Source-linked AI summary
Authority-Inference Separation in Agentic Finance: First-Line Control, Blockchain Enforcement, and Replayable Assurance
Hui Gong, Michail Samawi, Francesca Medda
TL;DR
Agentic finance lacks a reliable separation between probabilistic inference and authority to execute financially consequential actions. This paper develops and evaluates AIS, an intent-centered control architecture that validates authority independently before execution and uses blockchain to enforce and observe granted scope. Across its fixed prototype fixtures, AIS prevented represented unauthorized effects while preserving admissible execution and evidence, but the evaluation remains an architecture-mechanism test rather than evidence of production effectiveness.
Problem
Agentic finance needs to prevent probabilistic inference from conferring authority to execute financially consequential actions while preserving accountability and auditability.
Method
AIS makes a typed financial action intent the control object and uses an independent deterministic control plane to validate identity, ownership, mandate, policy, state, approvals, and economic semantics before execution.
Results
Across 48 fixed prototype fixtures, AIS accepted all admissible cases, prevented all represented authorization, replay, and substitution effects, retained all 13 defined evidence fields, and detected every represented service-delivery break.
Takeaways & Limitations
AIS separates adaptive inference from executable financial authority, while blockchain can enforce approved authority and independently evidence selected authorization fields and settlement.
Takeaways & Limitations
The prototype is a deterministic architecture-mechanism test without live models, production keys, concurrency, adaptive attacks, or implementation-vulnerability testing.
Abstract
from arXiv · showhide
AI agents can select tools, counterparties, and transaction parameters, yet inference should not itself confer authority to execute a financial action. This study develops and evaluates Authority-Inference Separation (AIS), an intent-centered architecture for bounded agentic finance. AIS treats a financial action intent as the control object: a machine-generated proposal can receive temporary executable authority only after an independent deterministic control plane validates registered agent identity, accountable ownership, mandate and risk-appetite lineage, policy version, state, approvals, and exact economic semantics. Blockchain can then enforce the operational representation of granted authority and record portable settlement evidence, while institutional legitimacy, service delivery, accounting classification, and human accountability remain off-chain obligations. Evaluation combines four-domain instantiation, official BIS and MAS cases, a 48-fixture executable prototype, and a public-ledger observability test. Across 36 synthetic authorization attacks, a direct-agent baseline accepted 36 attack effects, a prompt-policy baseline accepted 20, and AIS accepted none; all three accepted 8/8 admissible fixtures. AIS also rejected 4/4 token replays and 8/8 recipient or rail substitutions, withheld completion in 4/4 service-delivery failures, and populated all 13 defined evidence fields. A test of 1,700 recent Base transactions associated with public x402 facilitator addresses shows that public ledgers can evidence settlement and selected authorization parameters but cannot establish institutional mandate, legal accountability, service delivery, or accounting treatment. AIS and blockchain are therefore complementary: AIS decides whether a specific intent may act, while blockchain can make granted authority bounded, executable, and independently observable.
1 Introduction
Agentic finance turns probabilistic model outputs into potentially consequential actions, creating a need to separate inference from determinate execution authority. AIS addresses this gap by controlling a financial action intent through independent validation and by dividing authority, execution, and assurance responsibilities across institutional and technical layers.
- Agent workflows can transform model outputs into asset transfers, contractual events, limit consumption, or accounting consequences, making accountability and operational resilience central governance questions.
- Inference is probabilistic, but financial execution systems require binary decisions about mandate, eligibility, approval, finality, and record creation.
- AIS scopes first-line preventive control to codifiable checks while preserving institutional ownership, exception paths, and evidence for independent monitoring and assurance.
- AIS makes the financial action intent the control object: a machine-generated proposal is evaluated, bound to temporary authority, reconciled with delivery, and replayed for assurance.
- Blockchain can enforce selected operational representations of granted authority and settlement, but mandate legitimacy, delivery, accounting treatment, and accountability remain off-chain obligations.
- The study evaluates AIS through requirements traceability, cross-domain instantiation, official cases, executable fixtures, and a public-ledger observability test.
2 Related Work and Theoretical Foundations
Related work supplies foundations in agent action, internal control, reference monitoring, model governance, and blockchain execution, but does not by itself define the agent-generated financial object requiring bounded authority and replayable assurance. AIS integrates these foundations around a typed financial action intent and an accounting-grade evidence chain while retaining institutional accountability outside the mechanism.
- Agentic systems can transform goals and observations into financially consequential intents affecting assets, contracts, limits, pricing, approvals, accounting entries, or service procurement.
- The relevant accounting object is a delegated decision chain linking mandate, FAI, model and tool versions, control evaluation, approval, execution, service receipt, accounting map, and reconciliation.
- Pre-action evidence explains admissibility, while post-action evidence records execution, settlement, service delivery, accounting classification, reconciliation, and exceptions.
- AIS is a first-line preventive control whose evidence bundle supports second-line monitoring and deterministic replay without transferring audit responsibility into the system.
- AIS adapts reference-monitor and least-privilege principles by deciding whether a specific typed FAI receives temporary executable authority under current mandate and policy state.
- Blockchain can enforce deterministic state transitions and operational AIS decisions, while introducing smart-contract, key-management, privacy, concentration, and finality risks.
- AIS controls whether a particular FAI acquires temporary executable authority and whether its decision and outcome can be independently reconstructed.
3 Research Method
The study uses design science to construct and evaluate AIS through requirements synthesis, cross-domain cases, executable fixtures, and public-ledger observability. The evaluation isolates architecture mechanics rather than production effectiveness or causal institutional outcomes.
- Design and evaluation strategy: The study follows design science through problem identification, objective definition, artifact construction, demonstration, and evaluation.The artifact includes the FAI, formal invariants, a governed five-plane architecture, evidence and handoff objects, a taxonomy, and a deterministic prototype.
- Design and evaluation strategy: Five evidence forms test conceptual fit, generality, institutional relevance, specified control mechanisms, and independently observable evidence boundaries.The forms are requirements traceability, cross-domain instantiation, official cases, executable fixtures, and public-ledger analysis.
- Requirements and artifact: The synthesis produced eight requirements covering non-standing inference authority, registered identity, governance lineage, complete mediation, and bounded authorization.The supplied passage begins the requirement list and explicitly states the first four requirements' themes.
- Requirements and artifact: The prototype tests transaction-time portions of Requirements 1 and 4–8 under fixed fixtures, while substantive institutional fitness remains untested.Accountable-owner fitness, appetite, model, monitoring, audit, and attestation are treated as institutional requirements and handoffs.
- Executable evaluation: The fixture population contains 48 fixtures across four financial domains and twelve scenarios, producing 144 architecture–fixture results.The primary denominator is 36 authorization attacks; secondary denominators cover admissible fixtures, replays, substitutions, and service-delivery failures.
- Evaluation boundary: The evaluation does not call a live language model or estimate empirical attack probability, and the prompt-policy baseline is a specified research implementation.Exact zero or one rates are expected when a tested mechanism is mandatory or structurally absent.
- Public-ledger observability: The public-ledger module analyzes 1,700 address–transaction rows filtered for successful Base USDC authorization transfers.The test asks which AIS evidence objects public records can verify, not whether they prove autonomous-agent adoption.
4 Authority–Inference Separation
AIS makes the financial action intent the object of control, separating adaptive reasoning from deterministic authorization and execution. Its architecture binds temporary authority to exact intent semantics while retaining institutional governance, fail-closed operation, and replayable evidence.
- 4.1 The Financial Action Intent as the Object of Control: AIS requires an adaptive agent to emit a financial action intent that converts natural-language planning into typed economic semantics.The FAI retains institutional origin, input provenance, and evidence expectations; production schemas would add domain-specific fields and validation rules.
- 4.1 The Financial Action Intent as the Object of Control: Identity and accountability are separate: credentials identify the acting actor, while registered identity, accountable ownership, and approving bodies establish delegated-authority context.Neither an agent identifier nor a key becomes a legal person.
- 4.2 Formal Decision and Architecture Invariants: Model rationale remains descriptive and probabilistic, whereas the control-decision record is deterministic, reproducible from pinned inputs, and authoritative for authorization outcomes.The decision record should emit a reason code for every denial and escalation.
- 4.2 Formal Decision and Architecture Invariants: The independent control function returns either a scoped authorization token or denial after evaluating governance linkage, mandate, policy, input quality, state, and required human approval.The governance linkage includes registered identity, accountable owner, mandate approval, and appetite lineage.
- 4.2 Formal Decision and Architecture Invariants: Execution requires an authentic, unexpired, unused token bound to the canonical intent hash, and accepted execution atomically consumes its nonce.These rules make authority scoped, short-lived, single-use, and tied to the exact FAI.
- 4.2 Formal Decision and Architecture Invariants: The seven invariants require separation of inference and authority, explicit institutional lineage, exact-intent binding, complete mediation, bounded authority, deterministic reason records, and replayable evidence.They are design obligations rather than mathematical proof that an implementation, attestation, or policy is correct.
- 4.3 Five-Plane Reference Architecture: Figure 1 separates adaptive reasoning from state-changing components, with typed artifacts crossing execution boundaries and unstructured explanations unable to substitute for an FAI.The architecture assigns codifiable first-line control to AIS while leaving institutional governance and other obligations outside that path.
- 4.3 Five-Plane Reference Architecture: Every execution adapter validates AIS tokens independently, while the meta-control layer governs control changes, revocation, upgrades, key custody, and in-flight tokens.A blockchain adapter additionally checks intent hash, identity, mandate, policy, scope, expiry, recipient, asset, rail, and nonce.
5 Cross-Domain Validation
AIS is instantiated across cross-organizational and tokenised workflows while remaining independent of any single settlement rail. Official cases support relevance to programmable compliance and settlement, but do not establish adoption or effectiveness.
- 5.1 Financial-Domain Instantiation: The blockchain adapter applies the same FAI across rails by verifying scope, constraining state transitions, settling assets, and exporting portable receipts.Table 4 assigns domain-specific semantics to FAI, authority, human-governance, and evidence objects.
- 5.1 Financial-Domain Instantiation: Table 4 presents AIS instantiation across financial domains, mapping the architecture’s control and evidence objects to domain-specific semantics.The supplied passages identify the table's cross-domain purpose rather than its individual rows.
- 5.2 Comparative Case Mapping: Official BIS and MAS cases support the relevance of programmable compliance, tokenised obligations, and shared settlement while leaving institutional and legal controls outside the ledger.The cases are mapped to AIS without treating them as proof of adoption or effectiveness.
- 5.2 Comparative Case Mapping: The comparative case mapping is bounded evidence: it connects documented workflows to AIS without claiming institutional adoption or control effectiveness.The interpretation is explicitly limited by the case evidence.
6 Blockchain Execution and Public-Ledger Evidence Test
The public-ledger test finds that blockchain can independently verify selected authorization semantics and settlement state, while institutional mandate, accountability, delivery, and accounting remain off-chain evidence obligations.
- Sample profile: 1,193 transactions met the EIP-3009 candidate rule from 1,700 deduplicated Base transactions, but the sample is non-random and not a population estimate.The candidate sample totaled USD 470.866, with a median transaction value of USD 0.10 and a maximum of USD 25.00.
- On-chain assurance: Independent observers can verify successful inclusion, ordering, contract and method, payer, recipient, amount, validity bounds, nonce, and receipt from public records.These fields can show whether execution matched the authorization placed before the adapter.
- On-chain assurance: Selected authorization semantics and resulting settlement state can be checked independently and linked by hash to an AIS decision bundle.On-chain registry or approval representations demonstrate configured state, not the legitimacy of their institutional source.
- Off-chain evidence boundary: A chain receipt complements rather than replaces pre-action mandate, policy, accountability, and delivery evidence.The evidential hierarchy requires additional evidence from facilitator activity through authorization, settlement, agent initiation, counterparties, and delivered service.
7 Executable Prototype Evaluation
The executable prototype tests whether separating deterministic authorization from adaptive inference makes specified attack effects nonexecutable and preserves evidence for independent reconstruction. AIS blocked the tested unauthorized effects without falsely blocking admissible fixtures, while service-delivery failures remained unreconciled rather than complete.
- Metrics and validity boundary: The prototype counts unauthorized execution only when manipulated or replayed effects are accepted in 36 authorization-attack fixtures.Replay attacks count only the second use, substitutions mutate the recipient or rail after the initial check, and unsafe completion occurs despite missing service delivery.
- Metrics and validity boundary: Evidence completeness covers 13 equally weighted fields, measuring schema completeness rather than evidence truth, policy legitimacy, or institutional audit quality.The fields span canonical intent, identity, mandate, appetite, policy, inputs, decision, authorization, execution, reconciliation, and replay records.
- Results: AIS rejected all tested unauthorized effects, while direct access accepted every authorization attack effect and the prompt-policy baseline accepted stale-policy, injection-override, substitution, and replay effects.All configurations accepted all eight admissible fixtures; AIS used exact intent binding, active policy, and nonce state outside the inference path.
- Results: In 4/4 service-delivery failures, direct-agent and prompt-policy workflows marked completion, whereas AIS marked 0/4 complete and retained a reconciliation break.The break retained age, escalation threshold, provisioning status, and named write-off authority; these one-period fixtures do not estimate operational ageing or escalation rates.
- Validity boundary: The experiment demonstrates an executable mapping from invariants to observable outcomes and machine-readable records, not a real-world security-incidence estimate.The authors do not claim that every prompt control has a 55.6% failure rate or that every AIS implementation achieves zero failures.
8 Discussion
AIS separates probabilistic inference from executable financial authority, while blockchain enforces selected operational controls and exposes settlement evidence without replacing institutional governance. The discussion emphasizes conditional assurance, explicit boundaries, and substantial prototype and field-evaluation limitations.
- AIS and assurance: AIS binds machine-generated financial action intents to identity, ownership, mandate lineage, policy, approvals, state, and exact economic semantics.Its evidence bundle spans authorization, execution, delivery, accounting, and replay.
- Assurance boundaries: Replay can test conformance for a covered population, but it does not establish that the policy was defensible or that off-system activity is absent.Coverage requires population-boundary checks and reconciliation between execution endpoints and evidence records.
- Assurance boundaries: Blockchain receipts independently evidence selected execution and settlement facts but do not establish institutional rights, approval, valuation, accounting presentation, or delivered consideration.Ledger visibility is therefore an incomplete assurance object.
- Blockchain’s role: Blockchain can enforce nonce-bound state transitions, expose settlement evidence, carry cross-organizational receipts, and encode selected governance representations.Examples include quorum approval, time-locks, eligible approvers, and policy-version hashes.
- Public-ledger evidence: The non-random public-ledger sample characterizes observable execution evidence and institutional boundaries, not adoption rates or delivered demand.Public addresses cannot reveal legal identity, commercial relationships, agent control, or delivery.
- Limitations: The prototype is a deterministic architecture-mechanism test without live models, production keys, concurrency, compromise, or implementation-vulnerability testing.The authors call for adaptive attacks, multiple models, property-based testing, concurrency, key compromise, policy change, and independent red-team implementations.
- Limitations: AIS covers codifiable first-line preventive control, while model fitness, compliance judgment, audit, statistical monitoring, and third-party inference-provider risks remain separate.The FAI and deterministic policy may still be wrong, stale, incomplete, or discriminatory.
9 Conclusions
The paper positions AIS as a codifiable first-line control that migrates selected governance checks from humans to agents or contracts while retaining institutional accountability. Across its fixed prototype fixtures, AIS prevented represented authorization, replay, substitution, and service-delivery effects, though the results demonstrate harness mechanics rather than production effectiveness.
- 9 Conclusions: AIS separates adaptive inference from executable financial authority and binds typed intents to institutional control fields and reproducible authorization reasons.Independent validation, monitoring, audit, and legal accountability remain with their institutional owners.
- 9 Conclusions: Across 48 fixed prototype fixtures, AIS accepted all admissible cases while preventing all represented authorization, replay, and substitution effects.The implementation retained all 13 defined evidence fields and detected every represented service-delivery break.
Abbreviations
This section defines the manuscript’s principal abbreviations and summarizes reporting disciplines for reproducibility, metric interpretation, and separation of observable activity from stronger institutional claims.
- Abbreviations: AIS means Authority–Inference Separation; FAI means Financial action intent; IAM means Identity and access management; RBAC means Role-based access control.The abbreviation list also defines AI, EIP, FX, SoD, and USDC.
- Reporting discipline: Reproducibility requires preserving source, retrieval, transformation, code, fixture, and checksum information while reporting populations, exclusions, numerators, denominators, and configuration mechanisms.These requirements support auditable interpretation of the executable and ledger analyses.
- Reporting discipline: Interpretation must distinguish mechanism-test outcomes from language-model performance, institutional effectiveness, real-world attack prevalence, and the different meanings of facilitator activity and delivered service.Latest-activity samples must not be compared directly with population metrics.
C Conventional Control Environment Mapped to AIS
The conventional control environment is mapped to AIS’s first-line transaction-time scope and to institutional handoffs across the governance lifecycle. AIS produces evidence and replayable decisions, while independent functions retain monitoring, assurance, legitimacy, and responsibility for residual obligations.
- C Conventional Control Environment Mapped to AIS: The mapping distinguishes first-line obligations within AIS from handoff information that independent functions must own.AIS is positioned within the conventional control environment rather than as a replacement for it.
- Governance lifecycle: The lifecycle mapping locates the transaction-time AIS core from appetite setting through independent assurance and feedback.It distinguishes implemented artifact functions from extensions and institutional handoffs.
- Three Lines Model: AIS is management-owned first-line prevention; its evidence supports second-line monitoring, and deterministic replay provides instrumentation for third-line assurance without transferring audit responsibility.Replay proves conformance to pinned inputs, not policy defensibility.
- Three Lines Model: Third-line assurance re-performs decisions and opines on design and legitimacy.This role remains distinct from the transaction-time AIS artifact.