THREAT OBSERVATORY / STRUCTURAL OBSERVATION
THREAT-AUTHORITY-001 / OBSERVATION — ACTIVE / 2026-09-26
OPERATIONAL CONCEPT
Authority Surface
When AI Capability Becomes Real-World Authority
AIの能力が、現実世界の権限になるとき。
AI risk does not depend only on what a model can do.
It also depends on what the surrounding system allows the model to reach.
A model may gain access to networks, credentials, APIs, financial systems, industrial equipment, vehicles, robots or other AI systems.
Each connection expands the surface through which model capability can become real-world action.
This surface is the Authority Surface.
The problem is no longer only what AI can do. The problem is what AI is allowed to reach.
Structural observation. Operational concept. Emerging pattern. Not proven science, and not a quantitative risk score.
Operational concept
Authority Surface
The set of systems, resources, credentials, interfaces, infrastructure, financial mechanisms and physical mechanisms that an AI system is permitted or able to reach.
AIシステムが、到達を許されている、あるいは到達できてしまう、システム・資源・認証情報・インターフェース・基盤・金融手段・物理手段の集合。
03 · Dimensions
Authority Surface Dimensions
ACCESS
What can the AI reach?
- internal files
- databases
- internet
- external APIs
- cloud infrastructure
- operational networks
- third-party systems
PERMISSION
What can the AI change?
- read
- write
- delete
- execute
- authorize
- publish
- transfer
- deploy
PERSISTENCE
For how long can the AI continue acting?
- one request
- one session
- scheduled execution
- autonomous loop
- persistent service
- multi-agent delegation
PROPAGATION
Can one AI action trigger other systems?
- workflow automation
- downstream agents
- financial transactions
- infrastructure changes
- machine commands
REVERSIBILITY
Can the action be undone?
- editable document
- reversible configuration
- financial transfer
- public publication
- machine movement
- infrastructure shutdown
OBSERVABILITY
Can humans see what is happening before consequences propagate?
- audit log
- approval checkpoint
- real-time alert
- delayed review
- invisible background execution
04 · Supervisory Layer
The Supervisory Layer Sits Between Capability and Authority
- AI CAPABILITY
- AUTHORITY REQUEST
- SUPERVISORY LAYERALLOWHOLDDENY
- REAL-WORLD ACTION
The Supervisory Layer is not intended to reduce model intelligence.
Its purpose is to govern the transition from model intention to external consequence.
- A system may allow reasoning while holding execution.
- A model may discover a credential without being allowed to use it.
- A model may identify an external system without being allowed to connect to it.
- A model may prepare an action without being allowed to execute it.
This separation is fundamental.
- ALLOW
Execution may proceed within the current grant.
- HOLD
Execution is interrupted. Context is preserved for review.
- DENY
Execution is refused.
05 · Unresolved authority
HOLD Before DENY
Many AI governance systems assume binary permission: ALLOW or DENY.
Uncertainty often appears before a violation is fully known.
SHIRO & Co. uses ALLOW, HOLD, and DENY.
HOLD is the supervisory state for unresolved authority.
HOLD is not rejection.
HOLD interrupts execution while preserving context for review.
- UNKNOWN DESTINATIONHOLD
- NEW CREDENTIAL DISCOVEREDHOLD
- THIRD-PARTY SYSTEM DETECTEDHOLD
- PRIVILEGE ESCALATION REQUESTHOLD
- PHYSICAL ACTUATION REQUESTHOLD
- IRREVERSIBLE ACTIONHOLD
- HIGH-CONSEQUENCE ACTIONHOLD
- UNKNOWN DOWNSTREAM EFFECTHOLD
08 · Physical layer
When Authority Reaches the Physical Layer
Authority Surface becomes especially important when AI actions leave software environments.
- robot motion
- industrial machinery
- warehouse systems
- autonomous vehicles
- drones
- energy systems
- building control
- logistics
- medical devices
A software mistake can become a physical event.
Can the model generate the command?
Who authorizes the command to become motion?
09 · Structural model
The Real Risk Relation
STRUCTURAL MODEL
NOT A QUANTITATIVE RISK EQUATION
REAL-WORLD AI RISK
CAPABILITY
ACCESS
AUTHORITY
PERSISTENCE
Structural model, not a quantitative risk equation. Real-world AI risk is approximated by capability, access, authority, and persistence.
Limiting layers
- SUPERVISION
- REVERSIBILITY
- OBSERVABILITY
These act as limiting layers.
- Capability↑
- Authority↑
- Persistence↑
- Consequence potential↑
- Capability
- What the AI can reason about, generate, discover or execute.
- Access
- What systems, networks, APIs, tools and data the AI can reach.
- Authority
- What actions the AI is permitted to take.
- Persistence
- Whether the AI can continue acting across time, sessions, systems or environments.
A supervisory model for comparing dimensions. It does not produce a score.
10 · Research questions
Questions for Observation
- 01When does tool access become operational authority?
- 02When does credential discovery become permission?
- 03When should a system move from ALLOW to HOLD?
- 04How long should autonomous authority persist?
- 05Which actions must always require human review?
- 06Can high-consequence actions remain reversible?
- 07How quickly can supervision intervene?
- 08Can downstream systems distinguish human authority from AI-derived authority?
- 09When one AI delegates to another AI, does authority expand automatically?
- 10Can an AI inherit permissions that were originally granted to a human?
- 11What happens when temporary access becomes persistent authority?
- 12Where should authority expire?
12 · Provenance
Authority Needs Provenance
Systems should record not only: What action occurred?
- Who granted authority?
- Where did the permission originate?
- Was the authority direct or inherited?
- When was it granted?
- When does it expire?
Was the action generated by
- HUMAN REQUEST
- SYSTEM POLICY
- AI INFERENCE
- DELEGATED AGENT
- DISCOVERED CREDENTIAL
- EXTERNAL SYSTEM
- UNKNOWN SOURCE
AUTHORITY SOURCE
- HUMAN GRANTED
- SYSTEM GRANTED
- INHERITED
- DISCOVERED
- INFERRED
- UNKNOWN→ HOLD
Unknown authority source should default to HOLD.
Decision provenance →15 · Observation card
THREAT-AUTHORITY-001
ACTIVE OBSERVATION
Capability Is Becoming Authority
Observation
AI systems are increasingly connected to tools, credentials, APIs, infrastructure and physical systems. As these connections expand, model capability can increasingly translate directly into external action.
Interpretation
The risk boundary is moving from model intelligence toward operational authority.
Supervisory relevance
Systems may require runtime intervention before uncertain authority becomes execution.
Boundary
This observation does not establish that autonomous AI systems will inevitably cause catastrophic harm. It examines how operational risk changes as AI systems gain broader authority.
17 · Evidence architecture
Separate the registers
Observed fact, interpretation, hypothesis, and illustrative scenario stay in separate panels.
OBSERVED
AI systems are increasingly being connected to external tools and infrastructure.
INTERPRETATION
External authority may become a more useful risk dimension than model capability alone.
HYPOTHESIS
Authority should expire unless explicitly renewed.
ILLUSTRATIVE SCENARIO
A cybersecurity agent discovers an external credential.
18 · Context
Why This Observation Matters Now
Recent cybersecurity evaluations have shown that advanced AI systems can sometimes discover and use unexpected pathways through networked environments.
These incidents make the distinction between capability and operational authority increasingly important.
The relevant question is not whether an AI system “wanted” to cross a boundary.
The relevant question is whether the surrounding infrastructure allowed the boundary to be crossed.
Citations are taken from the existing Supervisory Layer source record. They are context for the distinction. They are not a reconstruction of the illustrative authority chain, and they are not a claim about motive.
When Agent Populations Require Runtime Supervision →- Hugging Face — Security incident disclosure, July 2026 ↗
- Hugging Face — Anatomy of a Frontier Lab Agent Intrusion: technical timeline ↗
- OpenAI — The Hugging Face incident and the road ahead ↗
- METR / Redwood — Brief independent investigation of agents’ behavior, reasoning and collaboration ↗
- Reuters — Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week (24 Jul 2026) ↗
19 · Supervised transition
Where this sits
This observation informs SHIRO & Co.'s broader work on supervised transitions between observation, inference, decision and action.
The connection runs through ALLOW, HOLD, and DENY, through the Authority Boundary, through human review, and through the passage from observation to proposal. Kosuke Protocol names the same supervisory transition. No separate route for that protocol is recorded in this Observatory.
Who allows AI capability to become authority?
THE QUESTION
Not: How intelligent is the AI?
But: How much of the world can it reach?
Capability becomes consequence only when a system grants authority.
The boundary belongs between the two.