Real World Atlas

Research note // 001

Category

Identity / Authorization /
Agentic commerce / Physical AI

Status

Frontier /
Emerging infrastructure

Research origin

Milan, Italy
45.4642° N, 9.1900° E

Who gives AIpermission to actin the real world?

AI is rapidly moving from answering questions to taking actions. That changes the problem.

When an AI recommends something, almost nothing has been authorized. When an AI spends money, shares information, books transportation, sends someone to your home, coordinates a physical service or delegates a task to another machine, something fundamentally different has happened.

Intelligence has acquired agency.

The question is no longer only

Can the model

understand what I want?

It becomes

Who authorized it

to make it happen?

01

What is being solved

Work across standards bodies, identity infrastructure, payment networks and academic research is increasingly converging on the same set of unresolved primitives for AI agent authorization.

01

AI agent identity

02

Delegated authority

03

Authorization

04

Human consent

05

Agent permissions

06

Auditability

07

Non-repudiation

08

Transaction authorization

09

Proof of user intent

The core transition

Traditional software generally operates inside predefined workflows. AI agents increasingly discover tools, choose actions dynamically and pursue goals across systems.

Permission therefore cannot remain an afterthought.

// System observation 001
Intelligenceis not authority.

Real World Atlas · Research note 001

02

The user permission problem

Human

“Organize my trip.”

Goal received // authority undefined

Can the agent

  • 01

    Book a €40 taxi?

  • 02

    Book a €300 transfer?

  • 03

    Change the hotel?

  • 04

    Cancel a non-refundable reservation?

  • 05

    Share passport information?

  • 06

    Spend €1,500?

  • 07

    Contact another human?

  • 08

    Delegate execution to another agent?

  • 09

    Give a machine access to a physical space?

The goal may be clear.

The authority is not.

03

Money exposes the problem

Payments make agent authorization unusually visible. A transaction is a hard boundary: it either clears or it does not, and someone remains accountable afterwards.

An agent transaction forces systems to answer questions such as:

Emerging concept

Verifiable intent.

// Field note 008
A machine that can paymust also provewhy it was allowed to pay.

Authorization path

01Human intent
02Mandate / authority
03AI agent
04Transaction
05Merchant / provider
06Verification
04

From digital agents to Physical AI

In software, an unauthorized action produces a bad record. In the physical world it produces a person at a door, a vehicle in motion, a machine inside a home.

Humanoid service robot standing still in a dark residential kitchen at night, holding a grocery bag on a steel counter

“My parents arrive tomorrow.
Take care of dinner
and get flowers for the house.”

Understanding is not
permission.

Physical AI is also an authorization problem

Domestic execution // authority boundary undefined

The machine may understand perfectly. But understanding does not answer:

Physical AI

is also

an authorization problem.

05

The authorization stack

  1. Identity

    Who is asking?

  2. Agent identity

    Which agent is acting?

  3. Delegation

    On whose behalf?

  4. Intent

    What outcome was requested?

  5. Constraints

    Budget / time / location / providers

  6. Permission

    What may the agent actually do?

  7. Escalation

    When must the human return?

  8. Execution

    Who or what performs the action

    HumanProviderAPIMachineRobot
  9. Auditability

    What happened?

  10. Verification

    Did the physical outcome occur?

06

Human-in-the-loop

The human doesn't have to disappear. Their role changes.

Human-in-the-loop may become part of the authorization architecture rather than merely a temporary limitation of AI. The human is not slower execution; the human is where authority is granted, widened or withheld.

  • SearchAutonomous
  • Contact providersAutonomous
  • Negotiate within parametersAutonomous
  • Spend up to €100Autonomous
  • €450 purchaseHuman approval required

The human becomes

an authorization checkpoint,

not necessarily the executor.

07

What is still missing

How does authority survive

all the way through

the real world?

Chain of execution

01Human
02Agent
03Merchant
04Provider
05Machine / robot
06Physical outcome

Reality intervening

  • Restaurant closed

  • Driver cancelled

  • Robot cannot enter

  • Price changed

  • Provider doesn't answer

  • Reality changed

The original intent may still be valid.

The original authorization may not.

Our read

// Intent to Real World — interpretation, not sourced finding

The transition from generative AI to real-world agency creates an infrastructure problem larger than tool calling.

The difficult question is not simply:

Can AI act?

It is

Can AI prove that it is the right agent,

acting for the right person,

with the right authority,

under the right constraints —

and can that authority survive

all the way to a verified outcome

in the physical world?

Payments are forcing the industry to solve early versions of this problem. Physical AI may make the same problem unavoidable everywhere else.

Home.Hospitality.Mobility.Commerce.Services.Robots.Cities.
//

Core Atlas thesis

HUMAN INTENT

DELEGATED AUTHORITY

Signal held // awaiting authority

AI DECISION

REAL-WORLD ORCHESTRATION

HUMAN / PROVIDER / API / MACHINE / ROBOT

VERIFIED OUTCOME

The signal does not travel from intent to execution. It stops. Authority is constituted, and only then does orchestration begin.

// Gate: delegated authority

// State: hold → activate → execute

// Terminal condition: verified outcome

// Thesis 014
The future of AIis not only aboutwhat machines can do.It is aboutwhat we allow them to do.

Milan · 45.4642° N, 9.1900° E

The next generation of AI will increasingly know what should happen. The infrastructure opportunity may lie in determining:

Whether it is allowed

to make it happen.

//

Source material

Source slots are open. Findings are filed only against verified primary material; nothing on this page is attributed to a source that has not been filed. Interpretation is confined to Our read.

Research finding

Traceable to filed primary source material.

Our interpretation

Positioned separately. Never presented as evidence.

//

Related Atlas nodes

Next signal // Research note 002

What happens when reality says no?

Failure, recovery and replanning in Physical AI.

[ Coming next ]

// Milan, Italy

// Real World Atlas

// Observation continues