Skip to main content
Kent Academic Repository

Agentic AI Gone Rogue: Addressing the Limitations of Static Access Control

Gupta, Shivangi, Arief, Budi, de Lemos, Rogério (2026) Agentic AI Gone Rogue: Addressing the Limitations of Static Access Control. In: 2026 International Workshop on Security and Artificial Intelligence (SECAI 2026). (In press) (KAR id:116436)

Abstract

As agentic AI systems become increasingly capable of acting autonomously on behalf of users, they reduce users’ workload and improve the efficiency of achieving goals. However, they also introduce security challenges, such as privilege escalation due to broad access permissions granted to agents, and the lack of complete delegation chain verification at the server side. To address the lack of delegation chain verification, we introduce a decentralised delegation and verification approach that uses a signed JSON Web Token (JWT). The proposed approach performs continuous trust checks on every delegation before the agent reaches the server for execution. Agents’ authenticity is established through signed agent cards, whereas verification and authorisation are managed through a combination of tokens and a gateway integrated with a policy engine that enforces the permissions granted by the user. This approach ensures that agents are authorised only to perform user-approved tasks and can exercise only the permissions explicitly granted by the user for those tasks. Our approach aims to motivate a shift from the current methods (such as providing agents with access tokens without verifying what the user actually approves and delegates, which rely on predefined scopes or permissions that can be overly broad or restrictive), to fine-grained user-approved permissions. To evaluate the proposed solution, the approach was tested against ten different threats that are commonly found in agentic AI deployments. Based on the results, the proposed approach shows promising potential for verifying delegated permissions and ensuring that delegation is limited to permissions that are explicitly approved by the user. Such features are currently missing in existing frameworks, which tend to verify delegation requests only once they reach the resource server, which can lead to partial chain verification, and users’ actual requirements being missed.

Item Type: Conference proceeding
Uncontrolled keywords: Agentic AI · Trusted Delegation · Continuous Verification · Dynamic Authorisation
Subjects: Q Science > QA Mathematics (inc Computing science)
Institutional Unit: Schools > School of Computing
Institutes > Institute of Cyber Security for Society
Former Institutional Unit:
There are no former institutional units.
Depositing User: Budi Arief
Date Deposited: 25 Sep 2026 15:16 UTC
Last Modified: 25 Sep 2026 15:17 UTC
Resource URI: https://kar.kent.ac.uk/id/eprint/116436 (The current URI for this page, for reference purposes)

University of Kent Author Information

  • Depositors only (login required):

Total unique views of this page since July 2020. For more details click on the image.