Search papers, labs, and topics across Lattice.
This study introduces Authority-Inference Separation (AIS), an architecture designed to decouple the inference of financial actions from the authority to execute them, ensuring that only validated intents can trigger financial transactions. By implementing a control plane that verifies agent identity, ownership, and compliance with policies, AIS effectively mitigates risks associated with unauthorized financial actions, as evidenced by its performance against 36 synthetic authorization attacks where it accepted none. The findings demonstrate that while AIS can enforce strict authority validation, blockchain technology plays a crucial role in providing an observable and accountable framework for executing these validated actions.
AIS successfully blocks all unauthorized financial actions while maintaining the integrity of legitimate transactions, showcasing a revolutionary approach to agentic finance.
AI agents can select tools, counterparties, and transaction parameters, yet inference should not itself confer authority to execute a financial action. This study develops and evaluates Authority-Inference Separation (AIS), an intent-centered architecture for bounded agentic finance. AIS treats a financial action intent as the control object: a machine-generated proposal can receive temporary executable authority only after an independent deterministic control plane validates registered agent identity, accountable ownership, mandate and risk-appetite lineage, policy version, state, approvals, and exact economic semantics. Blockchain can then enforce the operational representation of granted authority and record portable settlement evidence, while institutional legitimacy, service delivery, accounting classification, and human accountability remain off-chain obligations. Evaluation combines four-domain instantiation, official BIS and MAS cases, a 48-fixture executable prototype, and a public-ledger observability test. Across 36 synthetic authorization attacks, a direct-agent baseline accepted 36 attack effects, a prompt-policy baseline accepted 20, and AIS accepted none; all three accepted 8/8 admissible fixtures. AIS also rejected 4/4 token replays and 8/8 recipient or rail substitutions, withheld completion in 4/4 service-delivery failures, and populated all 13 defined evidence fields. A test of 1,700 recent Base transactions associated with public x402 facilitator addresses shows that public ledgers can evidence settlement and selected authorization parameters but cannot establish institutional mandate, legal accountability, service delivery, or accounting treatment. AIS and blockchain are therefore complementary: AIS decides whether a specific intent may act, while blockchain can make granted authority bounded, executable, and independently observable.