AcquireBound: Runtime Authorization for Resources Acquired by AI Agents
| Source: arXiv AI
Tags: AI agents, security, MCP, runtime authorization, agentic systems, AI safety
AcquireBound is a runtime authorization architecture that quarantines all resources acquired by AI agents — compute, credentials, OAuth tokens, other agents — and activates them only after provenance verification, proving 8 safety properties and rejecting 40/40 unsafe traces in empirical tests.
Details
A persistent gap in agentic AI security is the post-fulfillment activation gap: payment, OAuth, and budget checks validate transaction conditions but don't govern what the returned resource can actually do. An agent that purchases compute or receives delegated credentials could amplify its own authority in ways no human approved. AcquireBound addresses this with a provenance-bounded runtime. Acquired outputs are quarantined; capabilities are resolved from authenticated provider evidence through a versioned resolver; activation proceeds only through a current activation transaction that checks a resolved manifest, provenance epochs, and a downward-closed relational envelope over a typed resource-capability hypergraph. Eight formal safety properties are proved: quarantine, backing, non-amplification, split non-evasion, crash/retry, refunds, epochs, and effect confinement. Empirically, reference semantics accepted 20/20 benign traces and rejected 40/40 unsafe traces over 810 events; an independent checker agreed on 100 traces and rejected 89/89 tamper tests. Frozen Codex and Gemini MCP client components completed 54/54 deterministic local calls. In an 18-case MCP-to-Docker composition, both benign paths completed and none of 16 unsafe paths added an unauthorized Docker start. This is a preprint (single author), but the formal apparatus and empirical coverage are extensive. As MCP and agentic systems become standard, provenance-aware authorization becomes critical for enterprise deployments.