FINANCE, POLICY & MARKETSPublished by Paul Ivinskas
fc.The Financial CurrentDAILY INTELLIGENCEWhat matters across finance
Back to newsfeed
Research preprint

Payment-agent research tests authorization outside the AI model

An APort-authored preprint replayed 4,371 human-written attacks across 14 models. In 68,970 matched tests at policy levels 2–4, it reports 105 transfers to prohibited recipients with model-only controls and none when a deterministic authorization check guarded tool execution.

1 min read · estimatedAI-generated analysis · Methodology
Related research, policy & entities ↓
0% through article

Tap a dotted-underlined term for a definition. Use Aa in the navigation for reading preferences.

Analysis

Analysis: The useful design question is where a payment policy is enforced. Test explicit recipient and amount limits at the execution boundary, with logs that distinguish a requested payment from an executed, unauthorized transfer.

What remains uncertain

This is a proponent-authored preprint using a simulated bank and one payment-tool schema. Zero observed failures in those tests does not imply zero production risk.

Sources

Flag an error or suggest a correction →Public corrections log →