Real World Atlas
Research note // 001
Category
Identity / Authorization /
Agentic commerce / Physical AI
Status
Frontier /
Emerging infrastructure
Research origin
Milan, Italy
45.4642° N, 9.1900° E
Who gives AIpermission to actin the real world?
AI is rapidly moving from answering questions to taking actions. That changes the problem.
When an AI recommends something, almost nothing has been authorized. When an AI spends money, shares information, books transportation, sends someone to your home, coordinates a physical service or delegates a task to another machine, something fundamentally different has happened.
Intelligence has acquired agency.
The question is no longer only
Can the model
understand what I want?
It becomes
Who authorized it
to make it happen?
What is being solved
Work across standards bodies, identity infrastructure, payment networks and academic research is increasingly converging on the same set of unresolved primitives for AI agent authorization.
AI agent identity
Delegated authority
Authorization
Human consent
Agent permissions
Auditability
Non-repudiation
Transaction authorization
Proof of user intent
The core transition
Traditional software generally operates inside predefined workflows. AI agents increasingly discover tools, choose actions dynamically and pursue goals across systems.
Permission therefore cannot remain an afterthought.
Real World Atlas · Research note 001
The user permission problem
Human
“Organize my trip.”
Goal received // authority undefined
Can the agent
- 01
Book a €40 taxi?
- 02
Book a €300 transfer?
- 03
Change the hotel?
- 04
Cancel a non-refundable reservation?
- 05
Share passport information?
- 06
Spend €1,500?
- 07
Contact another human?
- 08
Delegate execution to another agent?
- 09
Give a machine access to a physical space?
The goal may be clear.
The authority is not.
Money exposes the problem
Payments make agent authorization unusually visible. A transaction is a hard boundary: it either clears or it does not, and someone remains accountable afterwards.
An agent transaction forces systems to answer questions such as:
Was the agent authorized?
Does the transaction represent the user's actual intent?
What constraints existed?
Who is accountable if execution goes wrong?
Emerging concept
Verifiable intent.
Authorization path
From digital agents to Physical AI
In software, an unauthorized action produces a bad record. In the physical world it produces a person at a door, a vehicle in motion, a machine inside a home.

“My parents arrive tomorrow.
Take care of dinner
and get flowers for the house.”
Understanding is not
permission.
Domestic execution // authority boundary undefined
The machine may understand perfectly. But understanding does not answer:
- 01
Which florist may it use?
- 02
How much may it spend?
- 03
Can it share the home address?
- 04
Can it authorize a delivery?
- 05
Can it substitute another restaurant?
- 06
Can it increase the budget?
- 07
Can it allow someone into the property?
- 08
When must it ask the human again?
Physical AI
is also
an authorization problem.
The authorization stack
Identity
Who is asking?
Agent identity
Which agent is acting?
Delegation
On whose behalf?
Intent
What outcome was requested?
Constraints
Budget / time / location / providers
Permission
What may the agent actually do?
Escalation
When must the human return?
Execution
Who or what performs the action
HumanProviderAPIMachineRobotAuditability
What happened?
Verification
Did the physical outcome occur?
Human-in-the-loop
The human doesn't have to disappear. Their role changes.
Human-in-the-loop may become part of the authorization architecture rather than merely a temporary limitation of AI. The human is not slower execution; the human is where authority is granted, widened or withheld.
- Search✓ Autonomous
- Contact providers✓ Autonomous
- Negotiate within parameters✓ Autonomous
- Spend up to €100✓ Autonomous
- €450 purchaseHuman approval required
The human becomes
an authorization checkpoint,
not necessarily the executor.
What is still missing
- Agent identity✓ Emerging
- Delegated authority✓ Emerging
- Agent payments✓ Emerging
- Tool permissions✓ Emerging
- Proof of intent✓ Emerging
How does authority survive
all the way through
the real world?
Chain of execution
Reality intervening
Restaurant closed
Driver cancelled
Robot cannot enter
Price changed
Provider doesn't answer
Reality changed
The original intent may still be valid.
The original authorization may not.
Our read
// Intent to Real World — interpretation, not sourced findingThe transition from generative AI to real-world agency creates an infrastructure problem larger than tool calling.
The difficult question is not simply:
Can AI act?
It is
Can AI prove that it is the right agent,
acting for the right person,
with the right authority,
under the right constraints —
and can that authority survive
all the way to a verified outcome
in the physical world?
Payments are forcing the industry to solve early versions of this problem. Physical AI may make the same problem unavoidable everywhere else.
Core Atlas thesis
HUMAN INTENT
DELEGATED AUTHORITY
Signal held // awaiting authority
AI DECISION
REAL-WORLD ORCHESTRATION
HUMAN / PROVIDER / API / MACHINE / ROBOT
VERIFIED OUTCOME
The signal does not travel from intent to execution. It stops. Authority is constituted, and only then does orchestration begin.
// Gate: delegated authority
// State: hold → activate → execute
// Terminal condition: verified outcome
Milan · 45.4642° N, 9.1900° E
The next generation of AI will increasingly know what should happen. The infrastructure opportunity may lie in determining:
Whether it is allowed
to make it happen.
Source material
Source slots are open. Findings are filed only against verified primary material; nothing on this page is attributed to a source that has not been filed. Interpretation is confined to Our read.
NIST / NCCoE
Identity and authority for software and AI agents
AWAITING PRIMARY SOURCE
OpenID Foundation
Authorization / AuthZEN / agent authorization
AWAITING PRIMARY SOURCE
Google
Agent Payments Protocol (AP2)
AWAITING PRIMARY SOURCE
Visa
Trusted Agent Protocol
AWAITING PRIMARY SOURCE
Academic research
AI agent permission systems
AWAITING PRIMARY SOURCE
Research finding
Traceable to filed primary source material.
Our interpretation
Positioned separately. Never presented as evidence.
Related Atlas nodes
Next signal // Research note 002
What happens when reality says no?
Failure, recovery and replanning in Physical AI.
[ Coming next ]
// Milan, Italy
// Real World Atlas
// Observation continues