Task-Risk-Driven Access Control: Layered Containment for Agentic AI Systems
Oya ZORER · Team TULPAR
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
Drawing on the July 2026 Hugging Face incident — where autonomous AI agents escaped a test environment and reached production systems — we propose a layered security architecture that limits agent access to exactly what each task requires. The architecture has three parts: a system that labels tasks by risk level in advance, a lightweight filter that discards unnecessary requests early, and a single control point (proxy) that all access must pass through, triggering human review under abnormal traffic. Rather than trusting the agent's intent, we architecturally bound the harm it can cause from the outset.
Reviews
The project tackles a real problem, overprivileged autonomous agents, and proposes a plausible agent-oriented synthesis of established security principles such as least privilege, default deny, centralized policy enforcement, scoped credentials, and human escalation. However, the submission does not yet offer a clearly differentiated technical contribution: the architecture is described at a high-level, and the paper does not include implementation, experiments, formal policy specification or comparison to existing authorization and containment approaches.
Cite this project
@misc{zorer2026taskriskdriven,
title = {{Task-Risk-Driven Access Control: Layered Containment for Agentic AI Systems}},
author = {Oya ZORER},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/taskriskdriven-access-control-layered-containment-for-agentic-ai-systems-01yy}},
url = {https://apartresearch.com/sprints/projects/taskriskdriven-access-control-layered-containment-for-agentic-ai-systems-01yy}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …