Authorization Can Expire Between Request and Commit: Cross-Model Evaluation of a Currentness-Aware Reference Kernel for Tool-Using AI Agents

Tool-using AI agents can request a consequential action while authorized and commit it after that authorization has changed. This preprint reports matched synthetic experiments comparing Native natural-language authority, an isolated no-revalidation Static Typed architecture, and a compact currentness-aware authority-provenance Reference Kernel. In the qualified GPT-5.6 Sol study and a separately frozen Claude Sonnet 5.5 replication, Native and Static Typed committed every tested request-to-commit-revoked target (24/24 each per study), whereas the Reference Kernel committed 0/24. P4 unauthorized attempt rate was 0/24 in every arm, and authorized task completion was preserved. The manuscript makes a bounded systems claim and does not claim conceptual priority for commit-time authorization or universal provider/real-world generality. Preprint; not peer reviewed.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-05
DOI
https://doi.org/10.5281/zenodo.23147502
Primary Topic
Access Control and Trust
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
preprint

Authorization Can Expire Between Request and Commit: Cross-Model Evaluation of a Currentness-Aware Reference Kernel for Tool-Using AI Agents

Robert Bigsby
Zenodo (CERN European Organization for Nuclear Research)
Access Control and Trust
preprint

Authorization Can Expire Between Request and Commit: Cross-Model Evaluation of a Currentness-Aware Reference Kernel for Tool-Using AI Agents

Robert Bigsby
preprint en

Abstract

Tool-using AI agents can request a consequential action while authorized and commit it after that authorization has changed. This preprint reports matched synthetic experiments comparing Native natural-language authority, an isolated no-revalidation Static Typed architecture, and a compact currentness-aware authority-provenance Reference Kernel. In the qualified GPT-5.6 Sol study and a separately frozen Claude Sonnet 5.5 replication, Native and Static Typed committed every tested request-to-commit-revoked target (24/24 each per study), whereas the Reference Kernel committed 0/24. P4 unauthorized attempt rate was 0/24 in every arm, and authorized task completion was preserved. The manuscript makes a bounded systems claim and does not claim conceptual priority for commit-time authorization or universal provider/real-world generality. Preprint; not peer reviewed.

Zenodo (CERN European Organization for Nuclear Research)
Radiall (France) (FR), Radiant Research (United States) (US)
Access Control and Trust
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.