Story · arXiv
Agent Memory Is a Surface for Endogenous Authorization Laundering (arXiv)
paper · Story page

Persistent memory can record permissions the interaction history never granted, and a later agent acts on them with no attacker involved. On EAL-Bench, memory writers created false authority for up to 50.2% of unauthorized requests and executors acted on it in 98.6% of trials; provenance-backed permissions and bounded event sourcing substantially reduce it.
In plain words
- Researchers found that stored artificial intelligence memories can invent permissions that users never granted.
- A later system may trust the false record and take an unauthorized action without any outside attacker.
- Requiring every stored permission to link to a valid source greatly reduced the problem.
- Organizations using long-running automation need permission records that preserve where each authorization came from.
Appeared in
- GPT-6 Astra's score hinges on its harness, and agents rot geometrically with each step
Sep 04, 2026 · in the sections
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.
