# Preprint tests authorization broker for compromised LLM agents

_Wednesday, September 2, 2026 at 12:00 AM EDT · Science, Security · Latest · Tier 2 — Notable_

A preprint describes an authorization broker intended to confine LLM agents and their sub-agents to explicitly delegated actions.

The authors report that a default bearer-credential runtime failed four modeled threats, while their broker blocked those threats in adversarial testing. They report zero accepted forged tokens in 200,000 attempts and a mean of 1.5 reachable actions for a compromised sub-agent, compared with all 8,100 under bearer delegation.

The work remains a preprint, and its reported results have not been independently verified.

## Sources

- [cs.AI updates on arXiv.org](https://arxiv.org/abs/2609.00267)

---
Canonical: https://techandbusiness.org/newswire/zky0ym56QBMmqNh8ZucBgj
Retrieved: 2026-09-02T15:53:40.321Z
Publisher: Tech & Business (techandbusiness.org)
