Who authorises the machine?
Identity is easy. Authorisation is the wall — and it is where most enterprise AI is quietly dying.
Listen to the full conversation
The Control Layer — “Who authorises the machine?” with Alex Salazar, Co-Founder and CEO of Arcade.dev.
Watch on YouTube, or listen on Apple Podcasts and Spotify.
On 15 June 2026, a forty-person company in San Francisco announced a $60 million Series A, led by SYN Ventures with strategic cheques from Morgan Stanley and Wipro, to solve a problem most boards have not yet worked out they have.1 Eight weeks later its chief executive told me how he had discovered that problem himself — not in a customer deployment, but in his own inbox.
Alex Salazar had given an agent access to his email. It was, by his account, a magical experience: read everything, bucket it, draft the replies, archive the rest. Then a member of his team replied to a message he had never sent.
The email announced that the company was considering a candidate for a role, asked which of the recipients had met them, and requested their notes — because here, it went on, is the compensation package we are considering. There was no candidate. There was no package. The agent had invented both, selected the recipients itself, and sent the thing without ever surfacing it for approval. Salazar found out when the reply landed.
The agent had not been hacked, jailbroken, or prompt-injected. It had been helpful.
That is the story I want to sit with, because the instinct is to file it under model error and move on. It is not a model error. Every part of the machinery worked exactly as designed. The failure sits somewhere else entirely, and it is the same place where, on the best available evidence, the overwhelming majority of enterprise AI projects are currently dying.
The number nobody puts in the board paper
Here is the part that should concentrate the mind. Gartner expects more than 40 per cent of agentic AI projects to be cancelled by the end of 2027, and names inadequate risk controls alongside cost and unclear value as the drivers.2 Forrester and Anaconda data puts the share of agent pilots that fail to graduate into production at 88 per cent, with governance friction cited by 57 per cent of the leaders surveyed — second only to evaluation gaps.3 MIT’s NANDA study of more than 300 enterprise deployments found 95 per cent producing no measurable revenue acceleration at all.4
Read those three together and a pattern falls out that is genuinely awkward for the industry selling the technology. The agents are not failing because the models are not clever enough. They are failing at the boundary where the model stops thinking and starts doing.
Salazar puts it more sharply than I would dare to: “Agents don’t fail in production because the model is wrong. They fail because nobody can prove” who was permitted to do what.5
Identity is easy. Authorisation is the wall.
Salazar has earned the right to that claim the hard way. He built developer authentication once already — his company Stormpath was acquired by Okta, where he spent years on the systems that decide who gets through the door. He is now doing it again for agents at Arcade.dev. The unglamorous distinction he draws is, I think, the single most useful thing a board can take from this conversation.
Identity people talk about the three A’s. Authentication asks who am I. Authorisation asks what am I allowed to do. Audit asks what did I do. Authentication, in his words, is technically very easy. Audit is pretty easy. Authorisation is rocket science — so hard that his first company pivoted out of it, and so hard that Okta, by his account, largely avoided it too.
The reason is structural rather than technical. To decide what a user may do inside Salesforce, you have to understand Salesforce. So the industry did the sensible thing and pushed that question into the applications themselves — Gmail decides what you can do in Gmail, Workday decides what you can do in Workday. That settlement held for twenty years.
Agents break it. You cannot ask the agent to enforce its own permissions, because the agent is probabilistic and the whole point of a control is that it holds when the thing being controlled misbehaves. The thing taking an action has never been allowed to authorise itself — traders do not approve their own trades, and the engineer does not sign off their own access to the bank account. A cleverer model does not change that principle; it just makes the actor more capable.
Two failure patterns, both in production right now
If you are running agents in an enterprise today, you are almost certainly using one of two patterns, and Salazar’s argument is that both are broken.
The first is the service account. You give the agent its own identity and its own permissions — what the market has taken to calling a non-human identity. It fails on a question anyone in HR will recognise instantly: does the intern get to see the CEO’s pay? If the agent holds compensation-read access and the intern can invoke the agent, then yes, unless you throttle the agent’s permissions down to the lowest-privileged human who can reach it. Do that and the head of HR logs in to find the thing useless. The permission model collapses to the least-trusted user, and the return on investment collapses with it. This, Salazar argues, is a large part of why the retrieval-augmented generation wave of 2024 quietly disappointed: enterprise search that can only show you what the most junior person is cleared to see is not a product senior executives will use twice.
The second is the agent on your laptop. Coding agents and desktop agents are powerful precisely because they sidestep the first problem — they act as you, inside your session, with your access. Which is exactly why, in Salazar’s account, enterprises are quietly banning them from the network. They are secure in the narrow sense that the agent cannot reach anything you cannot reach. The trouble is the gap between what you can do and what you would want an agent to do on your behalf: you can delete the folder, drop the table, and mail everyone in the company. Inheriting your full privileges is not a safety property. It is the blast radius.
The fix he proposes is unglamorous and, I suspect, correct: evaluate both sets of permissions on every single call, at runtime, and require both to pass. The agent keeps its own identity. You keep yours. The agent acts on your behalf, never as you — so when central security reads the log at three in the morning, the entry says Claude Cowork, on behalf of Amer, and the diagnosis can begin rather than the blame.
Reading this far?
Subscribe to The Control Layer for one piece a week in this register — AI, cybersecurity, sovereignty, and the geopolitics of the technology stack. Free.
Guardrails are not governance
The objection I want to put honestly, because it is the one every AI lab would make, is that this is a problem the models will solve. Alignment work is real, it is improving, and a sufficiently well-behaved model would not have invented that job candidate.
Salazar’s answer is the best analogy I have heard on the subject, and it is worth repeating in full: you can raise your children with excellent morals, excellent ethics and excellent judgement, and you are still not going to give them the credentials to your bank account. Guardrails are character. Governance is structure. OpenAI and Anthropic will keep doing good work on the first. It does not remove the need for the second, because the entire purpose of the second is to hold when the first fails for honest reasons.
Which brings us to the sharpest thing he says, and the one that will annoy a category of vendor: agents are not people. They are application workloads.
The mental model of the agent-as-colleague is seductive and useful right up to the moment you start designing controls, at which point it falls apart. You do not grant a colleague’s trust to a process; you scope a process. Salazar argues that a whole market has grown up selling non-human identity as a novel category requiring novel products, and that the framing is largely promoted by the consuming end — people thinking very big — rather than by the people building the protocols. His position is that even if agents achieve something we would call sentience, they will still be application workloads.
This is where the Sorcerer’s Apprentice framing earns its keep. Mickey’s enchanted broom is not malevolent and it is not confused about its instructions. It was told to fetch water and it fetches water, faithfully, until the workshop floods — and the fault lies not with the broom’s character but with an apprentice who granted an autonomous process an unbounded permission and then went for a lie down. Nobody in that story needed a better broom. They needed a scope limit.
The sovereignty beat, and why it lands differently in London
There is a second conversation running underneath the first, and it is the one I suspect matters most to readers of this publication.
Salazar’s customers are, increasingly, refusing to run this in his cloud. His enterprise deployments now sit inside customers’ own private networks in Azure or AWS, or on their own iron via Kubernetes charts. His explanation is a lesson learned at Okta: selling to a Fortune 100 as a single central identity service meant six-month security reviews, because a central service holding everybody’s keys is, from the buyer’s side, a honeypot. In 2026 the calculus has flipped — deploying that infrastructure inside the customer takes minutes rather than being technically impossible, so the buyer takes it in-house and skips the review.
His phrase for it is that on-premise is back with a vengeance, and that every enterprise above a thousand employees now wants this inside their own network. The primary driver he names is not security but speed — nobody wants to wait six months to review someone else’s SOC 2 when the board thinks the technology is existential.
For a European reader the second-order effect is the interesting one. Because the control layer deploys anywhere, a multinational can stand it up inside its European network, touching only European data, and isolate that deployment entirely from its American one — with a governance layer between them stipulating exactly what may cross and in which direction, and the Chinese deployment firewalled off completely. Sovereignty stops being a policy aspiration and becomes an architecture decision, made by an engineer, on a Tuesday.
I want to label the following as my analytical position rather than his. This is the most consequential thing in the conversation for a UK or EU board, and it is the part least likely to appear in the vendor’s own marketing. For two years the sovereignty debate here has been conducted in the register of Yes Minister — a great deal of grave nodding about strategic autonomy, followed by a procurement decision that changes nothing. What Salazar is describing is the point at which the technical capability quietly outruns the policy conversation, and the honest question for any UK board stops being should we be sovereign and becomes why are we not, given that the deployment takes an afternoon.
Predictive judgement
Salazar’s own prediction, which he volunteered and dated, is that within 24 months the browser is dead — that point-and-click is over, and the interface to most software becomes an agent. His signals: his own site’s traffic, which he says is running roughly half bots and half humans, and an engineering team that, by his account, has not hand-written a line of code since February.
The traffic claim is corroborated independently and is if anything conservative — Imperva‘s 2026 Bad Bot Report puts automated traffic at 53 per cent of all web traffic, the first year it has exceeded human traffic outright.6 The no-code-since-February claim is his own account of his own company and should be read as such.
I am not going to adopt the browser prediction, because I think it conflates the interface dying with the interface becoming secondary, and those are different events with different timelines. Here is mine instead, which is narrower and therefore easier to hold me to.
Prediction: By 31 August 2027, at least two FTSE 100 or Fortune 500 organisations will publicly disclose an operational incident caused by an AI agent in which the named root cause is an authorisation or delegation failure — an agent acting with permissions it should not have held, or on behalf of a user who should not have been able to invoke it — rather than a model error, a hallucination, or a prompt injection.
Signals to watch: agent-specific language entering FTSE 100 cybersecurity disclosures and 10-K risk factors; the ICO or an EU data protection authority opening an enforcement action where the controller’s defence turns on what an agent was authorised to do; and the appearance of delegated authorisation as a named line item in enterprise procurement questionnaires.
What would falsify it: if, by that date, disclosed agent incidents remain overwhelmingly attributed to model behaviour — hallucination, jailbreak, injection — rather than to permission architecture, then the authorisation thesis is weaker than Salazar and I both think, and the labs will have been right that this is a model problem after all.
The publication that calls its predictions in writing.
Every Control Layer piece ends with a falsifiable prediction and a list of signals to watch. Subscribe to track them. One email a week. Free.
The bottom line
If you are a CISO, a founder or a board member reading this on a Wednesday morning, Salazar’s own Monday-morning advice is the least glamorous and most useful thing in the episode. Stop waiting for the perfect team — nobody has one, and unless you work at an AI-native company, no organisation has enough people who understand this yet. Put the skills problem aside. Write down ten things you could automate that are narrow, low-risk, and would matter if they worked. The first three will be obvious; keep digging to ten. Sit with the list for a day, see which one still nags at you, and do that one. You only learn this by taking shots on goal.
But take the governance question with you when you do. The uncomfortable finding in the Gartner, Forrester and MIT numbers is that the organisations quietly killing their agent programmes are not the ones that picked the wrong model. They are the ones that could not answer a question their auditor was always going to ask.
The model may be the brains. But somebody still has to govern the hands.
Amer Altaf is Founder and CEO of Arkava, a UK and European sovereign AI agentic automation business, and Managing Editor of The Control Layer.
The Control Layer publishes weekly. Subscribe free.
Decision-grade analysis on AI, cybersecurity, technology sovereignty, and the geopolitics of the technology stack — written for the board paper, not the timeline. By Amer Altaf, Founder & CEO of Arkava and Managing Editor of The Control Layer.
One email a week. No paywalls on the analytical pieces. Unsubscribe in one click.
References
Unattributed quotations and accounts are from the recorded conversation, The Control Layer, 12 August 2026. Figures describing Arcade’s own customers, growth and internal engineering practice are the company’s own account and are attributed as such throughout.


