NeFut Logo NeFut
中 Admin Login

[CS.AI] Subjects, Not Authors: The Authorship Hazard in Agentic Dataspaces

Published at: 2026-09-29 22:00 Last updated: 2026-09-30 01:41
#algorithm #AI #LLM

Dataspace connectors decide whether a transfer may occur, without inspecting the transferred value. This is acceptable for contracted applications but breaks for LLM agents that compose tool calls and spawn sub‑agents. Existing work evaluates the quality of governance artifacts generated by agents, yet it does not specify who may authorize those artifacts, leaving a gap between governance literature and agent literature.

A published policy is essentially a governance event enforced at a dataspace decision point. If an agent is both the subject and the author of that policy, it writes the norms that bind itself. We call this the authorship hazard and state a principle: an agent is a subject of the governance plane, never an author. Its authorization channel to publication is deliberately closed; its influence channel—drafting documents for human approval—is treated as an enforcement problem.

On a frozen corpus of agent drafts, publishing without approval reverses 80 authorization decisions, most of which involve only a change in a field’s sensitivity classification while leaving the policy text untouched. A classifier that reads the policy diff misses every such draft, which is inevitable. Treating classification as authorship routes all these drafts to review; we design and model the required registry‑held classification, though it is not yet implemented in the prototype.

At the execution boundary, protected fields reach the model in 105 of 105 cases when duties are stated in the prompt, but in 0 of 105 cases when an ODRL duty is compiled into an invocation‑time tool‑call constraint. However, if the value is not confined to a named field, the compiled condition exposes it in 7 of 7 cases. A centrally provisioned approval pool does not scale to the participant volume that motivates the problem.

Review: The paper convincingly argues that agents must be treated as governance subjects rather than authors and demonstrates, via experiments, the risks of unauthorized publication. The proposed classification‑to‑review pipeline offers a practical route toward secure agent governance.

Original Source: https://arxiv.org/abs/2609.30614

[h] Back to Home