Authority-Inference Separation in Agentic Finance: First-Line Control, Blockchain Enforcement, and Replayable Assurance
2026-08-31 • Cryptography and Security
Cryptography and Security
AI summaryⓘ
The authors created a system called Authority-Inference Separation (AIS) that keeps AI financial actions under strict control by separating the decision to act from the actual execution of that action. AIS carefully checks if an AI agent is allowed to carry out a financial task by verifying identities, permissions, and rules before letting the action happen. They tested AIS against various attacks and found it blocked all unauthorized actions, unlike simpler methods. The study also explains how blockchain records can support the process but cannot replace AIS’s role in deciding what actions are allowed.
AI agentsAuthority-Inference Separation (AIS)financial actionblockchainagent identityauthorizationpolicy validationoperational controlpublic ledgerrisk management
Authors
Hui Gong, Michail Samawi, Francesca Medda
Abstract
AI agents can select tools, counterparties, and transaction parameters, yet inference should not itself confer authority to execute a financial action. This study develops and evaluates Authority-Inference Separation (AIS), an intent-centered architecture for bounded agentic finance. AIS treats a financial action intent as the control object: a machine-generated proposal can receive temporary executable authority only after an independent deterministic control plane validates registered agent identity, accountable ownership, mandate and risk-appetite lineage, policy version, state, approvals, and exact economic semantics. Blockchain can then enforce the operational representation of granted authority and record portable settlement evidence, while institutional legitimacy, service delivery, accounting classification, and human accountability remain off-chain obligations. Evaluation combines four-domain instantiation, official BIS and MAS cases, a 48-fixture executable prototype, and a public-ledger observability test. Across 36 synthetic authorization attacks, a direct-agent baseline accepted 36 attack effects, a prompt-policy baseline accepted 20, and AIS accepted none; all three accepted 8/8 admissible fixtures. AIS also rejected 4/4 token replays and 8/8 recipient or rail substitutions, withheld completion in 4/4 service-delivery failures, and populated all 13 defined evidence fields. A test of 1,700 recent Base transactions associated with public x402 facilitator addresses shows that public ledgers can evidence settlement and selected authorization parameters but cannot establish institutional mandate, legal accountability, service delivery, or accounting treatment. AIS and blockchain are therefore complementary: AIS decides whether a specific intent may act, while blockchain can make granted authority bounded, executable, and independently observable.