A Zenodo paper distinguishes checking an agent’s access from proving that each regulated action followed the right policy.
The paper examines agentic AI systems that can write to databases, submit regulatory filings or execute transactions. It distinguishes access authorization—checking who an agent is and what it can access—from action authorization: showing that a particular output complied with the applicable policy version at the time it was released.
It identifies an “authorization artifact gap” when monitoring or access controls are treated as substitutes for advance authorization evidence. The paper describes requirements for an authorization boundary, including a repeatable decision, a binding to the relevant policy version, evidence issued before execution, and confirmation that the approved state and action remain valid at release.
What gateways do not prove
The authors argue that an AI gateway or MCP-based system does not, by its label alone, establish that an agent’s regulated action was authorized. Such systems may address interoperability, traffic management, identity and operational control without producing a record that lets an independent reviewer reconstruct the specific authorization decision.
The paper says a compliant authorization boundary should produce a pre-execution verdict that can be independently reconstructed from the artifact and its authenticated supporting materials. It also sets out requirements for repeatable evaluation, links to the governing policy and its version, issuance before execution, and fresh state at release. A release check can validate a completed authorization artifact, the paper says, but cannot replace one. Whether a gateway participates in authorization depends on its demonstrated design and the effects it covers, not its product name.
Why the authorization record matters
For organizations using AI agents in regulated work, showing that an agent had access may not be enough to show that its particular action was allowed. The paper’s distinction directs attention to evidence that can be reviewed after the fact while still being created before execution.
Its framework gives infrastructure architects, compliance officers and policymakers a vocabulary for examining whether an AI deployment can stop unresolved decisions, identify who owns the decision, preserve the relevant policy and inputs, and support independent replay. It does not say that gateways are incapable of authorization; it says their role must be demonstrated against the applicable requirements.
Evidence and limits
This is a conceptual and governance article deposited in Zenodo, not an empirical study reporting tests of particular gateways, agents or regulated actions. The abstract reports no experiments, performance measurements or case-study results. Its requirements and evaluation frameworks therefore describe how authorization evidence could be assessed rather than demonstrating that a particular implementation meets them.
The paper also states that its four implementation requirements are not, by themselves, a complete test. Completeness depends on the wider evidence framework and on the declared system topology, covered effects, policy state and replay conditions. The abstract identifies Version 3.0.0, published in August 2026, as superseding Version 2.0.
// Source
Zenodo (CERN European Organization for Nuclear Research) · 2026 · DOI: 10.5281/zenodo.18612065
Authors: Edward Meyman
Institutions: Ferghana Polytechnical Institute, Ferro (United States)