human operators with autonomous systems. A compromised credential may be exercised through many processes at once. The organizational authority behind those actors remains defined by the institution.
Illustratively, a spending limit does not increase merely because more agents act under it. Applying a shared limit across related results requires the organization to establish and configure that requirement.
The scaling problem is therefore not that authority must expand with activity. The organization still needs to apply its limits as the number of actors and operations increases.
Composition is also critical. A series of individually modest data operations can combine into a material disclosure. Individually valid configuration changes can collectively produce a system state outside the authority the organization intended. Many locally acceptable actions can then resolve into one organizational result.
Machine scale can take several forms. Many technical actions can contribute to one consequential result, while automated systems can also create many consequential results in parallel. The authority question remains focused on the result about to take effect.
Operational capacity can scale while organizational authority remains bounded.
At larger scale, a further question becomes prominent:
What are all of these individually valid actors and actions collectively causing for the organization?
That question holds for employees, services, vendors, AI agents, robots, and adversaries alike.
Security and capability literature already uses the word authority in a related technical sense. The Principle of Least Authority in capability systems concerns limiting software components to the information and resources they need, and prior research has used the term authority control for capability-based software modules.21
The organizational use here concerns the established institutional power to create or change specified consequences on an organization’s behalf, within defined scope, conditions, and limits. A useful research question is how technical forms of authority should interact with organizational authority as software components acquire greater capacity to act for institutions.
The commitment boundary becomes especially important where digital decisions change financial, clinical, industrial, or physical state.
Financial systems already provide a precise example of consequential finality. The CPMI-IOSCO principles require financial market infrastructures to define the point at which settlement becomes final and the point after which a payment, transfer instruction, or other obligation can no longer be revoked.4
The organizational authority question arises before that finality: what authority supports the result that is about to become final?
The Bank of England identifies related frontier-AI risks across payments, trading, clearing, settlement, operational resilience, and shared technology dependencies.12 These are environments where technical action can become institutional consequence quickly.
Software and networked medical devices increasingly participate directly in care delivery. The U.S. Food and Drug Administration treats cybersecurity as part of medical-device resilience and requires manufacturers of covered cyber devices to address cybersecurity risk throughout the product lifecycle.22 FDA digital-health materials also provide concrete examples of software-driven clinical state change: an infusion pump can receive patient data and change pump settings, while a centralized monitoring system can use device data to command a ventilator to adjust pressure, volume, and flow.26
Health care already has mature safety, clinical, regulatory, and access controls. The commitment-boundary question sits alongside them: when software can alter a clinical or operational state, what authority should govern the consequential transition?
NIST defines operational technology broadly to include industrial control systems, building automation, transportation systems, physical access systems, and other programmable systems that interact with the physical environment. Its guidance emphasizes the distinct safety, reliability, and performance requirements of these systems.23
A command that opens a valve, changes a power-system setting, modifies a transportation control, or alters an industrial process creates a different class of consequence from ordinary information access. Existing OT controls govern many of these transitions. The research question is where organizational authority should become an explicit part of that control.
NIST’s Cyber-Physical Systems Framework treats computation, communication, sensing, actuation, physical processes, and people as one integrated system across energy, manufacturing, transportation, health care, and other domains.24
Robotics brings the commitment boundary into physical space. A robot can enter a protected zone, move equipment, manipulate a workpiece, alter a laboratory process, or interact directly with a person. Safety engineering already governs hazardous transitions through domain-specific constraints, verification, and interlocks. Organizational authority adds a further question where a technically possible and safe action may still exceed the scope granted to the person, system, or agent initiating it.
Across these domains, the boundary is specific to the system. The architectural question is common:
At what point does proposed activity become an organizational or physical consequence, and what authority should govern that transition?
Access control governs the actor’s relationship to a resource.
Authority Control governs the organization’s relationship to a consequence through the commitment that would create it.
The organization remains the source of substantive authority. At a commitment boundary, Authority Control evaluates the proposed commitment against the authority the organization has established and that applies under the current conditions.
Organizational authority exists inside a wider legal and institutional environment. Laws and regulations constrain what an organization may do. Standards and industry practices inform how controls are designed. The organization’s own authoritative sources, including governing actions, delegations, signing schedules, policies, contracts, and accepted mandates, establish who or what may act on its behalf and within what scope, conditions, and limits.
Potential applications vary by domain, from financial commitments to production releases and data disclosures. Clinical, industrial, and robotic systems raise related research questions; this essay does not establish AC deployment capability in those environments.
The common reference point is the organizational result.
Technology can change without automatically changing what the organization has authorized. Different actors and paths may reach the same kind of result, and the authority question remains focused on the result about to take effect.
Compromise can expand technical reach without expanding organizational authority. During degraded trust, organizations may apply tighter conditions to selected consequential actions while allowing other authorized operations to continue.
Where Authority Control is applied at a commitment surface, the authority question still applies when credentials, systems, or execution paths may be compromised: may this result bind the organization under the authority that applies now?
This determination complements detection and response. Security tools identify, contain, and remove intruders. Commitment-boundary control addresses consequential results while those processes occur.
We argue that enterprise security is entering a stage in which consequence becomes an explicit control concern alongside access.
Existing domains already govern forms of finality, transaction integrity, safety, approval, access, and state transition. A broader architectural question appears when consequential results are assembled across independent actors, controls, systems, and paths and must still be evaluated against organizational authority.
The commitment boundary provides a candidate abstraction for that problem, and Authority Control provides a proposed control paradigm for governing it.
The principle underneath the architecture is simple on purpose. Technology can expand an organization’s capacity to act while the human and institutional source of authority remains bounded. An organization should be able to establish who or what proposed a consequential result, which authority applied, what limits and conditions governed it, and why the result was allowed to take effect.
Scale adds actors and parallel activity. Scope connects more systems and relationships. Pace changes capabilities and paths. The organization still needs to decide which consequential results may take effect.
The research question is whether organizational authority can be made operational at that point without displacing the specialized controls that already govern identity, access, security, workflow, data, safety, and execution.
The next work is empirical. One useful test is to examine real organizational authority against selected consequential workflows and determine whether the authority question can be answered without displacing the controls that already govern identity, access, security, workflow, data, safety, and execution. Researchers and practitioners should also identify where existing controls already govern these boundaries effectively and where an organization-level authority question remains unresolved.
Financial institutions, hospitals, critical infrastructure, autonomous systems, robotics, government, and defense are important places to test the idea because errors and misuse there can produce consequences beyond the immediate technical system.
Increasingly autonomous systems make the boundary more visible. Scale, scope, and pace increase the cost of leaving the organizational authority question implicit.
Certain Authority Control technologies are patent pending.