KYE Governed Research Rail™ · Why · Edition 2026-06
The authority that outlived its purpose — why standing permission is the quiet governance risk
Ed25519-sealed · fingerprint a580e81547f5281d · verify it yourself ↓
KYE Protocol™ governs actions and authorities, not outcomes, diagnoses, or results. This report synthesises public sources under the evidence / no-hallucination gate — every claim below is pinned to a cited source.
Executive tear-sheet
The loudest AI-governance fear is the rogue agent. The quieter, more common failure is zombie authority — permission, delegation or access that stays technically valid long after the purpose that justified it has changed or vanished. The project ended, the employee moved on, the market shifted, the clinical context changed — yet the access, the agent, the standing approval keep operating, because nothing explicitly revoked them. Security standards already recognise this: zero-trust architecture says trust must be continually re-evaluated, never inherited from a past grant, and account-management controls already mandate periodic recertification of standing access. This brief relays what those standards establish and, separately and clearly labelled, argues that the right governance question is shifting from "was authority granted?" to "does this authority still have a legitimate purpose?" It is not security or compliance advice.
Key findings
- Zero-trust already rejects standing trust. NIST's Zero Trust Architecture states that trust is never granted implicitly and access is evaluated per request — authorisation from a prior moment does not carry forward by default (NIST SP 800-207).
- Standards already mandate recertification — because permissions outlive their need. Account-management controls require organisations to review accounts and access for ongoing need and to remove or disable them when the conditions that justified them no longer hold (NIST SP 800-53, AC-2). The control exists precisely because access persists by default.
- For AI systems, oversight is a point-of-use duty, not a one-time sign-off. The EU AI Act™ places human-oversight and logging obligations on the deployer, discharged while the system operates — i.e. authority is meant to be exercised and re-checked at the moment of action, not assumed from deployment.
- The dominant risk is structural, not malicious. Across these sources the pattern is the same: systems preserve permissions, contracts and workflows extremely well, and re-examine whether their purpose still holds extremely poorly.
What the standards establish
TL;DR According to NIST SP 800-207, a zero-trust architecture treats no asset or session as inherently trusted: every access request is authenticated and authorised against current policy, and trust is continually evaluated rather than inherited from an earlier decision.
According to NIST SP 800-207, a zero-trust architecture treats no asset or session as inherently trusted: every access request is authenticated and authorised against current policy, and trust is continually evaluated rather than inherited from an earlier decision. NIST SP 800-53 control AC-2 (account management) requires that accounts and their privileges be reviewed for continued need and disabled or removed when the justifying conditions lapse — an explicit acknowledgement that access does not expire on its own. The EU AI Act™ assigns the deployer of a higher-risk AI system logging and human-oversight duties exercised at the point of use. This brief relays these published requirements; it does not characterise them beyond what the cited sources state, and whether and how any apply to a given organisation is a matter for that organisation's own advisers.
What KYE Protocol™ reads into it (interpretation, not advice)
TL;DR This section is KYE Protocol™'s interpretation, clearly separated from the standards above, and is not security or compliance advice.
This section is KYE Protocol™'s interpretation, clearly separated from the standards above, and is not security or compliance advice. The through-line is that authority should be purpose-bound, re-evaluated and contestable rather than static — and KYE Protocol™ governs agents and actions as first-class principals; it does not run them:
- Authority is bound to a purpose, not just an identity. A grant carries the purpose and scope that justified it, so the governing question becomes does that purpose still hold? — not merely is the credential still valid?
- Purpose deviation is drift, and drift depletes authority. When the workflow moves away from the context it was authorised in — purpose changes, role changes, jurisdiction changes, risk changes — that deviation is treated as drift against the originally-authorised context; as it accumulates, controls tighten and re-authorisation is required, rather than execution continuing on inherited permission.
- Re-evaluation happens at the action, not once at onboarding. Admissibility is decided at the moment of the consequential action against current authority and scope, which is the operational form of "trust is continually evaluated."
- Finality is closure, not immunity. An action reaching Authority Finality™ means it legitimately closed under the purposes, authorities and evidence that existed at that moment — captured in a sealed, replay-verifiable record. It does not place the action beyond future contestation: provenance is preserved and legitimacy stays time-aware.
The boundary KYE Protocol™ states plainly: the central risk in autonomous systems is often not a malicious actor but authority that outlived its purpose — and the only durable answer is to make purpose, not just permission, the thing that has to still be true at the moment of the action.
Claims → sources — every claim mapped to a pinned source
This is the claims→source map: no claim ships without a cited, pinned public source (evidence gate). Each numbered claim below is pinned into this edition's sealed evidence pack kye:evidence-pack:research:authority-that-outlived-its-purpose:2026-06.
- A zero-trust architecture treats no asset or session as inherently trusted: trust is never granted implicitly, and every access request is authenticated and authorised against current policy rather than inherited from an earlier decision (continual, per-request evaluation). https://csrc.nist.gov/pubs/sp/800/207/final — NIST Special Publication 800-207, Zero Trust Architecture. Cited as a published standard, not as a security or compliance recommendation by KYE Protocol™. (retrieved 2026-06-16T00:00:00Z)
- Account-management controls require organisations to review accounts and access privileges for continued need and to disable or remove them when the conditions that justified them no longer hold — an explicit recognition that standing access persists by default. https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final — NIST Special Publication 800-53 Rev. 5, control AC-2 (Account Management). Cited as a published standard, not as a security or compliance recommendation by KYE Protocol™. (retrieved 2026-06-16T00:00:00Z)
- The EU AI Act places logging and human-oversight duties on the deployer of a higher-risk AI system, discharged at the point of use rather than as a one-time sign-off. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202401689 — Official Journal of the European Union (Regulation (EU) 2024/1689) (retrieved 2026-06-16T00:00:00Z)
Replay-verifiable
This edition is sealed and Ed25519-signed over the published keys. Any reader can confirm the seal offline — no KYE™ service required.
- Signature algorithm
EdDSA- Key id
kye:key:self-audit-fixture-2026-06- Seal fingerprint
a580e81547f5281d(sha256 of the signature, first 16 hex)- Published keys (JWKS)
/trust/self-audit-jwks.json- Report envelope
kye:research-report:authority-that-outlived-its-purpose-2026-06· schemakye.research_report.v1
Verify it yourself: fetch the published JWKS, recompute the Ed25519 signature over this edition's canonicalised envelope (minus seal) bound to the body hash, and confirm it matches the key id above — from public keys alone, no KYE™ service in the loop.