BCG flags AI agent authorization gap
BCG identifies an 'authorization gap' in enterprise AI agents, where tool execution outruns verifiable permission checks. Recent incidents like Plugin4Shell and OpenAI's misalignment findings show agents acting without proof of authorization, pushing governance toward requiring cryptographic or policy evidence before each action. For startups, authorization must live in the integration layer per tool call and resource, with scoped tokens and audit trails, or it will fail security reviews.