© Mapbox, © OpenStreetMap

Speaker

Vikas Malik

Vikas Malik

A Senior Lead Cybersecurity Architect at JPMorganChase | Speaker & Creator on Emerging Security Trends | Driving Secure Cloud, SaaS & AI Adoption

Columbus, Ohio, United States

Actions

Vikas Malik is a senior cloud security architect with deep experience securing cloud and AI based systems. He has worked extensively with modern distributed architectures and industry-standard cloud technology stacks, focusing on how security controls behave in complex, real-world systems.

Area of Expertise

  • Finance & Banking
  • Information & Communications Technology

Topics

  • Cloud & AI Security
  • AI Security

Ambient Authority Confusion : Why AI Agents break our authorization assumptions

Modern app security models assume that authorization decisions implicitly capture user intent. This assumption has held for decades because the traditional systems are deterministic, and execution paths are tightly bound to the initiating principal.

AI agents quietly invalidate this assumption.

My talk introduces Ambient Authority Confusion (AAC), an architecture gap in which an AI agent executes actions it is fully authorized to perform, yet violates user intent because authority is no longer bound to the intent at runtime. Crucially, this occurs without any policy violation, misconfiguration, or exploit.

AAC is not an IAM bug, not a role design issue, and not a prompting failure. Instead, it emerges when systems allow agents to operate under broad ambient authority while making contextual decisions on behalf of specific users. This pattern first surfaced during a security review of an agent workflow that passed every access control check, yet repeatedly produced outcomes users could not explain or predict.

Through a simplified User -> Agent -> System Model and a live local demo, this session shows how AI agents amplify the classic confused deputy problem - not by escalating privileges, but by dissolving the runtime binding between authority and intent.

AAC does not replace the confused deputy problem; it formalizes a distinct failure mode that arises when delegation is continuous, decisions are non-deterministic, and authority is ambient rather than explicitly invoked.

This talk concludes with concrete takeaways AppSec teams can look for during agent reviews, questions security architects should begin asking platform owners, and why tightening RBAC, ABAC, or tool permissions alone cannot address this class of risk.

OWASP BASC 2026 Sessionize Event

April 2026 Boston, Massachusetts, United States

Vikas Malik

A Senior Lead Cybersecurity Architect at JPMorganChase | Speaker & Creator on Emerging Security Trends | Driving Secure Cloud, SaaS & AI Adoption

Columbus, Ohio, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top