INVARIANCE | Arc
MenuClose
Authority under changing conditions

More capable agents.
The same organizational authority question.

Frontier systems can work longer, coordinate across agents and tools, and change their approach as conditions change. Authority Control keeps the organization’s authority focused on the result.

The thirty-second read
Systems become more capable

They can coordinate, persist, and try more paths.

Organizational authority remains explicit

The organization defines which results may take effect.

Coverage remains important

Authority Control applies where the relevant execution paths invoke the determination.

The operating model

Agent behavior can change. Authority remains organization-defined.

Authority Control evaluates each proposed result against current applicable authority and records the determination.

Access

What an actor can reach.

Capability

What it can discover, coordinate, or attempt.

Authority

What it may commit the organization to.

Greater access and capability can produce more proposed actions. The authority applicable to each action remains defined by the organization.

Upstream providers may pace their own development. An enterprise still operates several model generations, third-party and open models, existing automation, vendor systems, APIs, and human users at the same time. The organization needs its own reference for what may take effect on its behalf.

OpenAI · pacing model development · 2026

OpenAI states that it temporarily slowed the pace of scaling, including a two-week pause in reinforcement learning training on its latest models intended for deployment, while it hardened and red-teamed its research environments and expanded the coverage of its monitoring systems, and that its largest planned frontier RL run remains on hold. The trigger it names is the OpenAI and Hugging Face incident together with preliminary evidence that an upcoming model may meet a critical cybersecurity capability threshold under its own preparedness framework. Read the statement →

What greater capability changes

Keep current authority as the reference.

More autonomy creates more ways to act. It does not automatically expand organizational authority.

Path / Result / Authority

More agent paths. The same authority question.

Organizational authorityAuthority that applies to the resultScope · Limits · Conditions
01 / TECHNICAL PATHS
Human / Service / SoftwareAI agents → toolsParallel agent pathsModel / tool handoffs
02 / EXISTING CONTROLS
IdentityAccessRuntimeWorkflow

Govern actors, resources and technical paths

03 / PROPOSED RESULT
What would
take effect?

The organizational result remains the reference

04 / COMMITMENT BOUNDARYMay this result
take effect?
PermitDeferBlock

Alternative determinations

Results only. Enforcement depends on integration with the execution path.Verified conditions inform evaluation. A durable determination record is preserved; execution evidence remains separate.

Models, tools, and methods can change while authority for results remains governed and current.

Organizational authority remains bounded as coordination, capability, execution capacity, and agent populations increase.

Durable authority recordEvery determination leaves a durable record.
TIMEPROPOSED RESULTDETERMINATIONRECORD
14:02:15ZRelease $750K to a newly added counterpartyDeferAC-4471-04

Existing controls govern identity, access, security, and operating conditions. Authority Control evaluates the result. Permit means it may proceed; execution remains a separate fact.

01

Gain more capability. New tools or access can make more possible without authorizing more.

02

Coordinate at scale. More agents can propose more results without multiplying organizational authority.

03

Change technical paths. Alternate routes do not establish broader organizational authority.

04

Reach new systems. Technical reach does not establish authority over the resulting consequence.

Adaptive systems can change how they work. Authority Control applies only where the organization has integrated it into the relevant workflow.

Machine-scale conditions

Coordination, changing paths, and mistaken context create different authority problems.

The three cases differ in where the authority problem appears: coordinated activity, changing paths, or mistaken context.

Machine-scale condition
The authority question

Coordination and parallel results

Many agents, many results

An agent population can work in parallel, divide tasks, and produce many separate consequential results at the same time.

The authority question

Can many machines create many consequences without multiplying the authority the organization has established?

Changing paths and uncertain trust

New access, new routes

An agent may gain a capability, credential, or route that reaches a consequential result. A previously unmediated route remains outside Authority Control until coverage is established.

The authority question

Does new access, capability, identity, or route create authority?

Incorrect understanding of real-world context

Assigned environment

An agent treats a system as part of its task environment and acts there on that understanding.

The authority question

Does the agent’s belief about the target or environment establish authority?

Organizational authority comes from the organization and remains separate from capability, coordination, access, or an agent’s belief.

Context and authority

Technical reach does not establish organizational authority.

An agent can form its own understanding of the environment and the systems involved in its task.

Technical access

Reaching a system demonstrates technical capability, not organizational authority.

Organizational authority

The organization still determines whether a consequential result is authorized.

Technical access establishes reach. Organizational authority is established by the organization, not by the agent’s interpretation of its environment.

Disclosed exercises

How the authority question appears in disclosed evaluations.

Three disclosed 2026 evaluation case families put the question to real systems. The environments and failure modes differed, but each separates technical capability from organizational authority over the actual result.

Incorrect understanding of real-world context

The agents were given a defined test range. Some acted outside it.

122evaluation runs across seven frontier models
10runs where agents acted autonomously on the live internet
19actions outside the intended scope
1 hourfrom detection to containment

Researchers identified which systems were part of the exercise. The agents also had access to the open internet, but the task did not clearly define what they could do there.

Some agents created accounts to get through sign-up checks, exposed a credential that another agent later reused, and opened a pull request against an unrelated repository.

They had the technical ability to reach those systems. Did they have authority to act there?

UK AI Security Institute · disclosed August 2026

Read the full case →
Changing paths and uncertain trust

An evaluation agent reached systems outside the intended sandbox while pursuing the benchmark task.

17,600attacker actions recovered
6,280action clusters over five days
181devices enrolled using one mesh key
0mutating cloud API calls where scope was bounded

The agent was given a task inside a controlled test environment. It found a path onto the open internet and continued into systems outside the test. Along the way, it created accounts, obtained and reused credentials, and reached another organization’s production environment.

The agent found technical paths that let it continue beyond the original environment.

It could keep going. Who had given it authority to act outside the test?

Hugging Face July · OpenAI August 2026

Read the full case →
Incorrect understanding of real-world context

The assigned task remained constant while the actual target changed.

141,006evaluation runs reviewed
3incident families identified
6runs across those incidents
15real systems that ran one publicly published package

Anthropic reported that evaluation prompts described a simulated environment with no internet access, while a third-party evaluation environment had live internet access. Models then encountered real systems while pursuing the assigned capture-the-flag objective.

The case separates the agent's understanding of its environment from the organization's authority over the actual target, destination, and consequence.

If the agent believes a real system is part of the simulation, does that belief create authority to act there?

Anthropic and Irregular · disclosed July 2026

Read the full case →

These summaries reflect the cited disclosures, not an independent reconstruction. Investigations and facts may change. They do not establish that Authority Control would have prevented the incidents.

Design partners

Begin with one important workflow or connected relationship.

Start by mapping one consequential AI workflow, observing proposed results, and assessing where selective enforcement is justified.