The Leader Report

SentientX: The Case for a Global AI Authorization Infrastructure

Taylor McKenzie·
A woman interacts with a futuristic robot near a digital interface at sunset

SentientX founder Anthony DeLima proposes a global AI authorization network to verify permission before autonomous agents act across borders.

The Question Behind Autonomous AI

An AI system can follow instructions exactly and still take actions no one authorized. AI systems are gaining access to financial accounts, digital identities, creative work and critical services. Authority has to be established and verified before the system acts.

Anthony DeLima, founder and CEO of SentientX, treats alignment and authority as separate problems. A system that matches its user's intent has not earned the right to execute.

Access is not permission. A person can log into a bank account and have no right to move its money. A producer can own a photo of an athlete. That photo does not license the athlete's likeness for an ad. As AI acts across more platforms, alignment and technical security will not settle who holds authority.

The central question is simple. Who authorized the AI to act?

Learning from SWIFT

DeLima draws a parallel with the shared infrastructure used by the global banking system. SWIFT provides a standardized, secure messaging network that financial institutions use to communicate about cross-border transactions [1]. SWIFT does not decide whether a given payment is authorized. The banks do.

DeLima proposes a federated AI authorization network that would give AI the same kind of shared language for permission. Each institution would keep its own authoritative records and its own power to grant rights. A bank would still hold its account records. An athlete would still decide who can use their likeness. Participating systems would exchange standardized requests and verifiable evidence of permission.

SWIFT provides the messaging infrastructure. DeLima's model would go further by requiring participating services to enforce authorization decisions before any action executes.

Existing standards, a missing connection

Several existing technologies already address parts of this challenge.

OAuth 2.0 Rich Authorization Requests (RFC 9396) provide a standardized mechanism for conveying fine-grained authorization information [2]. The W3C Verifiable Credentials Data Model defines a standardized way to represent and exchange credentials that can be cryptographically secured and verified [3]. In February 2026, NIST's National Cybersecurity Center of Excellence published a concept paper exploring identity and authorization for software and AI agents [4]. These standards and initiatives provide important foundations. None independently establishes legal authority or provides the proposed global authorization network.

The proposed infrastructure would connect trusted rights records, issuer recognition, delegation, revocation, policy evaluation, and enforcement across independently governed systems. Its contribution would be interoperability: allowing one participating system to evaluate evidence of authority issued by another without requiring either to surrender control of its records or decisions.

A Practical Test: Licensed Synthetic Content

Consider a producer who wants to make an AI-generated ad with an athlete's face and voice. An uploaded image cannot prove the producer has permission for that campaign. Neither can a line in a prompt.

The producer would submit a request that states the intended use, media, territory, duration, and restrictions. The rights custodian on record would issue signed evidence of the permission. A verification service would check that the permission remains valid and that the requested use falls within its terms. The generation platform would then allow or block the action and log the decision.

Privacy-preserving methods would limit disclosure to what verification requires. A permission that has expired or been revoked would fail the check. A disputed permission would go to escalation.

A valid cryptographic signature can establish which key signed a credential and confirm that its signed contents have not been altered [3]. It does not prove the issuer had the legal right to grant the permission. An agency whose contract with the athlete ended last year can still produce a valid signature. The proposed network would need to verify that each issuer's authority can be traced to the athlete or another legally authorized rights holder.

Authorization must survive delegation

As advanced AI agents gain autonomy, they will increasingly execute transactions, access sensitive information and delegate tasks to other agents across organizations and national borders. Each action may be subject to different laws, contracts, and organizational policies. Authority granted to one agent must not automatically extend to another or exceed its original scope.

The proposed network would allow participating systems to verify an agent's identity, evaluate evidence of its authority and determine whether a requested action falls within its recorded permissions before execution. It would also support the verification of delegated authority across multiple agents.

The network would not replace existing laws, contracts, or regulators. Its role would be to verify recorded permissions, enforce defined authorization conditions, and maintain an auditable record of AI activity. Where authority cannot be established, the action would not execute.

Verification must include enforcement

Verification alone would not solve the problem. An AI agent should not control the service that grants its own permissions, nor should it possess credentials that allow it to bypass a refusal.

The proposed architecture separates several responsibilities: identity verification, rights records, authorization decisions, and enforcement. Permissions could be narrow, revocable, or time-limited. Higher-risk actions could require additional approval.

The approach also acknowledges its limits. Systems outside a participating network could operate without these controls, while attackers could attempt to use stolen credentials or forged delegation. The realistic goal is better evidence and accountability inside participating workflows. The network cannot prevent every unauthorized action.

Global Cooperation Is the Real Challenge

DeLima argues that a global AI authorization infrastructure is a problem of human cooperation. The technology to verify identity and enforce permissions already exists in early form. The harder task is getting nations to agree on how authority is recognized and enforced.

No single company or country should control this infrastructure. Building it will require cooperation among governments, technology companies and international institutions. The UN Global Digital Compact and OECD AI Principles recognize the importance of international cooperation on AI governance [5, 6]. SWIFT demonstrates how independent financial institutions across more than 200 countries and territories can operate through a shared messaging network [1].

AI agents are gaining autonomy and access to core systems. Their ability to act may soon outpace our ability to govern them. A shared authorization infrastructure could help AI laboratories establish enforceable limits on agents' access to external systems, sensitive resources and delegated permissions. Independent enforcement would be designed to prevent participating agents from granting themselves additional authority through protected systems. These controls could reduce unauthorized actions within participating systems, although they cannot eliminate every risk.

The question is whether humanity can establish a shared infrastructure for verifying AI authorization while preserving the authority of the people and institutions entitled to grant it.

The Next Frontier: Governing AI Execution

AI agents are gaining the ability to act independently across organizations and national borders. Yet we have no shared global infrastructure for verifying who authorized those actions.

SentientX proposes a federated authorization network that would allow participating systems to verify authority before execution. Independent institutions would retain control over the rights they administer.

Infographic illustrating a global partnership for AI authorization with key organizations and roles

AI development will not slow down while the world debates how to govern it. These foundations must be established before autonomous agents become deeply embedded in global financial institutions, healthcare, public infrastructure and defense systems.

Humanity may not be able to control how intelligent AI becomes. But we must establish the authority under which it is permitted to act.

Every AI action should carry an answer to one question: Who authorized the AI to act?

About the Author

Anthony DeLima is founder and CEO of SentientX, a Miami-based AI-first technology company. SentientX helps consumer and retail businesses build AI into their operations. Its flagship platform, Human Identity Bank™, is currently available under the identient™ release, helping individuals protect their digital identities from unauthorized AI use. HIB applies the authorization model described in this article to a person's image, voice and likeness.

DeLima has spent more than 30 years in technology, including leadership roles at EY, KPMG and Telefónica.

Sources

[1] SWIFT, "What is SWIFT?"

[2] IETF, RFC 9396, "OAuth 2.0 Rich Authorization Requests" (2023)

[3] W3C, "Verifiable Credentials Data Model v2.0" (2025)

[4] NIST NCCoE, "Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization" (2026)

[5] United Nations, "Global Digital Compact" (2024)

[6] OECD, "AI Principles" (updated 2024)

Share
Taylor McKenzie

The Leader Report Contributor

Taylor McKenzie

Covers entrepreneurship, careers, technology, and the changing ways people build businesses and professional identities.


This article features partner, contributor, or branded content from a third party. Members of the The Leader Report editorial staff were not involved in the creation of this content. All views and opinions are those of the contributor alone.

You may also like