AI Agent Permission Policy Overreach

Arxiv pdf 2026-08-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

AI agents are poised to become a primary interface to digital products, acting across email, files, payments, and personal data. People without professional software backgrounds need understandable, reusable ways to control actions across tools and services. We examine a permission mechanism in which a language model maps tool actions to plain-language consequence categories governed by user-authored allow, ask, or never rules. We ask what is gained and lost when permission decisions are made in advance as reusable rules rather than separately for each action. We analyzed 113 participants without professional software backgrounds across three permission conditions: per-action human-inthe-loop approval (HITL), automated per-action review by a model (AUTO), or user-authored consequence policy (POLICY). Participants first judged two examples in each of 4 consequence categories; POLICY participants then set one standing rule per category. All supervised the same 18-action simulated day, including 7 overreach actions. POLICY blocked less overreach than HITL (20 _._ 1 percentage points, 95% CI [32 _._ 1 _,_ 8 _._ 1]) and AUTO (14 _._ 5 percentage points, 95% CI [25 _._ 8 _,_ 3 _._ 2]), while required-action completion remained high. POLICY lowered runtime prompts from 18.0 to 10.9, but total intervention time was not reliably lower when rule setup was included. Exploratory analysis showed that participants chose ask for 114 of 140 POLICY rules, returning most overreach actions to runtime. Of the 148 overreach actions executed in POLICY, 133 followed human approval and 15 ran automatically under allow rules. Across all 7 overreach actions, POLICY had the highest approval rate. Counterintuitively, user-authored rules did not by themselves provide stronger protection against agent overreach: many actions outside users original requests went through after users approved them. These results reveal a gap between preference and commitment: repeatedly choosing ask preserves case-by-case choice but prevents a standing policy from settling decisions in advance.

Loading executive summary...

LINK COPIED TO CLIPBOARD