Threat+Constellation
Live— UTC

THREAT OBSERVATORY / STRUCTURAL OBSERVATION

THREAT-AUTHORITY-001 / OBSERVATION — ACTIVE / 2026-09-26

OPERATIONAL CONCEPT

Authority Surface

When AI Capability Becomes Real-World Authority

AIの能力が、現実世界の権限になるとき。

AI risk does not depend only on what a model can do.

It also depends on what the surrounding system allows the model to reach.

A model may gain access to networks, credentials, APIs, financial systems, industrial equipment, vehicles, robots or other AI systems.

Each connection expands the surface through which model capability can become real-world action.

This surface is the Authority Surface.

The problem is no longer only what AI can do. The problem is what AI is allowed to reach.

Structural observation. Operational concept. Emerging pattern. Not proven science, and not a quantitative risk score.

Operational concept

Authority Surface

The set of systems, resources, credentials, interfaces, infrastructure, financial mechanisms and physical mechanisms that an AI system is permitted or able to reach.

AIシステムが、到達を許されている、あるいは到達できてしまう、システム・資源・認証情報・インターフェース・基盤・金融手段・物理手段の集合。

01 · Capability and authority

Capability Is Not Authority

AI capability has traditionally been evaluated through model benchmarks, reasoning performance, coding ability, planning ability and tool use.

But capability alone does not determine the consequences of an AI system.

A highly capable model operating inside a constrained environment may have limited ability to affect the outside world.

A less capable model connected to credentials, APIs, payment systems, industrial equipment or physical machines may have far greater operational impact.

What can the model do?

What can the system allow the model to reach?

CAPABILITY

  • Reasoning
  • Planning
  • Coding
  • Discovery
  • Generation
  • Tool use

AUTHORITY

  • Credentials
  • Network access
  • APIs
  • Payments
  • Infrastructure
  • Machines
  • Robots
  • External systems

Neither column is a safety rating. Capability is what the AI can do. Authority is what the surrounding system allows it to affect.

High capability with low authority may remain constrained. Moderate capability with broad authority may create significant systemic risk.

02 · Escalation

The Authority Surface

  1. MODEL
  2. Tool Access
  3. Data Access
  4. Network Access
  5. Credential Access
  6. External APIs
  7. Financial Authority
  8. Infrastructure Authority
  9. Physical Authority

Every layer increases the number of real-world systems that may be influenced by an AI process.

The Authority Surface is not simply a count of integrations. It also depends on:

  • scope of permissions
  • reversibility
  • human approval requirements
  • credential lifetime
  • system criticality
  • automation depth
  • downstream propagation
  • persistence
  • observability
  • intervention latency

03 · Dimensions

Authority Surface Dimensions

  • ACCESS

    What can the AI reach?

    • internal files
    • databases
    • internet
    • external APIs
    • cloud infrastructure
    • operational networks
    • third-party systems
  • PERMISSION

    What can the AI change?

    • read
    • write
    • delete
    • execute
    • authorize
    • publish
    • transfer
    • deploy
  • PERSISTENCE

    For how long can the AI continue acting?

    • one request
    • one session
    • scheduled execution
    • autonomous loop
    • persistent service
    • multi-agent delegation
  • PROPAGATION

    Can one AI action trigger other systems?

    • workflow automation
    • downstream agents
    • financial transactions
    • infrastructure changes
    • machine commands
  • REVERSIBILITY

    Can the action be undone?

    • editable document
    • reversible configuration
    • financial transfer
    • public publication
    • machine movement
    • infrastructure shutdown
  • OBSERVABILITY

    Can humans see what is happening before consequences propagate?

    • audit log
    • approval checkpoint
    • real-time alert
    • delayed review
    • invisible background execution

04 · Supervisory Layer

The Supervisory Layer Sits Between Capability and Authority

  1. AI CAPABILITY
  2. AUTHORITY REQUEST
  3. SUPERVISORY LAYERALLOWHOLDDENY
  4. REAL-WORLD ACTION

The Supervisory Layer is not intended to reduce model intelligence.

Its purpose is to govern the transition from model intention to external consequence.

  • A system may allow reasoning while holding execution.
  • A model may discover a credential without being allowed to use it.
  • A model may identify an external system without being allowed to connect to it.
  • A model may prepare an action without being allowed to execute it.

This separation is fundamental.

  • ALLOW

    Execution may proceed within the current grant.

  • HOLD

    Execution is interrupted. Context is preserved for review.

  • DENY

    Execution is refused.

Read The Supervisory Layer →

05 · Unresolved authority

HOLD Before DENY

Many AI governance systems assume binary permission: ALLOW or DENY.

Uncertainty often appears before a violation is fully known.

SHIRO & Co. uses ALLOW, HOLD, and DENY.

HOLD is the supervisory state for unresolved authority.

HOLD is not rejection.

HOLD interrupts execution while preserving context for review.

  • UNKNOWN DESTINATIONHOLD
  • NEW CREDENTIAL DISCOVEREDHOLD
  • THIRD-PARTY SYSTEM DETECTEDHOLD
  • PRIVILEGE ESCALATION REQUESTHOLD
  • PHYSICAL ACTUATION REQUESTHOLD
  • IRREVERSIBLE ACTIONHOLD
  • HIGH-CONSEQUENCE ACTIONHOLD
  • UNKNOWN DOWNSTREAM EFFECTHOLD
Open HOLD inside The Supervisory Layer →

06 · Authority chain

Example Authority Chain

ILLUSTRATIVE SCENARIO

ILLUSTRATIVE AUTHORITY CHAIN

Hypothetical case. This exact sequence is not claimed to have occurred in any particular real-world incident.

An AI cybersecurity agent is instructed to test an internal environment.

  1. 01

    ALLOW

    Model identifies vulnerability

    Identify vulnerability

  2. 02

    ALLOW

    Model exploits vulnerability

    Exploit authorized test environment

  3. 03

    ALLOW

    Model obtains broader network access

    Expand within authorized environment

  4. 04

    HOLD

    Model discovers credential

    Discover unknown credential

  5. 05

    HOLD

    Credential appears to belong to an external system

    Detect third-party destination

  6. 06

    DENYunless independently authorized

    Model prepares external connection

    Attempt external connection

The dangerous transition may not be the model discovering something. It may be the moment discovery becomes authority.

07 · Expansion

Authority Expansion

These stages describe how an Authority Surface can widen. They are not a claim that every AI system will move through all of them.

  1. Chatbot

    Produces information.

  2. Tool User

    Calls bounded external tools.

  3. Agent

    Plans and executes multi-step tasks.

  4. System Operator

    Changes software, data or infrastructure.

  5. Infrastructure Participant

    Interacts with critical operational systems.

  6. Physical Actor

    Produces real-world physical consequences through machines.

08 · Physical layer

When Authority Reaches the Physical Layer

Authority Surface becomes especially important when AI actions leave software environments.

  • robot motion
  • industrial machinery
  • warehouse systems
  • autonomous vehicles
  • drones
  • energy systems
  • building control
  • logistics
  • medical devices

A software mistake can become a physical event.

Can the model generate the command?

Who authorizes the command to become motion?

Hardware Layer signal →

09 · Structural model

The Real Risk Relation

STRUCTURAL MODEL

NOT A QUANTITATIVE RISK EQUATION

REAL-WORLD AI RISK

  1. CAPABILITY

  2. ACCESS

  3. AUTHORITY

  4. PERSISTENCE

Structural model, not a quantitative risk equation. Real-world AI risk is approximated by capability, access, authority, and persistence.

Limiting layers

  • SUPERVISION
  • REVERSIBILITY
  • OBSERVABILITY

These act as limiting layers.

  • Capability↑
  • Authority↑
  • Persistence↑
  • Consequence potential↑
Capability
What the AI can reason about, generate, discover or execute.
Access
What systems, networks, APIs, tools and data the AI can reach.
Authority
What actions the AI is permitted to take.
Persistence
Whether the AI can continue acting across time, sessions, systems or environments.

A supervisory model for comparing dimensions. It does not produce a score.

10 · Research questions

Questions for Observation

  1. 01When does tool access become operational authority?
  2. 02When does credential discovery become permission?
  3. 03When should a system move from ALLOW to HOLD?
  4. 04How long should autonomous authority persist?
  5. 05Which actions must always require human review?
  6. 06Can high-consequence actions remain reversible?
  7. 07How quickly can supervision intervene?
  8. 08Can downstream systems distinguish human authority from AI-derived authority?
  9. 09When one AI delegates to another AI, does authority expand automatically?
  10. 10Can an AI inherit permissions that were originally granted to a human?
  11. 11What happens when temporary access becomes persistent authority?
  12. 12Where should authority expire?

11 · Illustrative defaults

Authority Boundary Table

ILLUSTRATIVE DEFAULTS

SYSTEM-SPECIFIC POLICY REQUIRED

Not a universal policy. A supervisory model for discussion inside a specific system.

Illustrative authority defaults. System-specific policy is required. Not a universal policy.
EventAuthority ChangeDefault StateReason
Read internal documentationLowALLOWInformational access
Write internal draftLowALLOWReversible output
Deploy codeMediumHOLDOperational consequence
Use newly discovered credentialHighHOLDAuthority provenance unknown
Access third-party systemHighHOLDBoundary crossed
Transfer fundsHighHOLDFinancial consequence
Delete infrastructureCriticalDENYHOLDPotentially irreversible
Move industrial machineCriticalHOLDPhysical consequence
Modify safety controlCriticalDENYunless specifically authorizedSafety boundary

12 · Provenance

Authority Needs Provenance

Systems should record not only: What action occurred?

  • Who granted authority?
  • Where did the permission originate?
  • Was the authority direct or inherited?
  • When was it granted?
  • When does it expire?

Was the action generated by

  • HUMAN REQUEST
  • SYSTEM POLICY
  • AI INFERENCE
  • DELEGATED AGENT
  • DISCOVERED CREDENTIAL
  • EXTERNAL SYSTEM
  • UNKNOWN SOURCE

AUTHORITY SOURCE

  • HUMAN GRANTED
  • SYSTEM GRANTED
  • INHERITED
  • DISCOVERED
  • INFERRED
  • UNKNOWN→ HOLD

Unknown authority source should default to HOLD.

Decision provenance →

13 · Expiration

RESEARCH HYPOTHESIS

Authority Decay

Authority should not necessarily remain valid indefinitely.

An AI system that received permission yesterday may not automatically retain it tomorrow.

Authority should have a half-life.

No universal numeric half-life is defined. Expiration is a research hypothesis, not a measured constant.

  • time elapsed
  • environment changed
  • user intent changed
  • destination changed
  • model changed
  • tool changed
  • privilege level changed
  • downstream consequence changed

The idea is adjacent to the Reversibility Clock: remaining time in which an action can still be interrupted. This page does not implement that clock.

Reversibility Clock ↗

14 · Conceptual map

Authority Surface Map

CONCEPTUAL MAP

NOT LIVE SYSTEM DATA

Conceptual placement only. System reach increases upward. Authority depth increases to the right. No telemetry is shown.

System Reach by Authority Depth
Read
Write
Execute
Control
Physical
Critical
External
Internal
Local

System Reach ↑ · Authority Depth →

Select a plotted category to read its placement.

15 · Observation card

THREAT-AUTHORITY-001

ACTIVE OBSERVATION

Capability Is Becoming Authority

Observation

AI systems are increasingly connected to tools, credentials, APIs, infrastructure and physical systems. As these connections expand, model capability can increasingly translate directly into external action.

Interpretation

The risk boundary is moving from model intelligence toward operational authority.

Supervisory relevance

Systems may require runtime intervention before uncertain authority becomes execution.

Boundary

This observation does not establish that autonomous AI systems will inevitably cause catastrophic harm. It examines how operational risk changes as AI systems gain broader authority.

17 · Evidence architecture

Separate the registers

Observed fact, interpretation, hypothesis, and illustrative scenario stay in separate panels.

  • OBSERVED

    AI systems are increasingly being connected to external tools and infrastructure.

  • INTERPRETATION

    External authority may become a more useful risk dimension than model capability alone.

  • HYPOTHESIS

    Authority should expire unless explicitly renewed.

  • ILLUSTRATIVE SCENARIO

    A cybersecurity agent discovers an external credential.

18 · Context

Why This Observation Matters Now

Recent cybersecurity evaluations have shown that advanced AI systems can sometimes discover and use unexpected pathways through networked environments.

These incidents make the distinction between capability and operational authority increasingly important.

The relevant question is not whether an AI system “wanted” to cross a boundary.

The relevant question is whether the surrounding infrastructure allowed the boundary to be crossed.

Citations are taken from the existing Supervisory Layer source record. They are context for the distinction. They are not a reconstruction of the illustrative authority chain, and they are not a claim about motive.

When Agent Populations Require Runtime Supervision →

19 · Supervised transition

Where this sits

This observation informs SHIRO & Co.'s broader work on supervised transitions between observation, inference, decision and action.

The connection runs through ALLOW, HOLD, and DENY, through the Authority Boundary, through human review, and through the passage from observation to proposal. Kosuke Protocol names the same supervisory transition. No separate route for that protocol is recorded in this Observatory.

Who allows AI capability to become authority?

THE QUESTION

Not: How intelligent is the AI?

But: How much of the world can it reach?

Capability becomes consequence only when a system grants authority.

The boundary belongs between the two.