Authentication and Authorization for AI Agents and Risks Involved

Ravitheja Chinni · 2025

Enterprises are quickly transforming workflows through AI agents, autonomous software agents that make real-time decisions but now poorly suited to securing them. The existing systems of authentication and authorization, including OAuth 2.0 Client Credentials, mTLS, and RBAC/ABAC, do provide a basis but do not reflect the autonomy inherent in and behavioural unpredictability of AI agents and the challenges of their delegation. In this paper, the author critically looks at novel technologies and architectures aimed at agentic identity assurance. Authenticated delegation models were compared, including the extensions of the OAuth/OIDC standard by MIT, that support limited human delegation and the possibility of auditing the actions of agents. Industry solutions such as Auth0 for GenAI were examined, which combines and contrasts a Token Vault and asynchronous human-in-the-loop approval pipelines. Ephemeral authentication was also examined, where short-duration and contextspecific identity is proclaimed by the Cloud Security Alliance, used through AWS STS and GCP service-service impersonation. Beyond token models, the article also exemplified the fine-grained authorization (ABAC, policy-based RBAC) and continuous behavioural verification where trust is dynamically stepped up or down depending on the pattern observed at run-time. These models are promising, although still at an early stage; there is a need to have wider standardization, interoperability and enterprise readiness.

Read the paper · More papers on PaperTik