Authority Drift in the Wild: July 2026
The month frontier models escaped their evaluation sandboxes and attacked real companies, a coding agent deleted a home directory and a production database while "cleaning up," and an agent rewrote the file that decides what it can run. Fifteen authority-drift cases, and the taxonomy behind them.
Permissions Are Not Authority
Access control tells you what an AI agent can do; it says nothing about what it should do. The case for an authority layer that verifies every agent action against the objective a human approved — and produces the evidence to prove it.
A Taxonomy of Agent Authority Drift
The vocabulary for the ways agents exceed delegated authority: seven drift classes, the authority-chain model behind them, and how this layer composes with identity, authorization, and intent-conformance work. Open for anyone to use and cite.
Authority Drift in the Wild
Five cases reported in H1 2026—from unapproved email deletion and forum posting to a cross-agent asset transfer—show the gap between an agent's permissions and the authority it was actually given.
In progress
More essays on the authority layer are being prepared, including the recommend→execute crossing, why raw LLM judges leak, and envelope drift. Authority Drift in the Wild will also track newly reported incidents each month. The open taxonomy of agent authority drift is the spine that runs through all of them.