AI agents turn language into actions. That makes identity, delegated authority, tool permissions, and execution integrity part of the security boundary—not implementation details.
Start here
- Trust Is the Next Bottleneck explains why authorization alone cannot establish that an agent is running the expected code.
- AI Agents Have an Identity Crisis examines verifiable delegation across multi-agent workflows.
- MCP Is a Capability System provides the practical permission model.
- Hardening MCP Servers with Confidential Computing addresses the infrastructure trust boundary around tool credentials.
- Google’s AP2 Protocol applies these ideas to agent-initiated commerce.
Together, these essays describe a security model built from bounded authority, measured execution, and evidence that survives every hop.