PAPER PLAINE

Fresh research, simply explained. Updates twice daily.

Do User-Authored Permission Policies Improve Protection Against AI Agent Overreach?

Why asking permission each time protects better than preset rules

When people create standing rules to control what AI agents can do, those rules block fewer risky actions than asking for approval each time. Participants using preset rules allowed 20 percentage points more overreach incidents to happen compared to case-by-case human review, because they kept choosing "ask me later" rather than committing to firm policies upfront.

As AI agents gain access to email, files, and payments, ordinary people will need ways to protect themselves from unintended actions. This research shows that the intuitive solution — letting people write their own permission rules once — actually fails in practice because people second-guess their own rules when faced with real decisions. Systems designers now know they need to either push users toward firmer commitments, or accept that protecting against AI overreach may require sustained human attention rather than automated policies.