The Attack Was Authorized: The Missing Security Boundary for AI Agents
APIs can verify that an agent has permission. They cannot verify that you intended its action. Here’s how attenuated capabilities and signed receipts can close that gap.
Jul 23, 20269 min read14