Questions and answers — The four properties underneath

Questions and answers for The four properties underneath · v0.2 · 8 September 2026

How this was made. The version number counts drafts of the text. It does not measure the inquiry behind it, which has run over days and across several AI systems, with argument between those systems and within them, directed, refused and repeatedly redirected by the author. The source material was AI-generated, and then adversarially and iteratively refined across a range of tools — systems built by different companies in different jurisdictions, set against each other and against the author. No one of them produced this text, and no one of them reviewed it alone. The plurality is deliberate rather than incidental. A single model carries a single set of priors about which sources are authoritative, and this series argues that an evidence base narrowed in exactly that way is how a contested question comes to look settled. Using one model to investigate that claim would have been the claim refuting itself. To name a single model on it would credit that model with work that was neither its own nor done in a single pass. The plurality was also necessary, and the record should say why. In drafting, the assisting model repeatedly led with United States institutional sources — a national laboratory, an industry association, a market study nineteen years old — and presented conclusions drawn from them as the state of knowledge. On one occasion European measured data contradicting those conclusions was present in the same research return and was placed below them. Framings were proposed that would have argued against this series’ own position using that evidence base, and offered as rigour. Each was refused by the author and the material rebuilt. That is the mechanism these documents describe, occurring in their own making, and it is recorded because a series arguing that evidence bases narrow without anyone deciding to narrow them cannot credibly claim its own production was exempt. The framing, the corrections and the judgements are the author’s, and so are the errors. How this site is written sets out what is declared on every piece, who checks it, and where the per-piece record lives.


Is this not just security engineering with new words?#

Much of it is security engineering, and the piece leans on that literature rather than inventing a vocabulary. What is new is not the mechanisms but the question they are asked to answer: whether a claimed delegation of authority is real or nominal.

The four properties are stated so they can be checked by watching a system work rather than by reading a description of it.


“Principal”, “delegation”, “non-repudiation” — are these not settled terms?#

They are settled in incompatible ways, and the divergence does work in the argument.

Saltzer and Schroeder in 1975 defined a principal as “the entity accountable for the activities of a virtual processor” — accountability is in the definition. RFC 4949 defines it by identity alone. Both are standard; they are not the same concept, and a procurement document quoting one while meaning the other has said something nobody checked.

The deprecated definition of non-repudiation discussed in the piece is published by CNSS Instruction 4009, not by NIST. The two are easily confused.


Where does “ambient authority” come from?#

Miller, Yee and Shapiro, “Capability Myths Demolished” — a 2003 paper. The piece records a correction here too: the term does not appear in Miller’s 2006 dissertation, which was checked directly, zero occurrences across 229 pages. The 2003 paper is the source.

The idea is simple enough to state without the term: a request that presents nothing and succeeds because of who is asking, rather than because of what it carries, has ambient authority. It is the default in most systems, and it is why a persuaded agent can do damage its designers never granted.


Is prompt injection not a theoretical risk?#

A 2026 crawl of 1.2 billion URLs across 24.8 million hosts found 15,300 validated injection instances across 11,700 pages, around 70% of them in non-rendered HTML — present in the page, absent from what a person sees. An earlier benchmark found a ReAct-prompted GPT-4 acting on injected instructions in roughly 24% of cases.

The reason it belongs in a piece about delegation rather than in a piece about model safety is that the fix is not a better model. An agent that holds only the capability it was given cannot be talked into using one it does not hold.


Did anyone require this before?#

The FIPA Agent Management Specification, SC00023K, published in 2004, required that an agent have “at least one owner”. That requirement existed, in a published standard, twenty years ago.

A detail worth recording: the specification’s domain now serves a gambling affiliate site, captured between 21 July and 5 September 2026. The standard did not fail an argument; the organisation maintaining it stopped, and the requirement went with it.


What would show the four properties are wrong?#

A system holding none of them that can nevertheless demonstrate, to somebody who was not present, what it did and on whose authority — repeatedly, and not by reconstruction after the fact.

If that is achievable without the four, they are not necessary and the specification is overbuilt.

Disclaimer

Status of these claims

What this publication does not claim, and what is outstanding against it in the register.

Nothing outstanding in the register. Every claim in this publication has its evidence recorded, and no question against it is parked. That is a statement about this publication on the date shown above, generated from the register rather than asserted, and it will change when the register does.

Alongside: the publication · sources and provenance