Skip to content
Preprint

Authority-Inference Separation in Agentic Finance: First-Line Control, Blockchain Enforcement, and Replayable Assurance

Aug 2026 · 1 citation · 40 references
Economics Computer Science

TL;DR

This study develops and evaluates Authority-Inference Separation (AIS), an intent-centered architecture for bounded agentic finance that decides whether a specific intent may act, while blockchain can make granted authority bounded, executable, and independently observable.

Abstract

AI agents can select tools, counterparties, and transaction parameters, yet inference should not itself confer authority to execute a financial action. This study develops and evaluates Authority-Inference Separation (AIS), an intent-centered architecture for bounded agentic finance. AIS treats a financial action intent as the control object: a machine-generated proposal can receive temporary executable authority only after an independent deterministic control plane validates registered agent identity, accountable ownership, mandate and risk-appetite lineage, policy version, state, approvals, and exact economic semantics. Blockchain can then enforce the operational representation of granted authority and record portable settlement evidence, while institutional legitimacy, service delivery, accounting classification, and human accountability remain off-chain obligations. Evaluation combines four-domain instantiation, official BIS and MAS cases, a 48-fixture executable prototype, and a public-ledger observability test. Across 36 synthetic authorization attacks, a direct-agent baseline accepted 36 attack effects, a prompt-policy baseline accepted 20, and AIS accepted none; all three accepted 8/8 admissible fixtures. AIS also rejected 4/4 token replays and 8/8 recipient or rail substitutions, withheld completion in 4/4 service-delivery failures, and populated all 13 defined evidence fields. A test of 1,700 recent Base transactions associated with public x402 facilitator addresses shows that public ledgers can evidence settlement and selected authorization parameters but cannot establish institutional mandate, legal accountability, service delivery, or accounting treatment. AIS and blockchain are therefore complementary: AIS decides whether a specific intent may act, while blockchain can make granted authority bounded, executable, and independently observable.

View source

Similar papers

Review Aug 2026

Context Is Not Authority: Structured Runtime Governance for Financial Market Agents

SAGE-Fin is presented, a finance-specific authority-handoff contract that makes the proposed effect, not merely its text, the object of runtime control, and its results establish executable conformance, not independent safety accuracy.

Rui Tang, Qiang Liu, Yi-Chi Zhang et al. · 1 citation
Preprint Sep 2026

A Black Box for Agentic Processes: Blockchain-Anchored Evidence for AI Agent Communication, Human Oversight, and GRC Audits

A product- and vendor-neutral black-box architecture for agentic processes that creates blockchain-anchored cryptographic commitments for selected agent communications, human-in-the-loop approvals, tool calls, and process artifacts without placing sensitive content on-chain.

A. Brömme · 3 citations
Preprint Aug 2026

PACE: Policy-Attested Contract Execution for Safe AI Agents in Decentralized Finance

PACE (Policy-Attested Contract Execution), a transaction-level authorization framework that interposes between an LLM-based agent and on-chain execution, is presented and frame its claims as logic-level safety within a reproducible benchmark rather than deployment-ready DeFi security.

Rabimba Karanjai, Yang Lu, Richard Williamson et al. · 1 citation
Open access 2026

Expressible, Advisory, or Unenforceable: A Conformance Analysis of Delegated Financial Authority in Deployed Agent-Payment Protocols

This paper defines an authorization envelope of eight fields drawn from the delegated-authority literature and from the control primitives of existing payment rails, comprising a per-transaction ceiling, a cumulative ceiling, a merchant set, a category set, required product attributes, a validity window, a substitution...

Ian Staley · 0 citations
Open access Sep 2026

Runtime Policy Firewall: A Zero-Trust Governance Layer for Enterprise Agentic AI

Enterprise adoption of generative AI is shifting from passive question answering to autonomous agentic execution. Modern agents can decompose goals, retrieve business context, call tools, update records, send messages, initiate transactions, and coordinate workflows across multiple systems. This creates productivity op...

Swapneswar Ray · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.