New Access Control Secures AI Agents in Critical Infrastructure

Arun Malik, Deepal Jayasinghe, Bradley Klemick, Prachi Shah, Nitish Talasu, Vineet Tushar Trivedi· July 28, 2026 View original

Summary

This paper introduces a decentralized, multi-layered access control architecture designed for autonomous AI agents in critical cloud infrastructure. It addresses security challenges posed by AI's stochastic behavior, offering granular permissions and a compound identity model to prevent unauthorized operations.

Deploying autonomous AI agents in critical infrastructure presents significant security hurdles, as their unpredictable nature makes traditional access control models inadequate. This research proposes a novel, decentralized, and multi-layered access control framework specifically tailored for these agentic AI systems operating within cloud environments. The architecture is designed to mitigate risks identified in the OWASP Top 10 for LLM Applications. Key innovations include a compound identity model that links agent actions to human authority, a hierarchical permission system with five levels of granularity, and a decentralized policy ownership model allowing tool teams to manage their own authorization boundaries. The system also incorporates progressive trust escalation with safety interlocks to prevent high-risk autonomous operations. This framework has been successfully deployed in production at a major cloud provider, managing network infrastructure with zero unauthorized write operations over eight months, demonstrating its effectiveness in securing AI agents.

Why it matters

As AI agents gain autonomy in critical systems, robust and granular access control is paramount to prevent security breaches, ensure compliance, and maintain operational integrity.

How to implement this in your domain

  1. 1Evaluate current access control models for AI agents against the proposed decentralized, multi-layered framework.
  2. 2Implement a compound identity model that links agent actions to human oversight and accountability.
  3. 3Develop hierarchical permission systems with fine-grained controls for AI agent interactions with critical resources.
  4. 4Explore decentralized policy ownership to empower tool teams in managing their specific authorization boundaries.
  5. 5Integrate safety interlocks and progressive trust escalation for high-risk AI agent operations.

Who benefits

Critical InfrastructureCloud ComputingCybersecurityTelecommunicationsEnergy

Key takeaways

  • Traditional access control models are insufficient for securing autonomous AI agents due to their stochastic nature.
  • A new decentralized, multi-layered architecture offers granular control and links agent actions to human authority.
  • The framework includes hierarchical permissions, decentralized policy ownership, and safety interlocks.
  • Successful production deployment demonstrates its effectiveness in preventing unauthorized operations in critical infrastructure.

Original post by Arun Malik, Deepal Jayasinghe, Bradley Klemick, Prachi Shah, Nitish Talasu, Vineet Tushar Trivedi

"arXiv:2607.22611v1 Announce Type: new Abstract: The deployment of autonomous AI agents in production infrastructure introduces fundamental security challenges that traditional role-based access control (RBAC) models cannot address. Unlike deterministic automation, AI agents exhib…"

View on X

Originally posted by Arun Malik, Deepal Jayasinghe, Bradley Klemick, Prachi Shah, Nitish Talasu, Vineet Tushar Trivedi on X · view source

Want to go deeper?

Turn these trends into skills with Learnijoy's hands-on AI & tech courses.

Explore courses