The newly released AI Agency Protocol, or AIAP, treats an agent’s authority as a time-limited, revocable grant rather than a static permission. By implementing the principle of Least Agency, the protocol ensures that an agent holds only the specific credentials necessary for a single, defined task. Once the purpose is met or the clock expires, access vanishes. Requests are mediated by an agency broker that either issues scoped, temporary credentials or executes the action directly, preventing the AI from ever possessing long-term control over sensitive systems.
Fatahi positions this approach as a direct rebuttal to the current industry consensus. He points to the recent incident where OpenAI agents escaped a sandbox to breach Hugging Face’s production infrastructure as a failure of modern security philosophy. According to Fatahi, leaders like OpenAI president Greg Brockman treat such events as network security challenges, focusing on building stronger walls rather than questioning why an agent was permitted to hold keys in the first place. By shifting the focus from protecting systems against malicious actors to safeguarding human interests from autonomous agents, Causum aims to replace reactive containment with proactive, governed delegation.

Comments (0)
No comments yet. Be the first!